Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, 3 April 2016

Who is letting your organisation down?

There have been a number of high profile data breaches by members of staff in organisations.

From the disgruntled Morrison's employee who leaked the salaries of staff onto the internet and was subsequently jailed for 8 years to the Tesco employee who was emailing details of customers to his personal email account and the Enterprise car rental employee who was selling customer information to a claims company, the main weaknesses in most organisations are the staff.

So what do you do about it? The cases shown above have been high profile and widely reported but organisations are probably suffering breaches on a regular basis and may not even be aware of them. We get used to what we see and do and so often we forgot to stand back and view the situation with fresh eyes. 

When I start to work with organisations, I am that fresh pair of eyes. I often also represent your clients. Are you collecting information to help you communicate effectively with them? We can easily identify the areas in your business where there is potential for losing your business information.

If you want to find out  more, we offer a free initial consultation so you can see how we would work with you. Contact us today to book a meeting.

Monday, 28 March 2016

Do you have a strong password?

Recently the most used passwords were announced by Splashdata. You can follow the link to see the list - https://www.teamsid.com/worst-passwords-2015/.

The top three being password, 123456 and 12345678.

Passwords used to be simple 6-8 character words but with so many software packages able to crack simple passwords, we need to ensure that the most common source of security works for us. Here are some basic rules. At a recent security seminar, a speaker was suggesting that a password needed to be at least 25 characters long to be effective! (try remembering numerous 25 character passwords)

1. Make sure you use a password that is not linked to you personally, so no names, birthdates, addresses, pet names, children names, etc.

2. The best passwords are a mixture of lower case and upper case characters, numbers and symbols and should be at least 10 characters long.

3. The longer the password, the more difficult you make it for a hacker to access your information.

4. Make sure you have different passwords for different things. Your work passwords should be different from your personal ones.

5. Change passwords regularly, at least every three months and more regularly for sensitive information access. Work based computer systems can be set to prompt the change of password on a regular basis and this should be part of your password policy.

6. Do not write your passwords down on a sheet of paper or on a post it note stuck by the desk  - I have been to a number of organisations where this was the case!

7. For businesses, do not share passwords between colleagues. Each member of staff should have their own individual login and you shouldn't share your passwords with someone else.

8. Do not use characters which are adjacent to each other on the keyboard. So no qwerty, zxcvbnm, etc.

9. One of the best ways to create a password is either to use a phrase, song lyric or opening sentence of a book.You could use the initials of the sentence instead of the whole sentence if you want, even better if you add punctuation as well.

10. If you are using your web browser to store your passwords for websites make sure you use the master password option, otherwise anyone who has access to your machine has access to all your passwords.

11.There are online security services which can help users safeguard passwords, these include LastPass, DashLane, and 1Password. These store passwords and user names in the cloud and are secured with a master password (make sure it is a strong password). Additionally, there are ones which will store passwords on your computer, these include RoboformPasswordSafe or Keepass. If you can't remember the master password you are pretty much out of luck.

As your password is one of the key lines of security for your information, make it the best it can be.


Sunday, 28 February 2016

Bring your own device - and don’t lose data



Working from home and being able to take work out of the office makes working life easier but can be a nightmare for data privacy. With an estimated 56 per cent of employees reporting that they either very frequently or frequently stored sensitive data on their laptops, smartphones, tablets, and other mobile devices, the chances of confidential information getting lost or into the wrong hands are very high. 

Bring-Your-Own-Device (BYOD) is part of the modern workplace. It’s becoming more and more normal for business information to be stored in or accessed by devices that are not fully controlled by IT administrators, and the possibility of data breaches caused by personal devices that aren’t properly protected is also on the rise. 

Protecting business information on mobile devices can be as simple as encrypting files and/or password protecting the device - it won’t stop them being lost but IT admin will be able to selectively remove sensitive encrypted data and the chances of someone using stolen information maliciously are much smaller if it’s not possible to get straight into any files that may be sensitive. The issue is clouded when the device actually belongs to the employee and not the business, however.

Most businesses think nothing of allowing employees to use their own devices to access email, office calendars and contacts, and a strong BYOD policy is vital if company information is accessible on the go, via personal devices. 

