Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, September 22, 2011

Thomson Reuters Survey Shows Most Corporate Board Correspondence Easily Hacked

A global survey of corporate boards published yesterday by Thomson Reuters concludes that most boards are transparent to the lowest level of hacking efforts. According to the survey, published through Thomson Reuters' London office:

Most major corporations surveyed have significant security gaps that leave sensitive board-level information open to information theft and hacking. Those are among the findings of a new survey of board members of UK and global corporations conducted by Thomson Reuters Governance, Risk & Compliance. The findings are particularly noteworthy in light of recent news stories about the handling of board communications involving executive succession decisions at companies including Yahoo and Apple.

The survey found that information provided to members of corporate boards of directors is often in unencrypted email accounts and computers, or otherwise provided in forms that are easily lost, misplaced or stolen. The Thomson Reuters Governance, Risk & Compliance survey polled general counsel and board members at leading global corporations across a wide variety of industries.

Unencrypted board communications

85%

Board documents stored on personal computers at home or work

79%

Board documents stored on personal mobile devices
(e.g., iPad, laptop, smartphone, etc.)

75%

Documents sent to board members via personal, non-commercial email addresses

73%

Board documents accessible via wi-fi or unsecured networks

71%

Have reported computer, mobile devices, or sensitive company documents
lost, stolen or left in public places

10%

Friday, August 5, 2011

Law Firms Face Prospect for Public Admission of Wholesale Violations of Client Privilege

With SB 24 likely to pass in California, companies incurring a data breach with clients in the state will now be required to place the breach on record with the State’s Attorney General’s Office. For the law firm, it turns out to be more than a public embarrassment.

Consider that according to privacy advocate and attorney Mari Frank, Esq., law firms are often primary data sources for identity theft. The result is that, that while haughty law firms may have actually been data sieves in the past, a formal admission of a data breach opens a firm to threat of civil litigation for violating client privilege. The threshold for AGO breach reporting is loss of 500 client records. What appears unsure is whether exceeding that threshold creates a requirement to public admission by law firms of wholesale violation of client privilege.

On the high side, encryption of a firm’s files exempt it from the AGO reporting requirement.

Even as the change brings the California law more in line with other states, data breach fines have already begun to mount in places like Massachusetts, while the Federal legislative effort this past month has been likened to herding cats.

Already through legislative committee in California, SB 24 is widely expected to be approved by the full legislature and signed into law by Governor Gerry Brown before October 9th of this year.

Looks like perfect timing: Chief of the California Office of Privacy Protection Joanne McNabb will present on the impact of SB 24 in a webinar sponsored by the California Webinar Law Journal on Oct. 20th. McNabb will discuss drivers to the changing status of the California Data Privacy Law and best practices for law firm client privacy. The event is open for members of the California State Bar for continuing legal education credit and free to law school staff and students. See here for registration details.

Thursday, July 28, 2011

Game Changing Software Cracks Servers in 15 Minutes

Consider that the Russian firm Elcomsoft has developed what they dub ‘password recovery assistance' software that with a single beefed-up PC can accelerate a brute force or rainbow password attack routine by up to 20,000 times. At this level of brute-force attack, according to reporting in InfoSecurity, it only takes around 15 minutes to crack an admin password on a typical server. So when did Elcomsoft release this game changing approach? Answer: 2009.

Keep all that in mind and consider that earlier this year, cloud security firm, Trend Micro, commissioned a survey of 1200 enterprise IT decision makers (in the U.S., UK, Germany, India, Canada and Japan) and found that 43% experienced security lapses in the cloud within the last 12 months. 10% of respondents had active cloud based projects in production, nearly half had cloud based projects in the works. But the same survey, according to InfoSecurity, forecasts a 5X growth in cloud computing over the next few years. Trend Micro produces security software designed for cloud server management to prevent data theft, business disruptions, and compliance violations with server security for virtualized datacenters. Conclusion: either the cloud will need this new level of security software, or it's already out of date.