Data Privacy Day report highlights need for encryption

Origin says Data Privacy Day report highlights need for encryption

Basingstoke, UK – Thursday, January 28, 2010, was international data privacy day and, says Origin Storage, the storage systems integration specialist, a report released to coincide with the campaign shows the need for best practices when it comes to digital data records.

"The research, from Iron Mountain, found that 77 per cent of companies have no established policies that cover electronic data records, even though the vast majority have them for physical databases," said Andy Cordial, Origin's managing director.

"This is an appalling indictment of the state of corporate data protection, but given the rash of regular news reports on firms leaking data, it is perhaps understandable," he added.

According to Cordial, whilst understandable, the faux pas that a company has failed to protect its data effectively is still unacceptable, both from a regulatory and legal approach.

And that, he explained, is before we get in to the morality of allowing your company's customer information to leak, and potentially be misused by the criminal community.

The message of - `thanks for buying from us, now we've leaked your data and it could cost you dearly' - is a pretty awful one, and one that will turn off customers from companies on a major scale, he went on to say.

The reputational damage, although not often reported on, is one that can really hit home on companies with a poor approach to encryption and data security generally, said Cordial.

"The good news is that researchers found that those firms with the strongest records management practices employed the most formal programmes governed by multi-disciplinary teams across the organisation," he said.

"This is what we are observing amongst our customers, namely that those firms that take a serious attitude towards encryption, using technology such as our Data Locker, to protect data on the move, are the most responsible when it comes to security policies," he added.

"And those that don't take a serious approach to the issue also tend to get hit by legal action and regulatory fines. But that's another story entirely."

For more on the Iron Mountain research: http://bit.ly/btKC54

For more on Origin Storage: http://www.originstorage.com

Source: Eskenzi PR Ltd

Rise in data breaches drives growth for Imperva

Imperva Experiences More Than 30% Growth in 2009

Data Security leader also posts biggest-ever Q4

Imperva, the market leader in data security, announced today that it achieved 30 percent growth in 2009 over 2008, finishing a strong fiscal year 2009 with the largest quarter in company history. Imperva increased its bookings in Q4 2009 nearly 30 percent over Q4 2008. The company's success is driven by significant success in global growth, increasing the customer count to more than 1000 enterprises.

“Imperva’s performance in 2009 highlights the high priority placed on data security during difficult economic times,” said VP of EMEA, Henk Jan Spanjaard. “Data breaches continue and organizations are looking for something fast and effective, which is what Imperva’s Securesphere provides. At a time when many companies—even security vendors—are struggling, I am glad that Imperva continues to thrive. The simplicity, comprehensive and effectiveness of our products make Imperva the market’s most attractive data security solution.”

The key highlights from 2009 include:

  • Imperva closed 2009 with more than a 30% growth rate over 2008.

  • Significant overseas growth:

  1. EMEA 59%

  2. APAC 28%

  • The appointments of Stree Naidu as VP of Asia Pacific-Japan, Henk Jan Spanjaard as VP of EMEA and Yaniv Shaya as VP of engineering.

New product capabilities:

  • The release of SecureSphere 7.0 and the introduction of the SecureSphere

  • Discovery and Assessment Server, which introduced integrated data risk management to Imperva’s leading Data Security product portfolio.

  • Improved insider threat protection that helped security professionals track, identify and block potentially malicious insider data theft.

  • Integration with WhiteHat Sentinel and other leading dynamic testing vendors so enterprises can immediately remediate discovered website vulnerabilities via a "virtual patch" without the need for development intervention.

  • A ground-breaking study on PCI best practices with the Ponemon Institute.

Imperva, the Data Security leader, enables a complete security lifecycle for business databases and the applications that use them. Over 4,500 of the world’s leading enterprises, government organizations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognized for its overall ease of management and deployment. For more information, visit www.imperva.com.

Source: Eskenzi PR Ltd

It Can Happen So Easily

by David Tomlinson, Managing Director
Data Encryption Systems

I noted on the BBC website on 12.01.2010 and across other news bulletins that the government has introduced new legislation enabling the Information Commissioner’s Office to issue fines of up to £500,000 for serious data security breaches.

This new rule is expected to come into force in the UK on 6th April 2010 and is a deterrent to try and stop employees from leaving laptops on trains or CDs in the back of taxis that contain sensitive public information after a number of very public and embarrassing high level incidents over the last couple of years.

It can happen so easily – and to anyone! Which I find ridiculous, because for as little money as it costs to install anti-virus software on your laptop, you can install encryption software and protect your organisation not only from a data breach but also against any backlash. It is irritating and upsetting enough when you lose a mobile phone or a laptop but devastating for some if you haven’t encrypted the data and your latest customer database and/or sales forecast ends up in the hands of the competition.

We’ve been in the encryption market for over 20 years and over this time we have witnessed all kinds of incidents and I would say that in most cases, in fact in almost every case, these breaches could have been prevented.

Technology is part of everyday life. Protecting your data and company confidential information should be a matter of course and part of an organisation’s daily routine – whether private or public sector. For under £50, a business user can purchase a DESlock+ licence, our data encryption software, and reinforce their security and personal liability.

About time I say! I applaud the Information Commissioner, Christopher Graham and concur with his press statement. Data encryption is now quick, easy to use, inexpensive and painless to implement – so if you have metaphorically been caught with your trousers down, and you’ve not taken adequate steps to protect your data – watch out! Not only will it be highly embarrassing but a hefty fine could be coming your way!

<>

British Tories aim for 100 Mbps broadband by 2017

Conservative party would "break up BT monopoly" or divert BBC license fee to fund “superfast” Internet infrastructure

by Michael Smith (Veshengro)

The British Conservative party has unveiled its plans to improve the country’s Internet infrastructure recently, underscoring the significance of Internet-related policy in the forthcoming general election.

Shadow Chancellor George Osborne told the BBC’s Andrew Marr Show that he believed the UK should become “the world leaders in superfast broadband” in order to stimulate economic growth.

“In the 19th century we built the railways; in the 20th century we built the motorways,” said Osborne. “In the 21st century, let's build the superfast broadband network. That will create hundreds of thousands of jobs for Britain.”

He criticized the government’s commitment, made in the Digital Britain report, to enable 2Mbps broadband connections throughout the UK by 2012. “They have a woefully poor ambition,” Osborne said. “We're talking about 100 megabits [per second], which is a big step forward for this country.”

Osborne said that the best way to achieve this would be “breaking up the BT monopoly… which holds back companies like Carphone Warehouse or Virgin”.

However, if market forces alone could not support the necessary investment, a Tory government might then use money saved by the BBC as a result of the switch to digital broadcasting infrastructure, due to be completed by 2012.

The Labour party said the Conservative party was simply “playing catch-up” to its own broadband plans.

BT is currently rolling out its Infinity service – based largely on fibre-to-the-cabinet (FTTC) technology – which allows download speeds of up to 40Mbps. The service will be available to only 4 million homes by the end of 2010, but the company says it will available to 40% of the population by 2012.

While Britain is still playing about speeds of more than 40Mbps are already common in use in countries such as Finland, even in the more rural areas and Finland is leading Europe, so it seems.

The Tories may be making nice noise, now that an election is in the offing but they have to win that one first and furthermore the question must be as to how this is to be paid for.

While in Finland there seem to be no huge charges for such speeds knowing how things work in Britain we can be more than sure that we would be paying at least a charge of a pound per Mbps per month.

Britain already has one of the most expensive broadband service in Europe with much lower speeds than the majority of of European Union countries, especially those in Scandinavia and the west.

I, for one, am not holding my breath as to such speeds at an affordable rate.

Neither am I holding my breath about the promises to have London and other towns and cities supplied with free WiFi broadband connections for all the residents and visitors. Chance would be a fine thing but I have given up believing in Santa and miracles some time ago.

© 2010

Top 10 Reasons the Firewall Guy's Hair is on Fire

The firewall is a mature technology, right? Then why do those who manage it feel like they're running a daycare overrun with little savages?

By Mark Desmond, Regional Manager, Tufin Technologies

Firewalls are a mature technology, right? Most companies have at least one, if not several. And since an established knowledge base exists to tap for issues and PCI DSS 1.1 and 1.2 are pretty clear cut, firewall management shouldn't be much of an issue, right? No one is going to suffer the brunt of managing the significant infrastructure change these regulations are bound to bring more than the security operations team, correct?

Well, not really.

If your friendly neighborhood firewall guy (or gal) rolls into work late on a Monday morning sleep deprived and grouchy, cut him some slack. Here are some of the most common-yet-nerve-sizzling firewall snafus that have kept many an admin on a Friday-to-Sunday diet of fast food and Red Bull:

10.) The Saturday-at-midnight policy update process didn't go exactly as planned and he spent the rest of the weekend sorting through a bloated rule base to find out exactly what went wrong, and it ended up to be a slight overlap of rule 847 (meaning, 847 rules deep into the rule base) with rule 73.

