DocuCrunch.com » Your network’s secure, but they’re looking in your trash

Your network’s secure, but they’re looking in your trash

October 13, 2009 by Steve Hannaford
Posted in: In this week's e-newsletter, Security

We all worry about ultrasmart cyber-thieves breaking into databases and running off with key records that can be used to commit fraud. But there’s a more low-tech approach criminals are also using.

In fairness to IT operations, it takes very clever systems management and a big investment in time and money to defeat the most determined hackers.

But any idiot can do a little dumpster diving to find paper documents left intact by careless employees.

“It is a mistake we made.” That’s the explanation a manager from Flagler County (Florida) gave when it was discovered that large quantities of names, Social Security numbers and driver’s license information were sitting unprotected in the county’s dumpster.

Employees, instructed to purge 10 years’ worth of old data, managed to shred only one of 16 boxes filled with information that could be used for identity theft. The rest was just sitting in the dumpster.

Luckily for the county’s residents, a local retiree (poking around in the dumpster for some unexplained reason) found out about the vulnerable data and contacted police and local media. Embarrassed county officials “verbally reprimanded” the careless employees and promised to destroy the documents. One official tried to quell the resulting uproar by saying: “It was less than 24 hours and we fixed it.”

Problem solved? Not quite. Apparently much of the data that was on the paper, including personal ID information, is also readily available on the county’s website, with little or no protection.

All this happens as Florida counties are under a state mandate to remove or secure sensitive data. According to an article in the News-Journal of Daytona Beach:

“Amended state law requiring all county court clerks to remove sensitive information electronically by January 2011 pits record custodians statewide in a race against time to vet millions of documents, some dating to 1917.” It involves mass redaction — that’s a major headache for cash-strapped counties.

The News-Journal performed a cursory search of the county’s website and found the Social Security numbers of “prominent citizens such as county commissioners and judges.”

Conclusion: Document security needs a two-pronged approach – for both paper documents and digital ones. On the paper side, it’s a matter of training and follow-up. The county had the shredder and the policy, but the employees didn’t follow up. On the digital side, you should be actively checking that crucial data is not casually accessible without authentication. For companies and agencies where website grew without much planning, there may be more data exposed than you realize.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , , ,


Comments are closed.


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement