Data security is not rocket science

An alarming number of data loss incidents continue to make news, despite the fact that multiple tools exist to address the problem

Written by Daniel Robinson

The rash of recent scandals involving loss of records from both government departments and commercial organisations has led many to question just how seriously the security of sensitive data is being taken. One can easily imagine the pressure now being put on various public bodies to tighten up their procedures ­ or else. But the incidents just keep coming and coming. One security web site, attrition.org, even keeps a list of major data exposure incidents, and it is a depressingly long one, at that.

Commentators have often focused blame on those individuals or employees that were handling the data when it was lost, such as the now infamous “junior official” blamed for sending out the UK’s entire child benefit records database on two CDs in an unregistered package last year. How could anyone be so stupid when handling such vital information, you might well ask.

But as IT Week pointed out at the time, these incidents reveal a systematic failure within some organisations to take security seriously and put appropriate measures in place. While it was phenomenally stupid to put sensitive personal information through the post, the question remains as to why a “junior official” was able to get unrestricted access to the entire data set in the first place, and why HM Revenue & Customs had not trained its staff in best practice when handling and processing such information.

With organisations now sensitised to the threat of data loss, there is perhaps a danger that there will be a backlash and that management will insist on a total clampdown on the movement of data and who has access. While this is right and proper in the HMRC case, where the information disclosed may expose millions of people to identity fraud, it would be a sad state of affairs if companies used this as an excuse not to allow employees to work from home, for example.

It’s not as if there aren’t tools on the market to secure data. Seagate’s hard drives with embedded encryption, for example, provide a reasonable level of protection against data on a laptop being exposed if it should be lost or stolen.

You could argue that encryption is still a bit of a black art ­ especially where public key infrastructure (PKI) is concerned ­ and that it is difficult to administer, but in a typical organisation, the number of staff that require such protection is likely to be relatively few.

And then there are tools that enable firms to enforce policy on removable storage, so that only authorised staff can copy files to USB Flash drives and the like. These products have been around for several years now, and are built into nearly every management suite of any significance, so why are they not used more widely by companies that could genuinely benefit from the technology?

This is only a guess, but I imagine that IT is often rather low on the list of priorities for departments like the HMRC, and proper security may have been seen as an expense they couldn’t afford. Sadly, as events such as the child benefit case and the more recent theft of a laptop stolen from the Ministry of Defence illustrate, harsh reality has a habit of proving otherwise.

Tags:

reader comments

related articles

security vault

Lock down your Macs, firms warned

Sophos threat report predicts hackers could target Macs and wi-fi enabled devices 22 Jan 2008

 

Research highlights continuing data loss fears

Deloitte report finds firms are underinvesting in security 11 Jan 2008

MPs make calls for stronger data controls

High profile incidents such as that at HMRC have lead to calls for stronger data legislation 03 Jan 2008

Interview : HMRC fiasco highlights need for PKI

OpenTrust chief executive David Terry explains why PKI may finally become ubiquitous 18 Dec 2007

HMRC scandal could hit ID card plans

The data loss scandal could knock confidence in the UK ID card scheme 22 Nov 2007

MoD launches inquiry into laptop theft

Parliamentary meeting reveals catalogue of errors 22 Jan 2008

MoD launches inquiry into laptop theft

Parliamentary meeting reveals catalogue of errors 22 Jan 2008

RAF loses data on 50,000 personnel

Records at risk after Royal Air Force security breach 29 Sep 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation