Posts Tagged ‘Data Breaches’

Senator’s computers hacked!

Monday, March 23rd, 2009

Bill_nelsonxlarge” Cyber-invaders.”  That’s what Sen. Bill Nelson (D-Fla.) calls the hackers who have already twice this month broken into two PC workstations used by several of his key staff members.

Although no classified information was kept on the breached PCs, the break-in demonstrates system vulnerabilities at the highest levels of government.

In fact, Nelson says similar breaches on Capitol Hill computer networks are on the rise in recent months, based on reports from various Capitol Hill IS offices.

“The threat to our national security, to be sure, is real; and, it will require significant investment and inter-agency coordination at an unprecedented level to gain an upper hand against would-be cyber criminals and spies,” Nelson said in a statement. “These are anxious days, when you consider the threat from such espionage facing our country and recent developments on this front.”

These and other more serious breaches have led Nelson, along with Sen. Jay Rockefeller, D-W.Va. and Sen. Olympia Snowe, R-Maine, to call for the creation of a permanent national “cyber-security czar” reporting directly to President Obama. The threee Senators have begun drafting legislation that, if passed, will require federal oversight and review of both government and “critical private networks,” and create a “public-private clearinghouse for cyber threat and vulnerability information-sharing.”

Furthermore, another group of security and privacy experts has requested that President Obama create a federal library of data breach information in their report titled, The Perfect Storm: Why the New Administration Cannot Ignore Identity Theft.

Nelson’s call for tougher U.S. cybersecurity oversight comes less than two weeks before management consultant Melissa Hathaway is due to deliver the results of her 60-day review of current U.S. cybersecurity policy to President Obama.

Photo: Nelson (Tim Dillon/USA TODAY)

New Insider Threat Emerges in the New Economy

Tuesday, March 17th, 2009

In today’s SecurityWire, sent out by SearchSecurityLumension’s new Whitepaper speaks to the costs of malicious insiders. Excerpts from the white paper support that pairing ongoing training with technology solutions is more effective than technology alone when it comes to minimizing insider threats:

photo source: www.kval.com

photo source: www.kval.com

“Whether an insider steals information for financial gain or simply leaves the organization open to a breach due to sloppy practices, the risks are costly to an organization. According to analysts with Forrester Research, the typical data breach can cost a company between $90 and $305 per lost record

“According to the Internet Threat Resource Center, 24 percent of all data breaches that hit financial institutions in 2008 were caused by insider threat. Similarly, 20 percent of government breaches and 16 percent of other business breaches were caused by internal attacks…

“In order to neutralize the threats posed by insiders, IT departments must take away the means and the opportunities to commit crimes. By creating strategic policies and by automating the monitoring, enforcement and reporting of those policies, organizations can understand how employees and partners are engaging with IT assets and intellectual property.”