Microsoft report shows decline in breaches caused by negligence
endif; ?>Lawmakers calling for open government have a saying that “sunlight is the greatest disinfectant,” arguing that when government has to disclose what it’s doing, voters can better hold it accountable. It seems the same holds true for disclosure of enterprise security breaches.
The latest Microsoft Security Intelligence Report, updated April 28, shows that as more states and other global jurisdictions adopt laws requiring enterprises to notify the public of security breaches, the number of breaches attributed to negligence has declined significantly. The report shows that the number of reported breaches attributed to negligence dropped to just 34 in the second half of 2009 from 110 in the first half of 2008. At the same time, the number of breaches attributed to “attacks,” such as hacking or installations of malware on a network, remained relatively constant over that same period at about 20 incidents.
Today, 46 states, the Distrtict of Columbia, Puerto Rico and the Virgin Islands have enacted disclosure laws of one kind or another. Prior to the enactment of disclosure laws, enterprises were reluctant to admit their networks had been breached because it would bring negatively publicity. Now they have no choice but to report a breach if there’s a possibility that personally identifiable information (PII) about their clients, customers or constituents has been compromised.
As a result of these laws, holders of PII have strengthened security by controlling data access privileges, hardening firewalls or encrypting more data. Under most laws, loss of encrypted data does not need to be reported as whomever has obtained the data likely can’t decrypt it.
The Microsoft report goes on to detail the variety of ways data can be lost or stolen, and many don’t involve hacking. They include: Lost or stolen equipment, such as a laptop left behind or stolen from a car; improper disposal of data in in either digital or paper form; an accidental release of information onto a Web site; fraud; release via e-mail or postal mail; and malware or other hacking. The number of each of these types of incidents declined from the first half of 2008 to the second half of 2009 as guardians of PII maintain better security in the physical and digital world.
While it’s encouraging that security has been improved by wider adoption of best practices by record keepers, the need for eternal vigilance remains. Patch Tuesday will still be celebrated each month. Not only are hackers continuing to develop new ways to break into networks, but rules to prevent breaches caused by negligence need to be maintained.




