<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management Monitor &#187; Data Security</title>
	<atom:link href="http://www.riskmanagementmonitor.com/tag/data-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.riskmanagementmonitor.com</link>
	<description>The Risk Management Blog</description>
	<lastBuildDate>Thu, 09 Feb 2012 17:59:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Cyber Crime: Recent Events and Insuring Against It</title>
		<link>http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/</link>
		<comments>http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 17:49:00 +0000</pubDate>
		<dc:creator>Emily Holbrook</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Insurance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology Risk]]></category>
		<category><![CDATA[Cyber Liability Insurance]]></category>
		<category><![CDATA[Data Security]]></category>

		<guid isPermaLink="false">http://www.riskmanagementmonitor.com/?p=6688</guid>
		<description><![CDATA[It seems like several times per day that I am sent a news alert of yet another data breach. The frequency with which they occur is frightening to say the least and unfortunately, many businesses are not covered for such an event. Let&#8217;s take a look at data breaches that have occurred over the past [...]]]></description>
			<content:encoded><![CDATA[<p>It seems like several times per day that I am sent a news alert of yet another data breach. The frequency with which they occur is frightening to say the least and unfortunately, many businesses are not covered for such an event.</p>
<p>Let&#8217;s take a look at data breaches that have occurred over the past week and what, if anything, can be done to prevent (or insure against) them.</p>
<ul>
<li>A report by Wake Forest Baptist Medical Center to the state attorney general&#8217;s office explained that 357 people were affected by documents from an 11-year period taken from the medical center due to a security breach, the <a href="http://www2.journalnow.com/news/2011/jul/09/wsmain01-regulatory-response-uncertain-after-lates-ar-1192162/" target="_blank">Winston-Salem Journal is reporting</a>. Wake Forest Baptist issued a statement early last month that it had fired an employee, Linda Bowden Turner, who had taken medical records and documents from 1995 to 2006 from the medical center to her own properties.</li>
<li>If you used a credit or debit card at Margarita’s restaurant over the past three months, a virus might have culled your information before it could be encrypted and then sold to underground markets, Huntsville police said. <a href="http://itemonline.com/local/x202397280/Not-yet-into-the-clear" target="_blank">At least 200 people over the past two weeks have reported incidents of stolen bank account information</a>, and authorities said they suspect there are many more cases that have not been reported and many potential victims whose numbers have not yet been used by thieves.</li>
<li>Nearly <a href="http://technolog.msnbc.msn.com/_news/2011/07/18/7106159-nearly-700-toshiba-customers-emails-passwords-stolen?preview=true" target="_blank">700 Toshiba customers&#8217; emails and passwords have been stolen from the company&#8217;s U.S. servers</a>, the latest company to be hit by hackers, although it doesn&#8217;t appear to be the work of the same groups that have infiltrated Arizona law enforcement, Orlando tourism or PBS. TechEYE.net reported that the hacker VOiD targeted Toshiba and claimed &#8220;to gain usernames and passwords on 450 of the company&#8217;s customers&#8221; as well as about 20 re-sellers and 12 administrators on the company&#8217;s Electronic Components and Semiconductors and Consumer Products sites.</li>
<li><a href="http://www.mirror.co.uk/celebs/news/2011/07/16/lady-gaga-website-hacked-and-fans-details-stolen-115875-23274356/" target="_blank">Lady Gaga has called in police after thousands of her fans&#8217; personal details were stolen from her website</a>. Her record label acted after the site was hacked into by US cyber attackers SwagSec. A source said: &#8220;She&#8217;s upset and hopes police get to the bottom of how this was allowed to happen.&#8221; The group struck on June 27 but did not make the information, which included names and email addresses, public until this week.</li>
<li>Anonymous, a group of “hacktivist” computer-savvy attackers, has already speared a number of big fish: credit-card companies, the church of Scientology, and Monsanto, a biotechnology firm. And the hackers have flaunted their skills by successfully attacking computer-security expert firms, like HBGary. <a href="http://www.economist.com/blogs/schumpeter/2011/07/security-breach-booz-allen-hamilton" target="_blank">Its latest victim is Booz Allen Hamilton, a big consulting firm to America’s government</a>, including on cybersecurity, with bigwigs like a former CIA head and a former director of national intelligence on its payroll.</li>
</ul>
<p>So how do companies work to prevent or mitigate the effects or data breaches? One option is cyber liability insurance. Major insurers like Chartis, ACE and Hiscox have been in the cyber liability insurance game for several years now and smaller insurers are entering the market at a rapid pace. But <a href="http://smallbusiness.foxbusiness.com/legal-hr/2011/05/23/hacker-liability-risk-company/" target="_blank">what types of coverage does a cyber liability policy include</a>? According to Dave Navetta, partner at <a href="http://www.infolawgroup.com/" target="_blank">InfoLawGroup</a> and contributor to Fox News, the following may be included:</p>
<ul>
<li><em>Breach Notice Costs.</em> Coverage now exists for direct costs incurred by an insured to provide notice to individuals in the event of a security breach, as well as expenses to set up a call center and provide credit monitoring services. These costs involve a multiplier effect. For example, credit monitoring can cost anywhere from $10 to $200 per year, per person impacted by a breach. If one million individuals are at issue, costs could run in the millions of dollars. These costs also include attorney fees and forensic investigation expenses to determine the cause of a breach and whether notice is required under law.</li>
<li><em>Damages and Defense Costs.</em> Provides coverage for information security and privacy breaches and technology professional liability. This element of the insurance plan is specifically designed to provide coverage for damages and defense costs arising out of lawsuits or claims resulting from a data security breach or an act, error or omission in the rendering of professional technology services (like data storage services). Some cyber policies will also protect your business against the cost of regulatory investigations or actions due to a security or privacy breach.</li>
<li><em>Service Provider Breach.</em>With more companies outsourcing their data processing to third parties or the “cloud,” it is important that a cyber policy provides coverage if the security breach happens to one of the insured’s service providers. That will protect your company against many types of expenses. However, these policies are unlikely to provide any coverage for the personnel hours expended internally to address the breach.</li>
<li><em>Crisis Management, Business Interruption and Data Restoration.</em> This insurance can also help cover the costs for getting the network back up and running and restoring lost data. Public relations services may also be included to help restore the company’s reputation.</li>
<li><em>Denial-of-Service Attack.</em> If your company or a service provider, such as a web host, is shut down by a denial-of-service attack or other type of hack, some insurance policies will cover lost income and the costs of repairing the network.</li>
<li><em>Cyber Extortion.</em> In a case where a hacker decides to hijack your website, network or database, and demands money to restore it, a cyber extortion clause in an insurance policy can help to cover the settlement and the cost of hiring a security firm to track down the hacker.</li>
</ul>
<p>Does your company have cyber liability insurance coverage?</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%2524%257Btitle%257D%2B-%2B%2524%257Bshort_link%257D&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=88&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=38&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-digg">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=3&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-reddit">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=40&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-tumblr">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http%3A%2F%2Fwww.riskmanagementmonitor.com%2Fcyber-crime-recent-events-and-insuring-against-it%2F&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=78&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Tumblr">Share this on Tumblr</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.shareaholic.com/api/share/?title=Cyber+Crime%3A+Recent+Events+and+Insuring+Against+It&amp;link=http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/&amp;notes=It%20seems%20like%20several%20times%20per%20day%20that%20I%20am%20sent%20a%20news%20alert%20of%20yet%20another%20data%20breach.%20The%20frequency%20with%20which%20they%20occur%20is%20frightening%20to%20say%20the%20least%20and%20unfortunately%2C%20many%20businesses%20are%20not%20covered%20for%20such%20an%20event.%0D%0A%0D%0ALet%27s%20take%20a%20look%20at%20data%20breaches%20that%20have%20occurred%20over%20the%20past&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=207&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul><div style="clear: both;"></div></div>

]]></content:encoded>
			<wfw:commentRss>http://www.riskmanagementmonitor.com/cyber-crime-recent-events-and-insuring-against-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Pros Not Protecting Sensitive Data</title>
		<link>http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/</link>
		<comments>http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 15:06:14 +0000</pubDate>
		<dc:creator>Emily Holbrook</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology Risk]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Security Breach]]></category>

		<guid isPermaLink="false">http://www.riskmanagementmonitor.com/?p=822</guid>
		<description><![CDATA[A recent survey by Credant Technologies shows that IT professionals really don&#8217;t have the time to be bothered with protecting their company&#8217;s sensitive data. The survey focused on mobile usage among 227 IT professionals &#8212; the majority of which hold a position at companies that employ more than 1,000 people. Thirty five percent revealed they just don&#8217;t get around to [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://credant.com/news-a-events/press-releases/353-it-security-professionals-passwords.html" target="_blank">recent survey</a> by Credant Technologies shows that IT professionals really don&#8217;t have the time to be bothered with protecting their company&#8217;s sensitive data. The survey focused on mobile usage among 227 IT professionals &#8212; the majority of which hold a position at companies that employ more than 1,000 people.</p>
<blockquote><p>Thirty five percent revealed they just don&#8217;t get around to using a password on their business phones and smartphones, even though they know they should as they contain sensitive and confidential information! Surprisingly, IT professionals are only marginally better at using passwords than the general population, as a survey conducted earlier in the year by CREDANT found that 40% of all users don&#8217;t bother with passwords on their mobile phones.</p></blockquote>
<p>The sorts of information that IT professionals are storing on their smartphones and mobiles, many of which are totally unprotected with a password, include:</p>
<ul>
<li>80% Business names and addresses</li>
<li>66% Personal names and addresses</li>
<li>23% Business emails</li>
<li>16% Personal emails</li>
<li>12% Bank account details</li>
<li>12% Business diary with details of all their appointments and meetings</li>
<li>7% Personal diary</li>
<li>5% Credit card information</li>
<li>4% photos</li>
<li>1% Passwords and Pin numbers</li>
</ul>
<blockquote><p>Andrew Kahl, Sr. VP of Operations &amp; Co-Founder from CREDANT Technologies explains &#8220;It is alarming to note that the very people who are responsible for IT security are not much better at protecting the information on their business phones than most of their co-workers, who don&#8217;t necessarily know any better. If a mobile or smartphone goes missing and isn&#8217;t protected with a password, and contains business names and addresses and other corporate data such as business emails, then the company is immediately in breach of the data protection act by failing to meet some of its principals on electronic data.&#8221;</p></blockquote>
<p>A scary thought, considering that last year alone saw <a href="http://www.idtheftcenter.org/artman2/publish/lib_survey/Breaches_2008.shtml" target="_blank">656 different security breach incidents</a>, an increase of 47% over 2007&#8242;s total of 446, according to the Identity Theft Resource Center. ITRC also claims that the bulk of breached data was unprotected by encryption or passwords.</p>
<p>If IT professionals are failing to protect sensitive data, who is succeeding?</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-829" style="border: 1px solid black;" title="CredantIDTHEFTcartoon" src="http://www.riskmanagementmonitor.com/wp-content/uploads/2009/06/CredantIDTHEFTcartoon4-1024x724.jpg" alt="CredantIDTHEFTcartoon" width="560" height="283" /></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%2524%257Btitle%257D%2B-%2B%2524%257Bshort_link%257D&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=88&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=38&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-digg">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=3&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-reddit">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=40&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-tumblr">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http%3A%2F%2Fwww.riskmanagementmonitor.com%2Fit-pros-not-protecting-sensitive-data%2F&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=78&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Tumblr">Share this on Tumblr</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.shareaholic.com/api/share/?title=IT+Pros+Not+Protecting+Sensitive+Data&amp;link=http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/&amp;notes=A%20recent%20survey%20by%20Credant%20Technologies%20shows%20that%20IT%20professionals%20really%20don%27t%20have%20the%20time%20to%20be%20bothered%20with%20protecting%20their%20company%27s%20sensitive%20data.%C2%A0The%20survey%20focused%20on%20mobile%20usage%20among%20227%20IT%20professionals%20--%20the%20majority%20of%20which%C2%A0hold%20a%20position%C2%A0at%20companies%C2%A0that%20employ%C2%A0more%20than&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=207&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul><div style="clear: both;"></div></div>

]]></content:encoded>
			<wfw:commentRss>http://www.riskmanagementmonitor.com/it-pros-not-protecting-sensitive-data/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Breach Sentence: $9.75 Million</title>
		<link>http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/</link>
		<comments>http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 13:55:06 +0000</pubDate>
		<dc:creator>Emily Holbrook</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Technology Risk]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Security Breach]]></category>

		<guid isPermaLink="false">http://www.riskmanagementmonitor.com/?p=815</guid>
		<description><![CDATA[On January 17, 2007, an individual hacked into the computer systems of TJX Companies (parent company of T.J. Maxx and Marshalls) and stole credit card information on at least 94,000,000 individuals. It ranks as the largest security breach ever recorded, according to DataLossDB.org. And as reported today, the company has agreed to pay $9.75 million to [...]]]></description>
			<content:encoded><![CDATA[<p>On January 17, 2007, an individual hacked into the computer systems of TJX Companies (parent company of T.J. Maxx and Marshalls) and stole credit card information on at least 94,000,000 individuals. It ranks as the <a href="http://datalossdb.org/" target="_blank">largest security breach ever recorded</a>, according to DataLossDB.org.</p>
<p>And as <a href="http://www.bizjournals.com/seattle/stories/2009/06/22/daily25.html" target="_blank">reported today</a>, the company has agreed to pay $9.75 million to 41 states as part of its settlement.</p>
<blockquote><p>Framingham, Mass.-based TJX Cos. said Tuesday it will pay $2.5 million to create a data security fund for states as well as a settlement amount of $5.5 million and $1.75 million to cover expenses related to the states&#8217; investigations. But TJX stressed that it &#8220;firmly believes&#8221; that it did not violate any consumer protection or data security laws.</p></blockquote>
<p><a href="http://www.google.com/hostednews/ap/article/ALeqM5ik7_ofxPQ8KwlW4uKpxtgiEqaaAgD990K2DO0" target="_blank">Under the settlement</a>, TJX must also prove that its computer systems meets stringent data security requirements.</p>
<p>Eleven people were charged with hacking into the systems of TJX and other retailers to steal credit card information. The legal proceedings for those individuals are still under way.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%2524%257Btitle%257D%2B-%2B%2524%257Bshort_link%257D&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=88&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=38&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-digg">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=3&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-reddit">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=40&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-tumblr">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http%3A%2F%2Fwww.riskmanagementmonitor.com%2Fsecurity-breach-sentence-9-75-million%2F&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=78&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Tumblr">Share this on Tumblr</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.shareaholic.com/api/share/?title=Security+Breach+Sentence%3A+%249.75+Million&amp;link=http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/&amp;notes=On%20January%2017%2C%202007%2C%20an%20individual%20hacked%20into%20the%20computer%20systems%20of%20TJX%20Companies%20%28parent%20company%20of%20T.J.%20Maxx%20and%20Marshalls%29%20and%20stole%20credit%20card%20information%20on%20at%20least%2094%2C000%2C000%20individuals.%20It%20ranks%20as%20the%C2%A0largest%20security%20breach%20ever%20recorded%2C%20according%20to%20DataLossDB.org.%0D%0A%0D%0AAnd%20as%20report&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=207&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul><div style="clear: both;"></div></div>

]]></content:encoded>
			<wfw:commentRss>http://www.riskmanagementmonitor.com/security-breach-sentence-9-75-million/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hiscox Studies Privacy &amp; Data Security</title>
		<link>http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/</link>
		<comments>http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 20:10:28 +0000</pubDate>
		<dc:creator>Jared Wade</dc:creator>
				<category><![CDATA[RIMS 2009 Orlando]]></category>
		<category><![CDATA[Technology Risk]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Hiscox]]></category>
		<category><![CDATA[Security Breach]]></category>

		<guid isPermaLink="false">http://www.riskmanagementmonitor.com/?p=434</guid>
		<description><![CDATA[On Monday at RIMS 2009, Hiscox unveiled its new study &#8220;Data Privacy and Corporate America: Who&#8217;s Recognizing the Risk.&#8221; So I sat down earlier today with one of the report&#8217;s authors Jim Whetstone, who is the company&#8217;s senior VP of technology E&#38;O. The chief finding is that 38% of Fortune 500 companies surveyed do not explicitly [...]]]></description>
			<content:encoded><![CDATA[<p>On Monday at RIMS 2009, Hiscox unveiled its new study &#8220;<a href="http://www.hiscox.com/Downloads/d2899def-619c-4147-bbe4-3a85426a44c4.pdf" target="_blank">Data Privacy and Corporate America: Who&#8217;s Recognizing the Risk</a>.&#8221; So I sat down earlier today with one of the report&#8217;s authors Jim Whetstone, who is the company&#8217;s senior VP of technology E&amp;O.</p>
<p>The chief finding is that 38% of Fortune 500 companies surveyed do not explicitly mention privacy/data breach in the risk factors section of their SEC 10-K filings, which when broken down by sector is even more alarming: 46% of diversified financial companies, 50% of telecommunications firms and an astounding 80% of utilities. </p>
<p>Worse still is that, according to Whetstone, many of even those that do realize the financial and reputational risks associated with a potential security breach deem the easiest solution, encryption, to be too cost-prohibitive to use even though they realize it would largely mitigate the threat altogether. You see, currently around 45 states now have laws that require any organization that loses confidential consumer/patient/student/etc. data to notify anyone who was affected. And that&#8217;s when the lawsuits, complaints and horror stories of identity theft begin. Not only is this a huge financial burden — the costs of hiring computer forensic specialists, mailing notifications, setting up call centers and offering free credit monitoring adds up very, very quickly — but the comparable reputational fallout is nearly impossible to quantify.</p>
