* Security matters
endif; ?>AT&T recently acknowledged thieves stole a laptop containing unencrypted data on present and former employees. The laptop belonged not to an AT&T employee but to an employee of a third-party contractor doing work for AT&T.
Yikes. It’s bad enough when employees’ are working on laptops with unencrypted data but extend that practice to third-party firms and the situation gets even worse. Depending on how they back up or share their data, that information could be getting into even more unencrypted, insecure devices of unauthorized people.
AT&T isn’t alone in this scenario. It happens all the time to all types of companies. Many times, the individuals whose personal data was compromised don’t even know about it. Other times, they know, but have no details as to how it happened.
It reminds me of a time about eight months ago when I received a letter from my primary credit-card company stating it had evidence that my credit-card number and associated information may have been intercepted by unauthorized users. A few days later, I received a new credit card in the mail.
I kept thinking when or where I used my credit card irresponsibly. So I finally called Citibank to ask. (I mean, this was a card I used all the time for several years. I knew the number by heart. I had all my automatic payments attached to this card, etc. So it was no small task to change card numbers.) The Citibank representative explained that I did nothing wrong. Rather, Citibank was the culprit. I received little explanation as to what happened or how this happened, despite my badgering — only that Citibank had reason to believe someone may have gotten unauthorized access to thousands of customers’ personal data.
The growing virtual workplace will only continue to facilitate such problems — if IT staffs let it. With more people working at branch offices, home offices, airports, cabs, restaurants, and coffee shops, securing data on laptops and mobile devices is becoming more critical than ever. More than 90% of employees work away from headquarters, on average, and the number of branch locations is growing by 11% per year.
Productive remote employees need access to data — sometimes sensitive data. IT staffs — and those who fund security budgets — should make it standard practice to encrypt data, use VPNs, and deploy stringent authentication policies.
If a problem does occur, such as that with AT&T or Citibank, use it as leverage to improve the security policy. And most importantly, treat victims with the respect they deserve by providing truthful information about what happened, who is at fault, and how their personal data may be compromised. AT&T, for example, offered victims one year of free credit-monitoring service. That’s good start, but one year may not be enough to determine whether someone’s identity has been stolen.