9.) The network firewall rule base(s) have become so bloated that likely erroneous, obsolete and overlapping (or "shadowed") rules have caused unneeded risk or degraded hardware performance due to unnecessary processing and hardware drain (Yes, rule bloat is a big enough issue it warrants two of the top-10 spots)

8.) Monday's firewall changes didn't work when the polices were pushed out on Saturday because someone else's changes offset his and he had no idea who might have been making changes, what the change was, or why they made it.

7.) The last firewall guy had his own way of managing changes that is virtually indecipherable to those of everyone else, with no reference to the original request or business unit. And before he quit last month he accidentally cut off access to a mission-critical application when making a change.

6.) Permissive rules (rules with "ANY" and "ACCEPT," or even better, "ANY ANY ACCEPT")? If you want to be on good terms with auditors, then get rid of these. Rest assured, the security implications will soon enough deem them unacceptable. That means rules will need to be more specific and precise – which could either be really good or really bad, depending on the size and nature of your existing base (see items 9 and 10).

5.) A user is requesting a change for a new rule, but the firewall guy can't tell if that traffic is already allowed, and has 30 other things to do so he simply adds the new rule with the intention of reviewing it later. Can you guess how the story ends?

4.) Process? Documentation? Authorization? Just how quickly does the CEO need network access?

3.) "You want a rule usage report for firewalls protecting the 50 Web servers in Sacramento? WHAT 50 Web servers in Sacramento?"

2.) "What do you mean the quarterly PCI reports are now MY responsibility?"

1.) It's 3 p.m. and his manager wants to know if all 200 firewalls (with at least 250 rules per firewall) from multiple vendors across six countries are in compliance with seven distinct regulations, two of which are regulations from different countries that contradict each other. And he wants to know by the end of the day.

Operations people are a noble lot. They deal first-hand with the never-ending network complexity, and because their triumphs are measured in disasters avoided, they are therefore rarely, if ever publicly acknowledged.

So, before you deny their request to attend Black Hat/DefCon this year, re-read this list for a reminder of how much they add to the organization. And then "Any, Any, Any, Accept" the request.

www.tufin.com

BridgeHead Software gives thumbs up to Sun/Oracle deal

Ashtead, UK – BridgeHead Software, the healthcare data management specialist, has welcomed news that Oracle's $7.4 billion take-over of software rival Sun Microsystems is set to go ahead after European regulators have given the green light on the deal.

"This really is excellent news for Healthcare providers as both Oracle and Sun have a focused Healthcare practice and complementary solutions in this vertical, and, of course, it goes without saying many of these clients and customers use our data archiving, back-up and recovery technology as part of these solutions," said Tony Cotterill, BridgeHead's chief executive.

"The deal - which was announced in April last year - will see the world's second largest software company gain access to Sun's hardware, as well as its Java/Solaris technologies. This will allow Oracle to further develop an end-to-end solution that rivals that of IBM and other major vendors," he said.

"Oracle's move is good news for our HEAT (Heterogeneous Enterprise Archive Topology) solution, which was developed in partnership with Sun, as it assures the continuing longevity of the technology, which supports seamless integration with PACS, HIS, and other medical records systems," he added.

According to Cotterill, the `plug and go' HEAT appliance automatically identifies the value of data and maps it to the appropriate Sun storage system.

Compared to Content Addressable Storage offerings, BridgeHead reports that - over the first five years of ownership - healthcare units such as hospitals and health centres can enjoy a 60 per cent reduction in total cost of ownership by deploying HEAT.

In addition, Cotterill explained, HEAT reduces cooling and power consumption requirements by up to 80 per cent, and allows hospitals to use up to 75 per cent less space for the same quantity of storage.

The good news about the effective merger deal, says Cotterill, is that it ensures continuity for Sun's various technologies, as well as enabling Oracle to expand its reach into healthcare, and compete head on with long-standing Healthcare Technology vendors such as HP and IBM.

This expansion, he said, will be further enabled by the expansion of Oracle's developer communities, who now have access to a much wider range of hardware and software technologies, including the HEAT technology, which was jointly developed by Sun and Bridgehead.

"Oracle has a healthy position in the North America healthcare IT sector, so having access to leading-edge technologies such as HEAT, will allow the company to expand into the international healthcare sector, driving forward with a combination of advanced technologies and access to Sun's comprehensive dealer sales and support channels," he said.

