There have been a number of high profile data breaches by members of staff in organisations.
From the disgruntled Morrison's employee who leaked the salaries of staff onto the internet and was subsequently jailed for 8 years to the Tesco employee who was emailing details of customers to his personal email account and the Enterprise car rental employee who was selling customer information to a claims company, the main weaknesses in most organisations are the staff.
So what do you do about it? The cases shown above have been high profile and widely reported but organisations are probably suffering breaches on a regular basis and may not even be aware of them. We get used to what we see and do and so often we forgot to stand back and view the situation with fresh eyes.
When I start to work with organisations, I am that fresh pair of eyes. I often also represent your clients. Are you collecting information to help you communicate effectively with them? We can easily identify the areas in your business where there is potential for losing your business information.
If you want to find out more, we offer a free initial consultation so you can see how we would work with you. Contact us today to book a meeting.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Sunday, 3 April 2016
Monday, 28 March 2016
Do you have a strong password?
Recently the most used passwords were announced by Splashdata. You can follow the link to see the list - https://www.teamsid.com/worst-passwords-2015/.
The top three being password, 123456 and 12345678.
Passwords used to be simple 6-8 character words but with so many software packages able to crack simple passwords, we need to ensure that the most common source of security works for us. Here are some basic rules. At a recent security seminar, a speaker was suggesting that a password needed to be at least 25 characters long to be effective! (try remembering numerous 25 character passwords)
1. Make sure you use a password that is not linked to you personally, so no names, birthdates, addresses, pet names, children names, etc.
2. The best passwords are a mixture of lower case and upper case characters, numbers and symbols and should be at least 10 characters long.
3. The longer the password, the more difficult you make it for a hacker to access your information.
4. Make sure you have different passwords for different things. Your work passwords should be different from your personal ones.
5. Change passwords regularly, at least every three months and more regularly for sensitive information access. Work based computer systems can be set to prompt the change of password on a regular basis and this should be part of your password policy.
6. Do not write your passwords down on a sheet of paper or on a post it note stuck by the desk - I have been to a number of organisations where this was the case!
7. For businesses, do not share passwords between colleagues. Each member of staff should have their own individual login and you shouldn't share your passwords with someone else.
8. Do not use characters which are adjacent to each other on the keyboard. So no qwerty, zxcvbnm, etc.
9. One of the best ways to create a password is either to use a phrase, song lyric or opening sentence of a book.You could use the initials of the sentence instead of the whole sentence if you want, even better if you add punctuation as well.
10. If you are using your web browser to store your passwords for websites make sure you use the master password option, otherwise anyone who has access to your machine has access to all your passwords.
11.There are online security services which can help users safeguard passwords, these include LastPass, DashLane, and 1Password. These store passwords and user names in the cloud and are secured with a master password (make sure it is a strong password). Additionally, there are ones which will store passwords on your computer, these include Roboform, PasswordSafe or Keepass. If you can't remember the master password you are pretty much out of luck.
As your password is one of the key lines of security for your information, make it the best it can be.
The top three being password, 123456 and 12345678.
Passwords used to be simple 6-8 character words but with so many software packages able to crack simple passwords, we need to ensure that the most common source of security works for us. Here are some basic rules. At a recent security seminar, a speaker was suggesting that a password needed to be at least 25 characters long to be effective! (try remembering numerous 25 character passwords)
1. Make sure you use a password that is not linked to you personally, so no names, birthdates, addresses, pet names, children names, etc.
2. The best passwords are a mixture of lower case and upper case characters, numbers and symbols and should be at least 10 characters long.
3. The longer the password, the more difficult you make it for a hacker to access your information.
4. Make sure you have different passwords for different things. Your work passwords should be different from your personal ones.
5. Change passwords regularly, at least every three months and more regularly for sensitive information access. Work based computer systems can be set to prompt the change of password on a regular basis and this should be part of your password policy.
6. Do not write your passwords down on a sheet of paper or on a post it note stuck by the desk - I have been to a number of organisations where this was the case!