Which devices are allowed?
It’s up to you to set the boundaries and specify what’s acceptable. If you only want to support employees’ personal Android devices and not iPhones or iPads, or vice versa, make that policy and stick to it. 

Enforce strict security rules
People don’t like having complicated passwords and lock screens - they get in the way of fast access to their devices and longer, more effective passwords are also easier to forget. If they are using their own mobile devices for work however, you can’t afford to leave them on a swipe and go setting. If your staff members want to be able to use their own gadgets for work too, they will just have to accept that they need to use a complex password to access them.

Banning apps
This also applies to corporate devices - social media browsing apps, email applications and VPNs or other remote-access software need careful consideration when you’re formulating a data protection policy. Although the devices are people’s own, they will have to consider business needs if they want the convenience of using them for work, and that includes not using apps or settings that could potentially compromise data security.

Businesses also need to consider what could happen if an employee leaves the company - you will have to have an agreed policy in place allowing you to remove any access tokens, e-mail, data and other access permissions.

Does your organisation have a BYOD policy? Do you have permission from your employees to delete information from their personal devices remotely when they leave, or if it’s lost/stolen? What safeguards are in place to ensure that staff don’t store sensitive information remotely? If you need advice on setting BYOD policies that keep your sensitive data safe, contact me and I will be delighted to provide you with guidance and advice.


Sunday, 7 February 2016

What's your score out of ten?

The ICO have recently issued an enforcement notice to the Alzheimers Society for various breaches of the Data Protection Act. There are 10 issues which the Alzheimers Society has six months to remedy. Although these need to be actioned by the Alzheimers Society, they apply to all businesses processing personal information. So here is the test, how many are you already doing?

1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?

2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.

3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.

4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?

5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.

6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.

7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?

8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.

9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.

10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.

So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?

Monday, 25 May 2015

How big is yours?

Your mailing list I mean.....

There is lots of talk of how big your mailing list is and this can be a wonderful addition to your business but only if you have collected the information in the right way. I have been talking to a couple of companies recently who are growing their mailing list by adding people to it, without asking their permission.

Generally they are people who have done business with the company before so have some history with them but the company didn't ask the individual if they wanted to receive further information. This usually boils down to a couple of reasons; the company thinks its OK to add people, they think the person might say no but they want the numbers on the list to increase or they didn't understand the benefits of asking the individual.

I would always advocate asking someone if they want to receive further information from you. Firstly it opens the discussion as to how staying in touch can help them keep informed of new events, etc. It also tells them that you will be adding them to a list and they can expect an email at some point in the future. Gives them something to look forward to! Also asking whether you can stay in touch indicates some thought for the persons privacy.

Finally it is always useful to show whether you intend to share the personal information with other companies, I always look to see, when I am providing my information, who it is going to be shared with. Lots of companies now state that they will not sell or share your information with other companies. (Good for them)


Sunday, 7 December 2014

Here's how to deal with an information security breach......

