Home > Security News > Data breach discovery, disclosure outpaces 2007
Security News:
EMAIL THIS

Data breach discovery, disclosure outpaces 2007

By Robert Westervelt, News Editor
26 Aug 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The number of data breaches reported in 2008 has surpassed those reported in 2007, according to the Identity Theft Resource Center (ITRC), a non-profit organization tracking the statistics.

Data breach news:
Data breach laws have no effect on prevention, researchers say: Researchers at Carnegie Mellon University say there is no evidence that breach notification laws prevent identity theft, but they may have other benefits.

The pros and cons of data breach insurance: The security incident at the Hannaford supermarket chain and elsewhere have some wondering if it's time to purchase data breach insurance. But experts say there are drawbacks.

PCI DSS 1.2 clarifies wireless, antivirus use Version 1.2 of PCI DSS, due out in October, requires 802.1x for wireless protection and antivirus for all operating systems, according to a summary of the changes issued Tuesday.

ITRC, an organization that tracks data breaches and educates consumers about identity protection, said its 2008 breach list surpassed the total of 446 reported in 2007. The number of data breaches the group has logged in 2008 stood at 449. The ITRC, established in 1999, has been tracking data breaches for three years and helps resolve identity theft cases.

The organization said the number of breaches in 2008 is likely much higher since breaches that affect multiple companies are listed as single events. In one case, a single breach event affected customers and employees of at least 20 companies.

"Those companies become victims of the breach as much as the individuals whose information has been affected," said Linda Foley, founder of the ITRC. "In many cases they entrusted a vendor to provide a service to safeguard information at the highest level, and when they transport it from one place to another unencrypted, they're not taking it to the highest level."

Companies need to have a better understanding of the contractual obligations of the firm they outsource payroll and other processes to, Foley said. Firms also need to cut back on the data they send to outsourcers, limiting the potential of a breach.

The number of compromised records is estimated at 22 million, according to the organization. Foley said the growth in the number of breaches from year to year can no longer only be attributed to required reporting laws and media investigative work. Currently 44 states have laws requiring notification of a data security breach. Since each state has its own law requiring notification, companies are not held to one consistent standard to report a breach. Some states are adding language to the law, making it a requirement to provide public notification of the breach notification letters issued to customers, Foley said.

"It's not to point fingers at companies," Foley said. "We want to look at this material so we can see whether there are ways companies and consumers can reduce exposure of information."

SearchSecurity radio:

While breach laws are seen as a way to shine a light on corporate neglect of security, a team of researchers from Carnegie Mellon University found they have no effect on preventing identity theft. The researchers said current breach laws are problematic because they leave any action, such as canceling a credit card, up to the consumer.

The ITRC is also in the business of selling breach notification services to companies who experience a breach. Foley said the ITRC's breach response program provides a consultant to the company to advise them on an appropriate breach notification letter and first responder calls. In many cases, Foley said analysis of breaches has shown that most people who receive a notification letter will not become a victim as a result of that particular breach. Credit monitoring services are not always the answer for consumers, she said. In many cases, if a Social Security number was not breached the customer only needs to cancel their credit card.

"People overreact and I think companies are not always giving sufficient information to make good choices because this is a topic that is not necessarily taught in law school," Foley said.



Tags: Identity Theft and Data Security BreachesData Privacy and ProtectionPCI Data Security StandardVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Identity Theft and Data Security Breaches
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy

Data Privacy and Protection
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Data Privacy and Protection Research

PCI Data Security Standard
PCI DSS compliance help: Using frameworks, technology to aid efforts
Chip and PIN adoption
Chip and PIN adoption serves lesson for U.S. payment industry
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Wireless network guidelines for PCI DSS compliance
Visa probes tokens, encryption for PCI card data protection
Feds push cybersecurity jobs, PCI DSS changes ahead.
Voltage, RSA spar over tokenization, data protection

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts