Data breaches are all around us

Opinion
Mar 6, 20072 mins

* There is a critical need to automatically monitor outbound e-mail communications for sensitive information

The Privacy Rights Clearinghouse recorded 586 publicized breaches of sensitive data between January 10, 2005 and February 19, 2007 affecting 104.1 million records. This amounts to an average of 5.3 breaches per week, or the compromise of 135,152 records every day. These breaches occur because of things like laptops that get lost or stolen, personal information that inadvertently gets posted on a Web site, hackers breaking into servers and so forth.

While most of the breaches cited by the Privacy Rights Clearinghouse do not involve e-mail breaches, many of them do. For example:

* In March 2006, the Connecticut Technical High School System inadvertently sent the Social Security numbers for 1,250 faculty and students through e-mail.

* The New York City Department of Homeless Services mistakenly sent personal information on 8,400 homeless people to a variety of people through e-mail.

* The University of Virginia at Charlottesville sent e-mails to a number of students that contained the Social Security numbers of 632 of their fellow students.

What this points out is the critical need to automatically monitor outbound e-mail communications to look for things like Social Security numbers, credit card numbers, competitors’ names, any of a variety of keywords that might be important to monitor and the context in which certain words are used. The goal of such monitoring is to automatically encrypt sensitive outbound content, pop up a message to the sender asking him or her to double check the content or route the content to a supervisor or compliance officer.

The vast majority of employees who send confidential information through e-mail in clear text rarely do so with malicious intent – instead, they do so because they forget a particular corporate policy, they are rushing to meet a deadline or they simply forget to scan an e-mail for sensitive content. Employees can also reply to or forward a message that contains a long thread of content that they did not create and that might contain sensitive information.

I’ll examine a specific example of the critical need for these kinds of systems in my next article.