We all hope that we will not be the subject of an informations ecurity breach but the chances are that all organisations will have a form of data breach at some time. Your effective response to an information Security Breach may have an impact on your company's public profile and the costs involved with the breach.
  • Have a plan. Don't wait to have a security breach before deciding what you should be doing in the event of one. Have a strategy in place that you can bring into action as and when the breach occurs.
  • Avoid Panic. Whether you are CEO, CIO, or any other senior officer, an information security breach can be alarming, but you should not panic. Evaluate the situation and decide on a plan of action as you would with any other business problem.
  • Secure the System. Take appropriate steps to contain and control the breach, to prevent further unauthorised access to or use of the personal information. You should preserve records and any other evidence. If the breach involves a lost or stolen computer or other portable media, secure any back-up files that show the information contained in the compromised system. It is helpful to make a mirror image of the records on your computer system or perform a comprehensive backup to ensure the preservation of information.
  • Organise a Response Group. You should take steps to ensure that other key members of staff and board members are notified of the information breach. Decide on a group who can make decisions to deal with the breach. the team should comprise of people who have technical expertise to deal with the situation and also who understand the nature of the information which has been breached and can advise on the information which may have been compromised or is at risk.
  • Retain Outside Advice. Retain outside advisors who have relevant expertise to help you decide upon a strategy, manage an internal investigation and comply with any notice or regulatory requirements.
  • Engage a Computer Forensic Investigator. Enlist the services of a firm specialising in computer forensics, cyber-crime response, internal investigations, and the preservation, analysis and production of electronic data.
  • Notify the relevant authorities. This should include the Information Commissioners Office if the breach is severe enough. Other organisations may include your insurer and the police depending on the type of breach.
  • Plan a Media Response. Any company which has been the subject of an information security breach should consider how they are going to deal with the press enquiries which may result. A severe breach which results in an ICO investigation will bring an interest in t the organisations which may need professional media experts to handle effectively. Any public statement should be factually accurate but reassure customers, potential customers and staff.
  • Review Your Company’s Privacy and Data Security Policies. If your company has adopted written privacy or data protection policies, review them to assess the company’s compliance with those policies in the context of the incident. Any response to the incident should be consistent with your internal policies. Also consider whether additional staff training is required to enforce the correct procedures when dealing with personal information.
  • Check Your Insurance. Check your insurance policies and other policies for potential coverage. Take the steps necessary to ensure that you do not lose insurance coverage by failing to give the required notice to the insurer or to meet any other procedural requirements. Make sure that you understand the company’s indemnity obligations under contracts with any third party involved in the incident, such as a client or vendor.
If you need any help or advice, we would love to help. Please contact me for further information at ask@audit-and-risk.co.uk

Saturday, 11 October 2014

7 Lessons to be learned from the Swale Council Email disclosure

In the news this week Swale Council admit that they sent the email addresses of 2500 residents to other residents in an email. See the link for the newspaper report.

http://www.kentonline.co.uk/sittingbourne/news/council-may-face-action-over-24879/

This is an easy error to make if there is insufficient guidance or training around emails.

So here are our 7 top tips to stop you making the same costly mistake:

  • Who has access to your database?
One of the principles of the Data Protection Act is that the information should only be made available to those who need to see it.
  • Who has the final approval for emails being sent out to the mailing list?
Who is checking the emails before the send button is being pushed? We all know how easy it is to make a mistake in an email and only realise just after you have sent it. My usual mistake is forgetting to attach a file.
  • What's your email policy?
Does your email policy allow emails to be sent to large groups of people from your main system? If so there should be a practice in place which limits the number of addresses that any single email can be sent to. This will reduce the potential for error. This is different from emails being sent via a mailing package such as mail chimp because this would automatically ensure the security settings meet DP requirements. 
  • How often are staff reminded of the email protocols?
It's great to have a process in place but completely useless if the staff who might need to use it are unaware of it. In a large staff team, it is good practice to have regular training around data protection and this should include information around email protocols. Records of the training should be maintained, including the date and the names of the staff who attended.
  • Can you create controls in the email system which limit the number of addresses?
In larger organisations the IT system can sometimes be sophisticated enough to limit the number of addressees an email can be sent to. This is to stop emails being sent to large groups of people and considered spam.
  • What happens following the breach?
How you handle a breach will be considered as part of any ICO investigation. Depending on the type of breach, dictates the action to be taken. You should try to notify those whose information is affected of the details of the incident and provide advice where necessary on what will happen next and any action the individual may need to take. Ideally have a written plan as to what you will do in the event of a breach as this will save time when it happens and you won't need to think what you should be doing.
  • Do I need to report the breach to the ICO?
This depends on the extent and severity of the breach. How many people the information related to and what the information was. If it is the email addresses of 5 people then no you would not need to report it. If it is the health records of 5 people, then you would need to report it. At the time of a breach you need to seek advice to ensure that further breaches do not occur and ensure that the breach is dealt with professionally and effectively. 

Data breaches happen all the time, it is what you do as a result of one which will be of interest to the ICO.

If you would like to discuss any aspect of the above, please contact me at lesley@audit-and-risk.co.uk or give me a call on 07828 124588. I look forward to hearing from you.