"For clients using Sun solutions, as well as companies developing solutions such as HEAT that support those solutions, this deal makes sound business sense. For that reason we fully support Oracle in its aims. This is a win-win-win situation for the two industry majors, their customers and professional companies like BridgeHead Software," he added.

For more on the Oracle/Sun deal: http://bit.ly/7UGady

For more on Bridgehead Software: http://www.bridgheadsoftware.com

For the latest news and views on Healthcare Data Management from BridgeHead Software follow their tweets at: www.twitter.com/BridgeHeadHDM

BridgeHead Software is a leading provider of Healthcare Data Management (HDM) software for healthcare institutions and is the world's leading provider of MEDITECH data protection, with over 300 hospital networks worldwide supporting more than 1000 individual hospitals. BridgeHead HDM combines backup, archive and recovery capabilities with seamless integration into specialized healthcare systems and applications commonly found in healthcare environments. Integrated systems include HCIS from MEDITECH, PACS systems from multiple vendors, Microsoft applications and leading storage systems such as Sun. BridgeHead Software HDM is storage and vendor agnostic, enabling HDM to work with a customer's current and future systems infrastructure.

Source: Omarketing

Fact, Fiction and the Internet

By David Harley BA CISSP FBCS CITP, Director of Malware Intelligence, ESET

In their simplest form, many social networking sites are not much more than online diaries. Whether you’re thinking of Bridget Jones or Adrian Mole, Alan Clark or Samuel Pepys, most of us realize that a diary is just someone’s personal view, and not a reliable source of indisputable information. Most of us except for financial institutions, that is, or so it appears.

In a recent blog post, security expert Roger Thompson related how an authentication check by his credit card company resulted in their asking him a question to verify his identity, using information publicly available. (As opposed to, or in addition to, the use of the sort of information we share with such institutions as “secret questions”, for instance.) The required answer in this case concerned the age of Roger’s daughter-in-law, to whom they referred to by her maiden name. The only public resource that Roger could think of that would connect the two of them is Facebook, though other commentators have pointed out that genealogy sites are used in identity checks too.

For a while now, some security researchers have advised people to be economical with the truth when using chatrooms, forums and social networking sites. Why would you give your true date of birth to a site that doesn’t need to know it, and can’t be trusted to keep it private? Is it a good idea to let all your facebook friends know you’re on holiday next week when you may not have met them all personally and can’t be sure how much of your information is available to their friends? If you must use your dog’s name as a password (you really shouldn’t be using names for passwords), talking about Fido on Facebook gives a determined attacker a good start along the password guessing route. How much easier is it to harvest information about a target when their place of birth or current home town is public knowledge?

In the security industry, we talk a lot about the dangers of social networking and sharing information that may be valuable to burglars and scammers, or even spies (if you happen to be married to the head of MI some-number-or-other). But it isn’t just about what you do, or information that you give away. Other people can give away information that impacts on you, like that photo of you next to Niagara Falls that your mate posts to his Facebook page, giving clear notice that you aren’t at home right now.

This latest revelation about how information posted to websites is being used (or misused) suggests a potential scenario where false information might actually be seen as more valid than true information, simply because it’s “publicly available” and your bank assumes that you – or someone within your social network – will never lie to a social networking site.

There is probably more misinformation than information in the online world, whether it’s deliberate deception, propaganda, fraud, well-meaning lack of comprehension, or just data that are no longer current. So any instance of an organization relying on the accuracy of data from a wider (more public) range of resources raises concerns about inaccuracy and perhaps even the deliberate poisoning of data. How can individuals keep track of and validate everything that is "known" about them when presumed-valid information is pulled from who knows where? More so, if the organization pulls that information long after it has supposedly already validated you as a customer.

While a bad guy who has access to all the information that a bank has may not need to change it in order to profit from it, there are several scenarios where he might want to. This might include hampering remediation; influencing the presentation of data he can write to even when he can't read it (a more common situation than one might think); and compromising public data as part of a social engineering attack. Not to mention where the objective is to actually block legitimate access to information as well as or instead of impersonation.

Regulation of data is nowhere near keeping up with the Internet age, and some of our legalist assumptions were outdated in the 19th century. The possibility of an organisation using one customer to validate (or invalidate) another poses more awkward ethical and practical issues than most of us have thought of. It might benefit us all to think for a moment about the long-term impact that our next Facebook update or tweet may have on ourselves or our friends, before we put fingers to keyboard or keypad...

ESET is exhibiting at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th – 29th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy of Infosecurity PR

<>