by Sean Steele

VA breach shows growing insider threats

Opinion
Jun 19, 20064 mins

VA example shows that inside risks are becoming more visible and damaging.

The recently disclosed theft of personal information on 26.5 million U.S. veterans and active-duty personnel from the home of a Department of Veterans Affairs analyst is a catastrophe that should have been anticipated and could have been avoided. The security risks posed by insiders are becoming more visible and damaging but are far from new.

Many executives in the federal government and corporate America remain ill equipped and unprepared to address the security threats posed by their trusted insiders. Security professionals continue to fight for each budget dollar allocated to safeguarding internal data, networks and systems. Private industry must reprioritize security and step up enforcement efforts for insiders. Congress must put teeth into its paper regulations and act quickly to strengthen consumers’ rights. We should all start by admitting insiders pose real security threats and need to be scrutinized as diligently as outsiders.

If 2005 was the Year of the Database Breach – more than 50 million personal records were lost or stolen – 2006 is shaping up to be the Year of the Insider Threat. The VA incident underscores how many organizations have given insiders unrestricted access to sensitive data. While organizations have spent billions of dollars building strong defenses to protect against outside attackers, the 2005 Computer Security Institute/FBI Computer Crime and Security Study found that insiders were responsible for nearly as many attacks.

In May 2005, Wachovia and Bank of America notified more than 100,000 customers after nine people, seven of whom were employees, were caught stealing and selling sensitive data about bank customers. But it’s not just the insiders-slash-thieves we should be concerned with; sometimes our best employees make mistakes in the name of improved productivity. A desire to work harder and better can lead to security breaches, as is likely the case with the VA analyst. Unfortunately, few organizations have implemented anything resembling reasonable insider security measures.

Human resource managers must move from focusing on employee retention and morale to holding employees accountable for cutting corners and jeopardizing security. The emergence of an employee-hiring blacklist in the financial services industry is a decisive if controversial move in this direction. The database is sponsored by BITS, a consortium of some of the largest U.S. financial institutions and lists employees at financial institutions who were fired because they deliberately caused financial damage or leaked sensitive customer data.

To make matters worse, the federal government isn’t enforcing industry data security regulations. Even though more than 19,000 complaints have been filed, not a single civil fine has been levied against the healthcare industry for violations of the Health Insurance Portability and Accountability Act. Congress must provide federal regulators with the necessary resources to police private companies. For example, although encryption is called for in numerous data security regulations governing the healthcare and financial services industries, very few organizations are taking basic steps to encrypt sensitive data that travels outside secure facilities on devices, laptops and portable hard drives. The VA could have mitigated or avoided the recent data breach with mandatory hard disk encryption.

Meanwhile, identity theft victims do not have the tools they need to discover or mitigate the damage done to them by the organizations that possess – and may lose – their personal data. Veterans and other individuals cannot easily place freezes on their credit accounts to stop potential thieves; only 17 states have freeze laws on the books.

Congress bears much of the blame for not moving aggressively to preempt state legislatures on this important issue. Likewise, the database-breach notification laws, which require companies to notify individuals whose information has been compromised, vary substantially from state to state. The California Security Breach Information Act requires organizations that maintain personal information to notify California residents if their information is compromised. Congress should extend this protection to all Americans regardless of where they live.

There are no quick fixes for managing insiders and their behavior, but Congress and private industry must do a better job.

Steele is a member of Virginia’s Joint Commission on Technology and Science, Privacy Advisory Committee, and co-founder of infoLock Technologies, an information security consulting firm. He can be reached at ssteele@infolocktech.com.