Home > Security News > Be afraid of the catastrophic data breach
Security News:
EMAIL THIS

Be afraid of the catastrophic data breach

By Ed Parry, Contributor
01 Dec 2005 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Data breaches seem to be getting more common, and soon they could get more costly. At least one security analyst predicts that a breach will bankrupt a high-profile company.

Bank of America Corp., CardSystems Inc., ChoicePoint Inc., LexisNexis Group and TransUnion LLC represent just a handful of the most recent victims bitten by the breach bug. But the lessons these high-profile companies are learning about customer data security may not be motivating other firms to secure their systems.

Many companies have not spent enough money on protection, according to Jon Oltsik, senior analyst with Enterprise Strategy Group in Milford, Mass. "They're playing catch-up now, but some say they will just live with the risk," he said. "Some old-school types can't justify the return on their investment."

Oltsik believes this ROI-based resistance will mean a new chapter in data security -- Chapter 11. He believes that a data breach will drive a large public company into bankruptcy within the next couple of years. "It's only going to get worse," he warned.

As further proof, a recent Ponemon Institute survey of 9,000 people found that 12% of respondents had been notified of a data breach or loss by a company with which they did business. Of those affected, 20% said they immediately stopped doing business with the companies that couldn't keep their data secure.

Costly consequences
CardSystems and ChoicePoint already have paid heavy prices for their breaches. Visa and American Express both dropped CardSystems after the Atlanta-based payment processor was hacked last summer, exposing more than 40 million credit card numbers.

"CardSystems' entire business viability is threatened," said Jonathan Penn, an analyst with Cambridge, Mass.-based Forrester Research Inc.

ChoicePoint took a $6 million charge in June after ID thieves duped the company into releasing personal data, exposing the information of as many as 162,000 Americans. The Alpharetta, Ga.-based data firm spent nearly $2 million contacting affected customers and offering them credit reports and monitoring services. ChoicePoint also saw its stock price fall after the breach and now faces a possible class action lawsuit.

The cost of disclosure, notification and the offer of credit monitoring services to affected users or customers after a breach can really add up. Penn said that the general rule is $15 per customer. "If it's a financial firm and credit cards are involved, that's an additional $35 for credit card replacement."

Chicago-based TransUnion suffered a breach in October when someone broke into a California sales office and stole a computer that might have contained credit information on approximately 3,600 customers. According to a statement, the company set up a toll-free hotline for affected consumers, let them request a free copy of their credit report from all three nationwide credit bureaus and gave them a free year of credit monitoring on all three credit reporting files. The company did not put a price tag on the damage control.

Millions affected

Data breaches in 2005 and people estimated to be affected.

Companies People affected
CardSystems 40 million
CitiFinancial 3.9 million
DSW/Retail Ventures 1.3 million
BofA 1.2 million
BofA, Wachovia, PNC Financial and Commerce Bancorp 676,000
Time Warner 600,000
Georgia DMV 465,000
Ameritrade 200,000
ChoicePoint 162,000
Boeing 161,000

Source: Privacy Rights Clearinghouse

TransUnion claimed that there was no indication of any fraudulent activity as a result of the burglary. According to company officials, identity theft is not a given after a breach.

"There is often a misconception that a compromise means identity theft is right around the corner," said Tim Keller, TransUnion's director of fraud and identity management solutions. "Many times, there's no evidence that information has fallen into the wrong hands – the key is to communicate with customers and address their concerns."

Lessons learned
Some 300,000 compromised passwords at LexisNexis were costly, but in the end might actually benefit the company.

While the Dayton, Ohio-based information company paid for a notification program and credit management consumer services, company officials did learn a valuable lesson.

"It brought home to us that customers needed to be more vigilant about their password protections," said Judi Schultz, the company's senior PR manager. The company now requires customers to change their passwords every 90 days.

Similarly, Bank of America, which lost backup tapes containing data on 1.2 million federal employees earlier this year and fell victim (along with several other banks) to dishonest insiders, has implemented a security program called SiteKey on its Web site. Intended to provide an additional authentication layer, customers are told not to enter their password unless they either see a specific image and message, or answer a series of confirmation questions.

Beyond financial and reputational consequences, data breaches undermine the public's confidence in online shopping and banking. Oltsik said even if a person's identity isn't stolen, he still pays in terms of privacy regulation, lost time, lost confidence and increased feelings of insecurity, all of which are proxies for money,. But he does believe that by and large, security in the digital age is coming around.

"We were so gaga over Internet connectivity over the years that we forgot we were making it easier to steal information," he said. "Now we're catching up."

Tags: Web Authentication and Access ControlData Privacy and ProtectionPassword Management and PolicyVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Web Authentication and Access Control
Group to shed light on secure identity management threats
IT business justification to limit network access
How to confirm the receipt of an email with security protocols
Schneier-Ranum Face-Off: Is Perfect Access Control Possible?
Kaminsky reveals key flaws in X.509 SSL certificates at Black Hat
Changing times for identity management
How to use single sign-on for Web access control to prevent malware
IBM USB banking device stops keyloggers, malware
Can mutual authentication beat phishing or man-in-the-middle attacks?
Could someone place a rootkit on an internal network through a router?

Data Privacy and Protection
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Data Privacy and Protection Research

Password Management and Policy
Microsoft, security firms warn of password meltdown
Two-factor authentication, vigilance foil password theft
Group to shed light on secure identity management threats
Prevent password cracking with password management strategies
Brute force attacks target Yahoo email accounts
Best Identity and Access Management Products
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
How to prevent brute force webmail attacks
Best practices for a privileged access policy to secure user accounts

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
access log  (SearchSecurity.com)
anonymous Web surfing  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
identity chaos  (SearchSecurity.com)
knowledge-based authentication  (SearchSecurity.com)
multifactor authentication (MFA)  (SearchSecurity.com)
walled garden  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts