A case study in government waste.
endif; ?>Back in 2006 the Department of Veterans Affairs had one of the “mothers of all data breaches.” A laptop was stolen that contained 26.5 million records of confidential and/or personally identifiable information (PII). Among the data stolen were the records of over 1 million military members. Of course, this kind of incident attracts headlines like moths to the flame. With all of the bad publicity it was not long until the VA announced that it was buying encryption software to encrypt all data stored on VA computers. They initially bought 300,000 licenses of Guardian Edge encryption software and another 100,000 licenses a few years later. Now, six years on an OIG report says only about 16% of those licenses have ever been used and over 84% of the VA computers don’t use the encryption software. What went wrong here?
For those of us who deal in the federal marketplace, we unfortunately hear stories like this all too often. The Fed market is a world unto itself, as big or bigger than any Fortune 100, but with a whole different set of rules and ways of doing business. But that is not an excuse for wasting $5 million and, beyond that, leaving the department open to another embarrassing and costly data loss.
This is a text-book case that those in both private and public sectors can learn from. In the heat of the moment the VA felt that it had to do something to “stop the bleeding.” Buying the initial 300,000 licenses for almost $4 million showed that the VA was doing something about this problem. However, it appears that the licenses were bought without adequate testing to see if they were compatible with the VA’s computers. There was not a real implementation and support plan developed. Rumors and whispers persist that the software does not work on some of the department’s computers and there really is at this point a real plan to roll out the majority of the licenses.
I spoke with my friend Gal Shpantzer, a DC-based security consultant. Gal tells me that in speaking to some folks he knows, they estimate that the cost to “do encryption right” with full support and resources is estimated at about $80 million across the VA for the lifetime of the project (since 2006, which is now estimated to be completed by September 30, 2013). Of course, this is a much bigger price tag than the $5 million the VA has already spent for 400,000 licenses in total.
Shpantzer says, “based on the pricing in the VA’s own OIG report [PDF], the VA got a great deal on the software licenses from Guardian Edge, back in 2006. Also in the report are major compatibility issues with the encryption software, which indicates a potential lack of proper testing, pre-purchase and certainly pre-deployment. There was also a missing technical personnel capacity for properly deploying the software. My motto for full-disk encryption success is a twist on the old real estate quip: ‘Pre-deployment, pre-deployment, pre-deployment.”
Without spending the money, though, those licenses will sit on the shelf and collect dust, while the data on the endpoints remains unencrypted. Again, a situation not unheard of in the infosec community. As a matter of fact, this kind of thing is exactly what Gal helps both private and public sector clients with. Gal says, “In some cases, starting small, with a targeted set of ‘high-risk’ laptops and desktops, is a better way to go than an emergency purchase of a site license, especially if you haven’t gone through some of the compatibility testing,” Shpantzer noted. “A well-planned full-disk encryption project shouldn’t drag on this long, so it’s good to see the OIG on the case and that the VA is committing to getting this right.”
Now don’t get me wrong. In the big picture of government spending, $5 million is not even a drop in the bucket. But if you count your pennies, your dollars take care of themselves. More importantly, the next data loss and breach may wind up costing us a lot more than $5 million. The lesson to be learned here is don’t rush out and buy the software until you understand how you are going to use it.




