What do they do with my data?
What companies should be doing:
Given the rise in these malicious attacks and the potential impact, companies should consider a holistic approach to protecting data wherever it is – at rest, in motion or in use. I recently read an article quoting Tim Matthews, Senior Director of Product Marketing at Symantec: “The good news is that there is a straightforward regimen to help stop these kinds of risks.” Matthews recommended that companies look at the following security measures:
- Installing device control: where no copying onto a disk of any type is possible, or via Bluetooth or Wi-Fi data transfer.
- Endpoint data loss prevention methods: which prevents sensitive data from being copied – copying of data or files is blocked based on content.
- Encryption: these types of programs render some or all data unreadable by anyone who does not have proper authorization, should they bypass the access control to these documents. End-to-end encryption is preferable because at every stage whether data is in use, in motion or at rest, is it encrypted and secure, and it is never ‘in the clear’.
Furthermore, documents that contain sensitive information, such as my electronic statements, should always be encrypted and password protected. In an online environment, companies can have firewalls and monitoring facilities where they can detect a breach. Whereas once a document is emailed out, the biller has no control over who can get access to that customer’s information. The sensitive information in these documents can include credit card information and personal identification details like ID number and date of birth. The only way to prevent unsolicited access is to password protect the document. I wholeheartedly agree with Matthews’ statement: “With such well understood defenses available, companies really have no excuse for not putting them in place.”
What should I be doing?
Simply put, I need to be cautious and vigilant. Always find out who is receiving my personal information and ensure that they implement the appropriate defenses.
The cost of a data breach
The 2012 Verizon Data Breach Investigations report says that in 2011 there were 855 data breach incidents involving 174 million compromised records. The personal cost of a security breach to each compromised individual is potentially massive: a sudden zero bank balance or complete identity theft. But the cost to companies can be catastrophic. From Symantec’s Cost of Data Breach study, United States (2011), the average cost per data breach for an organisation is $5.5 million, or $194 per record. While customers need to be cautious and vigilant when sharing personal information, organisations collecting customer data must ensure that they implement the necessary defenses against data breaches – don’t take the risk. Increase your security and reduce risk with ‘Push’ eDocument delivery
Get in touch with us
Keen to find out more or get an expert's opinion?