Last Wednesday in security hell - Silicon Valley Sleuth

Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from V3.co.uk





Other blogs
Download Junkie
Your daily dose of download discussion

IT Sneak
V3.co.uk's under cover reporter offers odds and ends from the odd end of the technology

Mac Inspector
Drills to the core of the latest Mac rumours and news

Security Watchdog
Sniffing out IT security issues

The Frontline
Insight into the latest tech news from V3.co.uk's team of reporters

V3.co.uk Labs
The latest UK business technology: quick reviews and first impressions




« Be nice to your sysadmin for one day | Main | Getting all mixed up about open source ideals »

Last Wednesday in security hell

Good news if you work for Armstrong World Industries, a manufacturer of floors, ceilings and cabinets. The company in 2005 achieved revenues of $4bn, but didn't feel the need to invest any money in a decent security policy and enforce it.

As the company reported on 25 July, this policy resulted in the loss of confidential information including social security numbers on 12,000 of its employees. The data was stored on a laptop that was stolen from company's auditor Deloitte & Touche.

Let's all say "thank you" to Armstrong World Industries and Deloitte & Touche for emphasising the need for harsh penalties against security ignorance.

There is also great news also for a group of up to 23,000 patients of the George Washington Hospital in Washington DC. You probably survived your treatment at the facility, but it isn't that certain that you'll survive the incompetence with InstantDx, a partner that attempted to provide electronic prescriptions.

InstantDx succeeded in exposing data including social security numbers for between 5,600 and 23,000 patients, the hospital disclosed on Wednesday. Amazingly, no medial or prescription data was leaked, only data that can really hurt consumers. George Washington Hospital wisely suspended the trial with InstantDx.

Let's all say "thank you" to InstantDx for demonstrating that security is strategic instead of merely a pesky added cost that gets in the way of your corporate greed.

To round out Wednesday's series of embarrassing security unveilings, a US subsidiary of the UK based financial services firm Old Mutual, realised that "sometime in May" a laptop was stolen. It contained data on 6,500 fund shareholders, including all the details that an identity thief would ever need.

Hopefully the financial services firm is better at investing than it is at securing its data. It's investors after all will need money to monitor their credit scores and fight claims for years to come.

Let's all say: "thank you" to Old Mutual for providing proof that unencrypted confidential data stored on a laptop really is a great way for identity thieves to strike it rich.

And let's finish off by thanking the privacyrights.org website for providing an overview of all these cases of data security incompetence.

Technorati technorati tags: , , , , , ,

Comments

Perhaps someone should start a "name and shame" web site that also discusses data security ideas and methods.

Post a comment







Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Investments Limited 2010, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093