Safeguard Your Company Against A Data Breach

A data breach is when personal information isemployees. You local police department may also be a
collected, retained, accessed, used or disclosed ingood source for information on tactics being used by
ways which are not in accordance with the provisionsdata thieves.
of the enterprise's policies, applicable privacy laws orComputer vulnerabilities:
regulations.Remember that computers are rarely stolen for the
It doesn't matter if the data in question has been takencomputers themselves; it is the data that thieves are
from an improperly protected corporate network orafter. A flash drive can copy all of the important files
from memos which have been tossed in the recyclingfrom a computer and be smuggled out with ease.
bin rather than being shredded. If customer informationInstant Messaging (IM), email and wireless networks all
has been disseminated without customer knowledgepose hazards to your company's data security.
and consent, then there has been a data breach and inEncryption of sensitive files, cables to prevent
40 states, the law requires that the company mustcomputers from being easily stolen, disabling USB ports
notify every current and potential customer,on workstations and other computer security practices
employees and vendor of the incident. Whatcan help. But your security strategy should be
constitutes a violation of good data security practice?proactive, not reactive in order to best protect your
A file cabinet left unlocked in an accessible area whichcompany.
contains customer information, a credit application formIT managers know these and many other security
left out in the open, an after hours order by faxmeasures to follow but the threats in the IT field are
carrying personal information - all of these areever-changing. An outside computer and network
violations, as is a stolen computer or a lost flash drivesecurity specialist should be brought in to evaluate your
carrying unencrypted files; you get the idea. There aresecurity. Afterwards, the company management and
many other potential areas where a data breach couldIT manager work together to resolve any vulnerabilities
happen and it is your legal obligation as a businessfound.
owner both to keep this data secure and to makeNetwork vulnerabilities:
notifications if a breach should occur.Being able to have all of your computers communicate
There are many different ways which data thievesamongst each other, having remote access to certain
can use to get at your information and the smartermachines, network print and fax capabilities - all of
ones among them will attack from more than onethese have greatly increased workplace productivity
angle: the employees, the computers, the network,while they have at the same time brought many new
even the building. Each of these vulnerable areasthreats to corporate security. There are backdoors,
presents its own challengesopen ports and other threats which can mean the
The Building:unauthorized access of the data - your data. When
The security systems and procedures in place in youryou have a third party analysis of your computer
building form the first line of defense against datasecurity, this should always include your network.
thieves. Break-ins are a threat you face, as is a quickToday's technology makes it more important than
grab and run operation. Merchandise may be stolen asever that you stay on top of what goes in and out of
a cover for the theft of data. Security should beyour network. Your IT department and security
practiced both inside and outside the building, as 70%personnel should work closely together to ensure the
of data breaches are inside jobs.safety of your sensitive data.
The majority of business owners think about locks,Your IT and security departments working together
access codes, video surveillance, fences and perhapscan keep employees from using another's access
a night watchman. There are many other securitycode to get onto a network. IT can prevent logons by
measures which should be implemented to protectemployees who have already left the building. Video
from data breaches. The storage, transmission ofsurveillance and computer monitoring can be switched
documents has become very important as hason to find out who is accessing a computer. IT can
controlling access to them. Which files should bealso limit access to employees to certain times and
locked and who should be allowed to have thedays.
combinations to them, where they should be locatedWith the increasing sophistication of networks, special
and so on are all important concerns.tools are needed to watch for vulnerabilities in these
The transmission of documents by printers, copiers,vital systems. The value of bringing in outside security
faxes, email and downloads is another area where aspecialists to analyze your security measures cannot
data breach can happen. Secure fax rooms havebe overstated. These professionals can assist your IT
been established by some companies with onlystaff in finding breaches faster, as well as identifying
authorized personnel allowed to enter. Faxes can onlywhose prying eyes are looking at your files.
be printed after entering a security code. Clean deskVulnerabilities Conclusion:
policies are in place at other companies to ensure thatWhile I have been speaking of each area of
no sensitive documents are left unattended, especiallyvulnerability separately, security must be an overall
after hours.effort which aims to secure every part of your
Another important area of data security concernsbusiness. Each part of your security system should
document disposal. A lot of the companies who haveintegrate with the others. Data should be shared
recently gotten into trouble over data breaches andamongst these components.
fined by the FTC had their data compromised byThere is security which seems to be expensive and
improper disposal - e.g.; an employee left documents inwithout obvious value; however, if a breach occurs
the recycling bin rather than shredding or burning themthrough a lack of security, the company could be out
as per the National Association for Informationfar more money later.
Destruction (NAID) guidelines suggest. Most companiesHere are a few things to consider before rejecting a
need to place individual shredders throughout the officesecurity budget.
and/or have secured container for documents, which1. How much have you spent on marketing and
can then be handles by a document destructionadvertising to acquire your current customer base?
company. Having secured bins for documents is theAfter a breach you will lose 31% of your customers
best way of ensuring that they are used byovernight. So is the loss of 31% of your current sales
employees. It may be necessary to replace somegreater than the cost of implementing proper security
existing trash or recycling containers with thesemeasures?
document disposal bins.2. How much does your company spend in marketing
Employee vulnerabilities:efforts to attract new business? After a breach many
When I am at security briefings, I commonly hearprospects will simply stop taking your calls.
worst case scenarios and data breach horror stories.3. How much has management spent on branding and
For instance, stories about employees who havelaunching new products and services to remain
criminal records selling company data, janitors who arecompetitive in your sector? After a breach, new
actually thieves casing the location and more. Theseproduct releases will have to be put on hold as
sorts of cases do occur, but a lot of companies do notmanagement focuses on damage control and
have the time or resources to do comprehensivereestablishing trust with clients.
background checks on new hires and put intensiveThese and many more direct and indirect costs can
security measures in place. Employee training can bebe caused by a lapse in security is why the average
one of the most effective, yet easy to implementloss a company suffers after a data breach is $6.3
methods of preventing a data breach.million dollars.
We already know that 70% of data breaches areFinally, remember the five walk away points:
from the inside of the company - of these, half are1. Protect documents with locked cabinets and
due to negligence or carelessness by employees whoshredders.
have not been trained on security. Thieves can easily2. Have ongoing security training for all employees.
trick an untrained employee into handing over personal3. Bring in specialists to analyze corporate security.
information; especially new hires who are unaware of4. Lock down electronic data with encryption,
company procedures.authentication tokens and IT monitoring
There should be regular compulsory training sessions5. Integrate security departments with each other so
on security for every employee. The cost of lunch forthat information can be shared.
a meeting can prevent incidents causing your"May your data always be secure, and your identity be
company millions of dollars. Security experts can beyour own.
brought in to explain what to watch out for to your