Management, Info System Security, Systems Russell Mickler Management, Info System Security, Systems Russell Mickler

Losing a Cell Phone is a Data Breach

Technology Consultant Russell Mickler of Vancouver, WA explains how losing a cell phone constitutes a potential data breach of unencrypted personal private information (PPI), and how small businesses need to respond to it.

Just Another Bad Day At The Office ...

The other day, a business associate told me a terrible story about losing his cell phone. He placed it on the roof of his car and it probably slid off and flew into the street. I was empathetic, but at the same time, I asked a critical question: "Did you perform any business on this phone?"

He answered that he did. I started asking a bit more. "Do you think any of the emails on your phone had names of people, personal private data like addresses and phone numbers, and account information with your institution?"

Sadly, his smile began to fade as he started to see where I was going with this line of reasoning. "My friend, you've got a data breach situation on your hands."

... Just Got a Whole Lot Worse

A data breach is a condition where unencrypted Personal Private Information (PPI) is suspected of being compromised, or, falls out of the control of its owner.  

Most States have data breach laws that require reporting and disclosure of a data breach affecting their citizens. If you're a small business in Washington State, you're subject to RCW 19.255.010 governing data breach reporting to affected Washington citizens.

Unfortunately, there isn't a national data breach law: each and every state has their own standard which makes it very difficult to do business in this country. Example: if you're a Washington State company that does business with consumers in the State of Oregon, you're also governed by the ORS 646A.600 Oregon Consumer Identity Theft Protection Act. You'd have to respond to both states and their requirements equally.

Cell phones and other mobile devices (tablets, laptops, wearable computers) are unencrypted storage devices and might contain classified forms of PPI covered in the statute.

Unencrypted means that the data on the hard drive of the device isn't scrambled so that somebody can't access it, and sadly, adding a passcode or a fingerprint access to your cell does not encrypt the contents of the device.

Generally, in the State of Washington, if your mobile device contains email, notes, documents, or contact information that draws a line between a first and last name and:

  • Social Security Number
  • Driver's License Number or Washington Identification Card Number
  • Account Number or Debit Card Number (in combination with any access password or PIN)

As a remedy, Washington State requires that you provide immediate notification to all affected parties in one of many possible forms for a breach consisting of less than 500,000 records:

  • Written response
  • Electronic notice ... "consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Sec. 7001"

And the law also specifically addresses the company's liability to consumer civil action to recover damages, exposing the company to lawsuit for things like identity theft. (And BTW: do note that these laws are a baseline, not covering anything federally recognized as classified forms of information like HIPAA, FERPA, or GLB.)

But Think Bigger Than the Law - Think About Your Social Obligation

The letter of the law is fairly specific, limited, and even provides exclusions for public information that could be obtained from governments and other sources.

But think about it. What if it was your PPI, your kid's PPI, the private checking account information of your company (although it didn't have a PIN or passphrase)? Wouldn't you want to know about the data breach so that you could take reasonable precautions to protect yourself?

It's kind of like the recent automaker testimonials before Congress lately. If you knew about something but didn't take action - didn't go above the letter of the law and embrace the spirit of the law - doesn't that violate social obligation? Ruin public trust? If any form of sensitive information fell out of your control, shouldn't you be notifying those affected, and keeping a record of your social response so that you can justify your transparency and defend yourself from civil litigation, or, embarrassing allegations of concealing your negligence?

What's worse: admitting to the problem, taking ownership of it, and being seen as a leader to accept responsibility and seek remedies? Or, being caught in a cover-up? Or have somebody somewhere else damaged because you didn't take reasonable steps to notify them of the breach?

Preventative Measures

Okay, how can we be proactive about this stuff? Make sure it doesn't happen in the first place? 

  1. Have a Security Policy. A document from your executive management that describes what your company does during a data breach and how it will respond. This document will demonstrate management's awareness of their obligations as custodians of PPI.
     
  2. Have a Data Classification Policy. A document that classifies certain kinds of information within a company as being more or less sensitive, and dictates the kinds of controls and accessibility it should have. Example: this policy should state that SSN's, account numbers, WA Drivers License Numbers, and access codes are restricted forms of information, and should never be transmitted out of an encrypted state or to a mobile device. Ever. This document will demonstrate management's specific instructions on how to handle classified forms of PPI.
     
  3. Training. You must communicate your intentions and train your staff so that they understand the risks and obligations taken on by your firm, and, how data breach affects them as individuals.
     
  4. Audits. Periodically review the Technical Controls that enable these policies. Review cell phones of employees. Put in the necessary technical precautions to prevent 

These are best-practice approaches to illustrating management's intention, recognizing their obligation, proactively identifying what forms of information should be classified and how they should be treated, training staff, and auditing compliance.

Without these instruments or practices, the company is at best a poor custodian and at worse negligent, seriously exposing their firm to civil action from consumers damaged by identity theft.

R

Read More
Info System Security, Systems Russell Mickler Info System Security, Systems Russell Mickler

Big Company Encryption Makes Small Business Vulnerable

Information security doesn't have to be a big-dollar, low-return activity. Practical approaches can help the small business implement best practices to reduce their vulnerability and make them less of a target - comparatively - to larger businesses with bigger budgets.

Companies all across the web are responding to a multitude of security threats by encrypting the web. Energy and resources are being expended to do the better thing and make their systems as difficult as possible to compromise. This is a great thing.

However, the small business usually doesn't have the resources or know-how to tackle these kinds of complex technology problems. The little guys don't know about encryption, Open SSL vulnerabilities, two-factor identification, or risk assessment. That makes small business substantially more vulnerable to attack and compromise: their IT systems are easier to hit and exploit by comparison.

I'm spending a great deal of time this quarter talking security with my clients. I'm making a slew of recommendations to improve their defensive posture. It's the right thing to do. It'll help provide a reasonable deterrent and make them less vulnerable as low-hanging fruit. If you have concerns about the state of information security in your small business, give me a call. I'd be happy to talk about practical, low-cost approaches to address these problems.

Thanks!

R 

Read More
Economy, Info System Security Russell Mickler Economy, Info System Security Russell Mickler

Small Business: Innovate or Attenuate

Are you a small business owner? Why are you doing the same thing, year after year? Why aren't you changing? Evolving? Innovating? Now's the time. There's no better time to think differently

So you're a small business owner?

Go ahead.  Keep doing the same thing.

Keep using the same business processes, the same hardware and software, the same approaches to your business game that you've been using for the last decade. Heck, maybe even before then.

Keep hiring the same kinds of people, execute the same strategy, depend on the same marketing techniques, and say the same thing about your product or service.

Keep doing the same thing because ... ? It's safe? It's what you've always done? You're afraid of alternatives? Consequences? Real and perceived risk? Losses? Embarrassment?

Keep doing the same thing because ... ? You believe the world is static - technology isn't reinventing your industry, consumer preferences aren't changing, and that the perceived value of your product or service doesn't continually wane in the eyes of your consumer?

Keep doing the same thing because ... ? You like consistency. You dislike change. You want to keep the cheese right where it is, thank you, and that makes you feel comfortable. Comfortable is preferable to disruption.

Keep doing the same thing and - in comparison to your competitors - your costs will increase, your margins will erode,  your perceived value will diminish, your market share will shrink, and you will be slow: you shall be the master of the wrong product, at the wrong place, at the wrong time. 

But maybe, in the end, you'll still feel good about it? If not, upswings in the economy are times to innovate. Do something different. Spend a little money to R&D - try new things, in new ways, to question your assumptions and think differently.  And a great place to start is with your business processes and systems automation. 

R

Read More