How PDAs Are Hacked, and How to Protect Them
exposed due to security breaches since February 2005. Since then, controls have been put into place to ensure that individuals are notified if a company has a security breach and if customer data has been compromised. (The specifics of the laws are discussed in the sidebar, Data-Breach Disclosure Laws. ) This is definitely a good thing for those whose data has been disclosed. The costs to the company responsible for the disclosure, however, can easily be in the millions of dollars.
The ChoicePoint incident prompted a slew of legislation designed to protect users whose data has become disclosed. California led the way and many states have followed suit. Let s look at some of the important parts of the groundbreaking California law and correlate those to PDA use. The California Law on Notice of Security Breach falls under California Civil Code Sections 1798.29, 1798.82, and 1798.84. This California law identifies a security breach as Unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information Specifically, this data includes the following: Unencrypted computerized data including certain personal information Personal information that triggers the notices requirements includes name plus any of the following: Social Security number Driver s license or California Identification Card number Financial account number, credit or debit card number (along with any PIN or other access code where required for access to account) Per the law, notice must be given to any data subjects who are California residents in the most expedient time possible and without unreasonable delay. Keep in mind that this is California s law, but many other states have very similar laws, as well. One of the key items to note in this synopsis is the use of the word unencrypted. This implies that encrypted data would not require that a notification be sent out. This makes sense and enterprises can relatively easily protect themselves by ensuring that all data that leaves their premises is encrypted. Sounds like a silver bullet, but some enterprises still don t understand that data needs to be controlled and that encryption must be enforced technically when copied to external sources, including PDAs. Companies are setting themselves up for failure if they are apathetic about the problem. It s really just a matter of time before they get hit.
Protecting Your PC and LAN from PDAs
A company that has a sensitive data-related security breach can expect to lose money associated with the following costs:
Retribution for harm done to individuals because the data was compromised. Loss of customers who will no longer do business with the company. Loss of potential customers who will not do business with the company because of fear of another data breach. Lawyers and legal fees. Fees associated with notifying users that their data was compromised. The cost of sending letters in the mail alone can easily be in the millions. Drop in the stock price as a result of the breach becoming publicized.
The costs of data breaches are staggering, especially considering that the comparative cost of prevention is so affordable. A notable publication by The Ponemon Institute, PGP Corporation, and Vontu, Inc. provides an in-depth analysis of the costs associated with data breaches. The document, 2006 Annual Study: Cost of a Data Breach (available at research_reports/ponemon_reg_direct.html) is an excellent resource for additional information. According to the researchers, it summarizes the actual costs incurred by 31 organizations that lost confidential customer information and had a regulatory requirement to publicly notify affected individuals. I highly encourage you to review this document. The State of California Office of Privacy Protection offers the following advice to companies in regards to safeguarding data: Pay particular attention to protecting higher-risk personal information on laptops and other portable computers and storage devices.
Restrict the number of people who are permitted to carry such information on portable devices. Consider procedures such as cabling PCs to desks or prohibiting the downloading of higher-risk personal information from servers onto PCs or laptops. Use encryption to protect higher-risk personal information on portable computers and devices.
The threat to enterprises isn t limited to customer data. Every enterprise has sensitive information (sales and pricing information, trade secrets, and so on) that would be costly if disclosed. All of this information needs to be controlled and encrypted.