7. For businesses, do not share passwords between colleagues. Each member of staff should have their own individual login and you shouldn't share your passwords with someone else.
8. Do not use characters which are adjacent to each other on the keyboard. So no qwerty, zxcvbnm, etc.
9. One of the best ways to create a password is either to use a phrase, song lyric or opening sentence of a book.You could use the initials of the sentence instead of the whole sentence if you want, even better if you add punctuation as well.
10. If you are using your web browser to store your passwords for websites make sure you use the master password option, otherwise anyone who has access to your machine has access to all your passwords.
11.There are online security services which can help users safeguard passwords, these include LastPass, DashLane, and 1Password. These store passwords and user names in the cloud and are secured with a master password (make sure it is a strong password). Additionally, there are ones which will store passwords on your computer, these include Roboform, PasswordSafe or Keepass. If you can't remember the master password you are pretty much out of luck.
As your password is one of the key lines of security for your information, make it the best it can be.
Sunday, 28 February 2016
Bring your own device - and don’t lose data
Working from home and being able to take work out of the
office makes working life easier but can be a nightmare for data privacy. With
an estimated 56 per cent of employees reporting that they either very frequently
or frequently stored sensitive data on their laptops, smartphones, tablets, and
other mobile devices, the chances of confidential information getting lost or
into the wrong hands are very high.
Bring-Your-Own-Device (BYOD) is part of the modern workplace. It’s becoming more and more normal for business information to be stored in
or accessed by devices that are not fully controlled by IT administrators, and
the possibility of data breaches caused by personal devices that aren’t
properly protected is also on the rise.
Protecting business information on mobile devices can be as simple as
encrypting files and/or password protecting the device - it won’t stop them
being lost but IT admin will be able to selectively remove sensitive encrypted
data and the chances of someone using stolen information maliciously are
much smaller if it’s not possible to get straight into any files that may be
sensitive. The issue is clouded when the device actually belongs to the
employee and not the business, however.
Most businesses think nothing of allowing employees to use
their own devices to access email, office calendars and contacts, and a
strong BYOD policy is vital if company information is accessible on the go, via
personal devices.
Which devices are allowed?
It’s up to you to set the boundaries and specify what’s
acceptable. If you only want to support employees’ personal Android devices and
not iPhones or iPads, or vice versa, make that policy and stick to it.
Enforce strict security rules
People don’t like having complicated passwords and lock
screens - they get in the way of fast access to their devices and longer, more
effective passwords are also easier to forget. If they are using their own
mobile devices for work however, you can’t afford to leave them on a swipe and
go setting. If your staff members want to be able to use their own gadgets for
work too, they will just have to accept that they need to use a complex
password to access them.
Banning apps
This also applies to corporate devices - social media
browsing apps, email applications and VPNs or other remote-access software need
careful consideration when you’re formulating a data protection policy.
Although the devices are people’s own, they will have to consider business
needs if they want the convenience of using them for work, and that includes
not using apps or settings that could potentially compromise data security.
Businesses also need to consider what could happen if an
employee leaves the company - you will have to have an agreed policy in place
allowing you to remove any access tokens, e-mail, data and other access
permissions.
Does your organisation have a BYOD policy? Do you have
permission from your employees to delete information from their personal devices
remotely when they leave, or if it’s lost/stolen? What safeguards are in place
to ensure that staff don’t store sensitive information remotely? If you need
advice on setting BYOD policies that keep your sensitive data safe, contact me
and I will be delighted to provide you with guidance and advice.
Sunday, 7 February 2016
What's your score out of ten?
The ICO have recently issued an enforcement notice to the Alzheimers Society for various breaches of the Data Protection Act. There are 10 issues which the Alzheimers Society has six months to remedy. Although these need to be actioned by the Alzheimers Society, they apply to all businesses processing personal information. So here is the test, how many are you already doing?
1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?
2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.
3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.
4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?
5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.
6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.
7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?
8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.
9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.
10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.
So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?
1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?
2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.
3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.
4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?
5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.
6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.
7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?
8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.
9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.
10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.
So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?
Monday, 25 May 2015
How big is yours?
