Archive

Archive for the ‘Uncategorized’ Category

Where Is My Bank Customers’ Sensitive Data?

April 2nd, 2010 rfernandez No comments

This year, in March alone, REPORTED data breach incidents tripled those of the preceding months, and looks like we are on track to do the same in all of 2010 compared to 2009. Where is all this data going? And why is it missing?  A recent article in CU Info Security, 22 Banking Breaches So Far in 2010, notes that many of these incidents were reported by financial institutions. These include regional or local banks, credit services organizations and even the U.S. Security & Exchange Commission.

We have to get smarter about figuring out what data we have, where it is and how to keep it where it belongs. Known solutions, and some very effective ones, exist to help. It should not cost you the annual IT budget. Here is a quick and dirty list of some things you can do – now and near-term – to prevent your company from being the next one in the headlines facing public scorn, hefty fines and associated negatives.

  1. Figure out what data you have that needs to be protected  - what’s considered sensitive?
  2. Find that data  - where does it live? Who has access to it?
  3. Narrow down who needs access – not everybody needs to have everything.
  4. Set polices and communicate them broadly and repeatedly. Determine how you enforce.
  5. Look at solutions like data loss prevention: it’s proven. It can be implemented in a few hours or a few days in many organizations. A good solution requires less than an hour or so a week to manage and should be scalable so you can add users and sites easily.

The reality is that you CAN prevent these ugly mishaps.  Townsend RealTick, the premier global, multi-broker, broker neutral, cross-asset Execution Management System, has learned how to protect its data. They use Code Green Networks TrueDLP to prevent highly sensitive date from leaving their network. You can learn more about their DLP strategy, the obstacles that they overcame, and why they selected TrueDLP at http://www.bankinfosecurity.com/podcasts.php?podcastID=429 (registration required by bankinfosecurity.com)

Categories: DLP, Data Loss Prevention, Uncategorized Tags: