* No matter how strong your company’s security, it can’t always guard against human error
endif; ?>Just last week, the Alabama Department of Public Health, Butte Community Bank and Carolinas Medical Center reported data breaches. The incidents stemmed from a mailing error, a stolen laptop and a lost laptop.
No matter how strong your company’s security, it can’t always guard against human error. It’s imperative to have policy and train employees about proper IT security procedures. But the reality exists that a data intrusion is still probably going to happen to your organization, the only real question is when.
A recent survey shows that while the number of breaches may be reduced, the severity of them has worsened.
Surely by now with all the stolen or lost laptops you’d think organizations would start encrypting any personally identifiable data. Fortunately, the use of data encryption is on the rise, as reported in this Network World article.
Not only have most states passed data breach notification laws, but some such as Michigan’s really have teeth in them. A data security notification amendment to its Identity Theft Protection Act went into effect last July and states that employees responsible for knowingly and maliciously failing to report a breach to those affected can be fined up to $250 per breached record or an aggregate liability of up to $750,000.
Ohio recently punished one of its IT administrators for failing to come clean in a timely manner after a backup tape went missing. The tape contained hundreds of thousands of citizen records.
The state is suing its consulting firm and still dealing with the aftermath of that breach.
For some insight into the right way to recover from a data breach, take a lesson from Boston College, which reached out to graduates right away and took steps to fix the matter.
Editor’s note: Starting Tuesday, Nov, 20, this newsletter will be renamed “IT Leadership Alert.” Subscribers to the HTML version of this newsletter will notice some enhancements that will provide you with access to more resources relevant to IT leadership and management. You will still receive Amy Schurr’s analysis of this market, which you will be able to read in its entirety online at NetworkWorld.com, along with links to relevant news headlines of the day. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.