<p>All this could be averted in most cases, however, with data encryption since almost all those same state laws also include a &#8220;safe harbor&#8221; provision that allows companies who safeguarded the data to forego the onerous notification process.</p>
<p>To put this all in proper perspective, all Whetstone had to do was ask me one question: &#8220;You know why a car has brakes?&#8221; </p>
<p>Since I learned this fact around first grade, I thought to myself &#8220;I got this one&#8230;to stop, right?&#8221;</p>
<p>But before I said anything he answered his own question: &#8220;So it can go fast.&#8221;</p>
<p>Most companies are prioritizing innovation &#8212; and rightly so. They&#8217;re trying to gather as much consumer data as possible to put this to use in sales, development and improved customer relations. But in making these technological advances, it&#8217;s also important to ensure you have the right safeguards in place. &#8220;It&#8217;s a constant battle between technology and the brakes on the car,&#8221; said Whetstone. &#8220;Companies are trying to be innovative &#8212; they&#8217;re trying to push the envelope &#8212; and that&#8217;s always dangerous.&#8221;</p>
<p>Whetstone has no delusions that any company should stall innovation for the sake of encryption and data security, however. On the contrary, he thinks gathering all this data is huge advantage for companies. They just have to be careful and understand their vulnerabilities. And all it takes is glancing at a few of the colorful charts in Hiscox&#8217;s report to realize that most companies are failing at the latter endeavor. In TJ Maxx&#8217;s infamous data breach, for example, the company was attempting to improve its store&#8217;s operations by implementing a wireless network yet it failed to realize that sub-par security opened up the location to nefarious data thieves.</p>
<p>Of course, it is indeed true that encryption is still expensive in some cases &#8212; back-archiving old legacy systems, for instance. But using encryption doesn&#8217;t have to be an all-or-nothing proposition and Whetstone believes that, at a minimum, companies need to at least encrypt the data stored on laptops, USB drives and back-up tapes. He includes this in what he calls a &#8220;defense-in-depth approach” to IT security. By securing those physical items that can be left at an airport or in a taxi cab, you allow risk managers and legal counsel to rest easy knowing that their employees at least won&#8217;t be giving confidential data away. Hackers can still breach the network and that will remain a concern, but protecting the physical storage devices provides a first level of defense.</p>
<p><!--StartFragment-->And most importantly, risk managers need to be involved in the IT discussion. The ideal balance between the legal team, IT and risk management is unique for each company. But unless everyone is talking and understands the priorities and recommendations of the others, data breaches are only going to happen more often.</p>
<div id="attachment_436" class="wp-caption aligncenter" style="width: 560px">
	<img class="size-full wp-image-436 " title="data-breach1" src="http://www.riskmanagementmonitor.com/wp-content/uploads/2009/04/data-breach1.jpg" alt="Hiscox found that only 7% of US companies have implemented end-to-end encryption on their confidential personal data." width="560" height="420" />
	<p class="wp-caption-text">Hiscox found that only 7% of US companies have implemented end-to-end encryption on their confidential personal data.</p>
</div>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%2524%257Btitle%257D%2B-%2B%2524%257Bshort_link%257D&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=88&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=38&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-digg">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=3&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-reddit">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=40&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-tumblr">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http%3A%2F%2Fwww.riskmanagementmonitor.com%2Fhiscox-studies-privacy-data-security%2F&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=78&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Tumblr">Share this on Tumblr</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.shareaholic.com/api/share/?title=Hiscox+Studies+Privacy+%26+Data+Security&amp;link=http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/&amp;notes=On%20Monday%20at%20RIMS%202009%2C%20Hiscox%20unveiled%20its%20new%20study%20%22Data%20Privacy%20and%20Corporate%20America%3A%20Who%27s%20Recognizing%20the%20Risk.%22%20So%20I%20sat%20down%20earlier%20today%20with%20one%20of%20the%20report%27s%20authors%20Jim%20Whetstone%2C%20who%20is%20the%20company%27s%C2%A0senior%20VP%20of%20technology%20E%26amp%3BO.%0D%0A%0D%0AThe%20chief%20finding%20is%20that%2038%25%20of%20Fortune%20500%20c&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=207&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul><div style="clear: both;"></div></div>

]]></content:encoded>
			<wfw:commentRss>http://www.riskmanagementmonitor.com/hiscox-studies-privacy-data-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