Your mailing list I mean.....
There is lots of talk of how big your mailing list is and this can be a wonderful addition to your business but only if you have collected the information in the right way. I have been talking to a couple of companies recently who are growing their mailing list by adding people to it, without asking their permission.
Generally they are people who have done business with the company before so have some history with them but the company didn't ask the individual if they wanted to receive further information. This usually boils down to a couple of reasons; the company thinks its OK to add people, they think the person might say no but they want the numbers on the list to increase or they didn't understand the benefits of asking the individual.
I would always advocate asking someone if they want to receive further information from you. Firstly it opens the discussion as to how staying in touch can help them keep informed of new events, etc. It also tells them that you will be adding them to a list and they can expect an email at some point in the future. Gives them something to look forward to! Also asking whether you can stay in touch indicates some thought for the persons privacy.
Finally it is always useful to show whether you intend to share the personal information with other companies, I always look to see, when I am providing my information, who it is going to be shared with. Lots of companies now state that they will not sell or share your information with other companies. (Good for them)
There is lots of talk of how big your mailing list is and this can be a wonderful addition to your business but only if you have collected the information in the right way. I have been talking to a couple of companies recently who are growing their mailing list by adding people to it, without asking their permission.
Generally they are people who have done business with the company before so have some history with them but the company didn't ask the individual if they wanted to receive further information. This usually boils down to a couple of reasons; the company thinks its OK to add people, they think the person might say no but they want the numbers on the list to increase or they didn't understand the benefits of asking the individual.
I would always advocate asking someone if they want to receive further information from you. Firstly it opens the discussion as to how staying in touch can help them keep informed of new events, etc. It also tells them that you will be adding them to a list and they can expect an email at some point in the future. Gives them something to look forward to! Also asking whether you can stay in touch indicates some thought for the persons privacy.
Finally it is always useful to show whether you intend to share the personal information with other companies, I always look to see, when I am providing my information, who it is going to be shared with. Lots of companies now state that they will not sell or share your information with other companies. (Good for them)
Sunday, 7 December 2014
Here's how to deal with an information security breach......
| We all hope that we will not be the subject of an informations ecurity breach but the chances are that all organisations will have a form of data breach at some time. Your effective response to an information Security Breach may have an impact on your company's public profile and the costs involved with the breach. |
|
|
|
|
|
|
|
|
|
Saturday, 11 October 2014
7 Lessons to be learned from the Swale Council Email disclosure
In the news this week Swale Council admit that they sent the email addresses of 2500 residents to other residents in an email. See the link for the newspaper report.
http://www.kentonline.co.uk/sittingbourne/news/council-may-face-action-over-24879/
This is an easy error to make if there is insufficient guidance or training around emails.
So here are our 7 top tips to stop you making the same costly mistake:
Who is checking the emails before the send button is being pushed? We all know how easy it is to make a mistake in an email and only realise just after you have sent it. My usual mistake is forgetting to attach a file.
Data breaches happen all the time, it is what you do as a result of one which will be of interest to the ICO.
If you would like to discuss any aspect of the above, please contact me at lesley@audit-and-risk.co.uk or give me a call on 07828 124588. I look forward to hearing from you.
http://www.kentonline.co.uk/sittingbourne/news/council-may-face-action-over-24879/
This is an easy error to make if there is insufficient guidance or training around emails.
So here are our 7 top tips to stop you making the same costly mistake:
- Who has access to your database?
Who is checking the emails before the send button is being pushed? We all know how easy it is to make a mistake in an email and only realise just after you have sent it. My usual mistake is forgetting to attach a file.
- What's your email policy?
- How often are staff reminded of the email protocols?
- Can you create controls in the email system which limit the number of addresses?
- What happens following the breach?
- Do I need to report the breach to the ICO?
Data breaches happen all the time, it is what you do as a result of one which will be of interest to the ICO.
If you would like to discuss any aspect of the above, please contact me at lesley@audit-and-risk.co.uk or give me a call on 07828 124588. I look forward to hearing from you.
Subscribe to:
Posts (Atom)

