Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts

Wednesday, June 6, 2007

Back from the dead ... and more concerned than ever!

So this blogging is harder to keep up with than I expected. I can't believe it's June already. Let me catch you up quickly on the last month:
  • My company has gone through significant growth - our unique approach to security and risk assessments has really caught on and we're hiring people as quickly as we can find them. If you're a CISSP or have a similar background, please call me!
  • I have attended several regional trade shows and conferences over the past month. Some were security related, but most were not. As a result, I have spent a lot of time talking with people who are not "security experts".
  • I have also spent significant time speaking with IT directors and leaders in local and regional government bodies.

And after a month of talking and listening, listening and talking, here's what I see:

  • Everyone seems to accept that security issues are real and that they are at risk.
  • If you haven't been breached, the risk you're under is acceptable. I would be a rich man if only I had a dollar for every version of, "it won't happen to me" that I have heard.
  • The security threats - particularly in the area of social engineering - are becoming more prevelent and are attacking smaller and smaller organizations. I recently ran into the president of a company in rural Pennsylvania - Amish country - whose A/R person was deceived into giving away banking information. They are a 24 person company.

Folks - what's it going to take?!?! At some point, this is going to become irresponsible behavior to keep ignoring these issues. (In fact, California is currently considering forcing companies who have been breached to cover all costs for consumers and businesses who have to deal with their information being compromised)

This blog REALLY isn't intended to be a commercial for my company. But it drives me crazy that we have the resources and ability to help protect you, your company and your customers - but you won't let us. (obviously, I don't direct that to our customers - you guys I love!) :-)

I know this sounds like a rant - and it is - but it's also a plea. As a business owner, you have a responsibility to protect your customers. Do the right thing. Your I.T. people don't have the depth - trust me - they don't. It's not their fault - I'm sure they do a great job keeping the business running. But security is a full time job and they just don't have the time.

So bring in a professional organization. If you don't like me or Pervasive Solutions - no problem. I'll even recommend some others for you if you want. But find someone you can trust and have them help you. At a minimum, here are the things you should be doing every 9 - 12 months:

  • End-user security awareness training: help your employees understand the importance of security and the threats that they may face.
  • External network vulnerability assessment: find out what risks exist on your network
  • Network and server configuration assessment: help your I.T. team build security into your infrastructure instead of trying to bolt it on afterwards
  • Policy & procedure review: establish and review your security policies and procedures, both for your I.T. team and your company as a whole, to set expectations and protect the company from compliance and litigation risks

I know these may sound like a lot. But I assure you, they aren't. For only a few thousand dollars per year, you can cover 80% of your risk with just these four steps. Certainly, I would suggest that you eventually conduct complete, thorough security and compliance risk audits which will dig deep. But don't worry about that now. Just do the basics. If you do, you'll be ahead of your peers who are still burying their head in the sand.

It's like the old joke, "if we get chased by a bear, I don't have to outrun the bear - I just have to outrun you." Make your company a smaller target - sure, you'll still be a target - but there will be bigger targets all around you.

Friday, April 6, 2007

What you Need to Know about Breach Notification and Privacy Laws

Have you ever heard of California law SB 1386? Chances are good that if you do business in the United States, whether you have heard of it or not - and even if you're not in California - this law impacts you.

SB 1386 was a groundbreaking statute that first took effect July 1, 2003. You can find the actual bill here, but boiled down, it exists to protect the personal privacy information of all California residents. If your business has acquired such personal information (which includes SSN, driver's license number, account or credit card numbers, etc.), and you realize that at some point, you did not have complete control over that data, you must alert each individual in writing of the potential breach of their information.

The law also establishes provisions for civil suits by impacted residents, creating a basis for class action suits against your company should such a breach occur.

To date, well over 50 companies and institutions have been required to alert individuals of the risk of identity theft due to this law.

"So what?", you say, "I don't do business in California". Since SB 1386 took effect, 33 other states have approved similar legislation and several others are considering it - as is the Federal Government. The University of Georgia has put together some great resources, including a map of the states with approved legislation.

What are the REAL Impacts of Breach Notification Acts?
So chances are pretty good that at least one of these laws impacts your business. But what are the real impacts? Let's look at an example. A financial services firm with 3,000 clients obviously stores protected data. One day, they realize that a laptop with client records was stolen from the back seat of a car. The likely impacts of this event include:
  • Written notification to each client at a cost of approximately $3,000.
  • To try to maintain their clients' confidence, they elect to provide 1 year of credit reporting services for each of their clients (this is becoming the norm). At a cost of $50 per client, that will run them $150,000.
  • Depending on their state, they may be subject to fines reaching as high as $150,000.

So that creates the potential for over $300K of hard costs. But what about the soft costs? How many clients are going to leave because of this event? How many clients are going to file suit? If this company only lost $300K, it would be a miracle. In reality, an event like this could cripple a small company.

Now, what happens if you're a local or regional retailer? Do you know whether your systems record the credit card numbers that you take? Do they store them unencrypted? You might easily have 100,000 consumers' information. Can you imagine the cost should you be breached?

What Should You Do?
So clearly, the impacts of these laws are real and they are significant. The question then becomes, what do you need to do to protect your company?

For starters, you need to take data security seriously. This starts with security policies and procedures. For example, you probably have back-up tapes of servers and databases. What is your policy for handling and storage of those tapes? Is that policy followed by your IT organization? What about password management? Do you have employees that share passwords? Or do you have systems whose administrative password is left blank? These are common issues for SMBs but it is precisely these issues that could result in a breach of your data. Establishing a thorough set of information security policies and then training your team to follow them is a critical step in protecting your data and your company.

In addition, you do need to make sure your networks, servers, workstations, desktops, mobile devices, etc. are all protected from breach and inappropriate access. If you're a mid-size company with just a handful (or less) of IT people, you probably don't have the security expertise needed to evaluate and implement a sufficient level of security around your technology. Bringing on a consultant to help this process will be money well spent. However, be warned - if the consultant you hire works for a company that sells security appliances or other network devices, they may have an agenda when they walk in the door (to sell you expensive technology).

Ideally, you'll find a security consultancy that is vendor-neutral. Ask them if they resell hardware and whether the company receives any income from such sales. If they do, my advice is to keep looking. This is exactly why my company doesn't resell hardware at all. We want to be completely neutral and be able to advise our clients strictly based on what is in their best interest. I don't want this to be a commercial about Pervasive Solutions - I just want to underscore that if you bring in a hardware reseller to audit your security, don't be surprised when their recommendations come back with six figures worth of equipment that is "mandatory".

Admittedly, this is a really high-level glance at this subject. The implications of the various Breach Notification Acts and Privacy Laws vary by state. But in the end, the message is clear - if you have a breach, you must publicly disclose it. Regardless of the hows and the direct costs, that type of disclosure can have such a detrimental impact on customer confidence that you really need to do everything you can to protect yourself. Get serious about security NOW.

If you have questions or would like my help, please feel free to give me a call or shoot me an email. I look forward to hearing from you.

Josh

Thursday, March 8, 2007

Welcome to Security & Compliance for the SMB...

Thanks for stopping by! This blog will be the home for advice, commentary and discussion regarding the information security and compliance landscape as it pertains to America's small and medium size businesses. I intend to discuss a wide variety of topics and hope that you will also contribute to the discussion.

Before we get started, a little about me...

I am a partner in the firm, Pervasive Solutions, LLC. Located in Rochester, NY, Pervasive Solutions provides information security and compliance services and solutions to the SMB world - particularly in the Healthcare, Banking/Financial Services, Legal and Government/Non-Profit industries. We are passionate about protecting our customers from the increasing threats that SMBs face and helping them find reasonable solutions to the mountain of legislation and regulation that seems to continue to proliferate.

Prior to joining Pervasive Solutions, I led several other organizations including a 300-person e-learning company and the strategic consulting division of an $800M publicly-traded enterprise. I also started a software company in 1999, but it wasn't exactly successful. :)

Over the last twelve years, my clients have included the largest of the large and the smallest of the small. But in the last few years, I continued to notice that while large companies were investing in protecting their businesses, systems and data, their smaller counterparts seemed oblivious to the very real threats to their businesses. As I would speak with these business leaders, it was clear - they ALWAYS fell into one of two camps:
  1. They didn't know that they needed protection and didn't understand the regulatory requirements facing them OR
  2. They didn't believe they were big enough to be a victim

Unfortunately, I also ran into business owner after business owner that had been burned by employee theft, data leakage and other such problems. Some lost their business. Some survived but experienced significant pain.

And thus, I jumped into security and compliance with two feet - my ultimate goal being to educate and protect as many small businesses as I can. I am a firm believer that the future of America is dependent upon a strong, innovative, growth-enabled SMB environment. But if they are going to succeed, they need to be protected and compliant. I hope this blog will help.

Josh