Data breaches: Blame sloppy companies, not hackers
Researchers say organizational mismanagement causes 60% of breaches
By Network World staff
,
Network World
, 03/13/2007
- Share/Email
- Tweet This
- Print
Electronic records in the United States are streaming out of companies at a rate of 6 million a month this year, up roughly
200,000 a month from last year, according to a University of Washington researcher.
The researcher says organizations that accidentally expose their data are often to blame due to administrative errors, insider
abuse, stolen equipment and the like.
Phil Howard, an assistant professor of communication at the school, has reviewed major data breaches in the United States since
1980 and says that the 2 billionth personal record will become compromised sometime this year (that's about nine records per
U.S. adult). He and doctoral student Kris Erickson will publish a report on their findings in the July issue of the Journal
of Computer-Mediated Communication.
The research is based on media reports of breaches and the researchers said they suspect many incidents went unreported or
were underreported before a California law went into effect in 2003 that forced companies to fess up (the number of incidents
confirmed tripled in 2005 and 2006 compared with the previous 24 years).
About a third of 550 breaches were attributable to malicious hacks between 1980 and 2006, whereas 60% happened as a result
to organizational mismanagement, the study says. The rest were unspecified.
Universities have been hit hard by breaches, accounting for 30% of reported incidents. However, they account for less than
1% of lost records.
The researchers said they aren’t convinced that market forces, such as negative publicity generated by data breaches, will
necessarily curb the problem and suspect that more states will put regulations in place. (Read about the fine art of writing
a data-breach apology here.)
Some in the industry, such as Symantec, are pushing for federal regulation to address data breaches.
Check out Network World's Alpha Doggs blog for the latest in networking research at universities and other labs.
Comments (3)
The things I could have done if I'd been dishonestBy Anonymous on March 15, 2007, 3:01 pmI worked for a well-known east coast women's college. My department was part of a larger department called "Resources" that encompasssed all donor- and development-related...
Reply | Read entire comment
Data Security - Some ThoughtsBy GDoC63 on March 31, 2007, 6:33 pmAs the amount of information stored, about an increasing number of individuals by more and more corporate and government agencies, increases as well as the vectors...
Reply | Read entire comment
Data breaches: Blame sloppy companies, not hackersBy Anonymous on April 1, 2007, 7:36 amIsn't it time that the people who write the headlines are forced to read the article first? When the company is at fault, the company should be blamed, and when...
Reply | Read entire comment
View all comments