privacy

cloud data protection

Cloud Data Protection

The shift to the cloud.   It’s one of the IT world’s fastest growing trends. Cloud storage has brought about a revolution in data management, allowing enterprises to store and process large quantities of data without dealing with the costs … Read More

Insider Threats, preventing data exfiltration

The digital economy is undergoing remarkable transformation and security is being compelled to evolve as organizations embrace services that are more dynamic in nature. The things organizations do to grow, innovate, and drive performance change the cyber risk landscape every day.

Business leaders today are realizing that the digitalization is fundamentally enabling sharing of information across a multitude of platforms, not necessarily protecting it.  They recognize that they are essentially at the mercy of their own employees and third parties associated with them to handle crucial business sensitive information.

On the other hand, cyber security incidents, including breach and disclosure of intellectual property, customer data, other sensitive data (e.g., GDPR, PII, PHI, PCI), are increasingly pervasive in today’s business environment. Data is one of a organization’s most vital asset and the cyber risks associated with data is crucial for any organization.   According to a 2017 Insider Threat Report, out of all the potential cyber threats in the wild, insider threats is one of the most prevalent threats and associated incidents have risen due to economic conditions and insider access accorded to non-approved third parties.

So, fundamentally who is an insider threat? Any employee who has the potential to harm an organization for which they have inside knowledge or access. The past several years have seen some of the history’s most high-profile data breaches. The extent of data loss across the organization is incrementing year by year and so are the associated challenges in protecting the data.

The Ponemon Institute’s 2017 Cost of a Data Breach study estimates that in the US, the cost per record of a data breach is $201 per record (including many factors, direct and indirect).  Those costs jump to $215 per record in the case of malicious attacks, or incident involving third parties. Obviously, this can add up to hundreds of thousands, or millions, depending on the amount of sensitive data involved.

But what the various cost analyses of cyber incidents don’t take into account is that malicious attacks are increasingly aimed not at the theft of sensitive data, but the serious disruption of operations, the elimination of data, or theft of intellectual property or information that can permanently impact market share and competitive advantage.

Recent attacks demonstrate that we need to change the game

There are multiple types of insider incidents seen across industries. The GTB perspective is that organizations cannot succumb to thinking of themselves as passive victims of cyber crime. However, we need to take stock of the fact that, it is our own relentless leveraging of technology, which create gaps that cyber criminals exploit.

To manage the risks arising from internal threats from a cyber risk perspective, though, means that it has to be taken on as a business problem. Executives do not need to suddenly become cyber security experts, but need to lead the discussion with an emphasis on:

  1. Focus on risk mitigation versus compliance requirements: Many organizations are heavily focused on addressing audit and regulatory findings, but the solutions implemented often do not help reduce risk and address threats that the company faces.
  2. Build and maintain a comprehensive inventory of sensitive assets and data: Many organizations don’t know where their data is. It’s very difficult to appropriately protect data if you don’t know where it is collected, stored, used, and transferred both inside and outside the organization.
  3. Focus on implementing solutions to protect data and monitor for data loss at the “data layer”: Many organizations are not effectively implementing critical capabilities such as Data Loss Protection (DLP) solutions, encryption and database activity monitoring, among others. Building the capability to monitor systems, applications, people, and the outside environment to detect incidents more effectively.
  4. Consistently execute the security fundamentals: Many organizations are still not consistently executing fundamental data protection capabilities (e.g., patching, privileged access, asset management), which leaves sensitive data even more vulnerable.

This may require more investment, but it may also simply entail a new approach. The crux of that approach is to recognize that managing cyber risk must be an inherent aspect of growth and innovation strategies. The two cannot be separated.

How secure is your data?  Do you REALLY know? Find out now

DLP that Works Legal Defense Healthcare BA

Which DLP Solution are you using?

Which DLP Solution are you using? Sound familiar? Many organizations are now being required to discuss with their customers which DLP solution they have in place and how effective the solution is. Healthcare Organizations, Defense Contractors, Financial Firms and the like, are … Read More

ICO publishes International Strategy to help protect UK public’s personal information in a global environment

04 July 2017    Latest news from the  UK’s Information Commissioner’s Office (ICO) website

The ICO has published its first ever International Strategy to help it meet overseas data protection challenges including increased globalism, changing technology, GDPR and Brexit.

The strategy aims to enhance privacy protection for the UK public, no matter where in the world potential threats and risks emanate from. It also commits the ICO to learning about new ideas and developments emerging from other countries.

Elizabeth Denham, Information Commissioner, said:

“There is little doubt that there are challenging times ahead but we are well placed to tackle them. We have a powerful voice and it is heard around the world, but we are excellent listeners too. That is our strength.

“This blueprint for how we’ll deliver on our international objectives was informed by experts from all over the world who challenged our perceived priorities and advised on what our next steps should be.”

The strategy sets out what the ICO sees as its main international concerns over the next four years:

  • To operate as an effective and influential data protection authority at European level while the UK remains a member of the EU and when the UK has left the EU, or during any transitional period.
  • Maximising the ICO’s relevance and delivery against its objectives in an increasingly globalised world with rapid growth of online technologies.
  • Securing that UK data protection law and practice is a benchmark for high global standards.
  • Addressing the uncertainty of the legal protections for international data flows to and from the EU, and beyond, including adequacy.

To continue this article, go to https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/07/ico-publishes-international-strategy/

 

GTB The Leader

Europe hit by massive cyberattack

Europe hit by massive cyberattack By Associated Press June 27, 2017 | 11:20am | Updated “PARIS — A new and highly virulent outbreak of malicious data-scrambling software appears to be causing mass disruption across Europe, hitting Ukraine especially hard. Company and … Read More

Ohio governor’s website among government sites apparently hacked on Sunday

CLEVELAND, Ohio — The Ohio governor’s website was apparently hacked on Sunday, along with the state’s prison system’s website.

The official website for Ohio Gov. John Kasich showed the same message from the hacker on its homepage as did the Ohio Department of Rehabilitation and Corrections’ website.

Several other state government websites were also apparently hacked, including the websites for: Ohio First Lady Karen Kasich, the Office of Workforce Transformation, the Casino Control Commission, Medicaid, the Office of Health Transformation, the state Inspector General, the Office of Facilities and Construction Commission and LeanOhio.   **

**Click the article title to continue reading http://www.cleveland.com/metro/index.ssf/2017/06/ohio_governors_website_among_g.html