A one man army - defeated by business - everyone loses

by SrChasJC 5. October 2008 05:08

It’s a disappointing day for the security information professionals. When a man elected by the people sides with business concerns, we all lose. According to http://idtheftcenter.org/workplace_facts.html claims “One study said that identity theft cost U.S. businesses and consumers $56.6 billion in 2005” and “According to the U.S.  Department of Justice Statistics, identity theft is now passing up drug trafficking as the number one crime in the nation”.

On October 5th, 2008 I read a report from SANS that detailed how California Governor Arnold Schwarzenegger vetoed the Consumer Data Protection Act again on October the 2nd. His comments regarding his reasoning included "by requiring notification even where no information was obtained improperly, this bill would likely result in significant costs to businesses and to the state."

Identity theft is life changing. Imagine for a moment, opening your credit card bills one month and seeing that all the interest rates raised to 24%, and the payments doubling. If you are trying to finance a home, forget about it because your ratio will change significantly, and your credit rating will be in the toilet. After you pull a credit report, you realize someone has opened a credit card account in your name, charged $20K, and to boot, they are late on the payment! Correction, YOU are late on the payment! That is why all of your credit card companies have revised their terms with you. Even if you get the card company convinced it wasn’t you and the charges are removed from your credit file, you are responsible for the increased payments on all the other cards, and getting the terms revised, well, ask anyone who is in that position, you can pretty much forget it.

Three months later, you’re considering bankruptcy, you’re savings account depleted, and you are considering cashing out your 401K to pay off the credit cards. You have no budget because you can’t meet the payments as they are. Now all it takes is a car repair, an increase in gas price, well, you get the picture. The most the “company” responsible is going to offer you is a free credit report.

According to http://ag.ca.gov/idtheft/ there were 45,175 victims reported from California in 2005. This will increase. As a security specialist I have a few observations. Businesses as a rule are lazy, doing only what they have to. (This is not a reflection of any company I have worked for who hired me to improve their security.) If only the businesses treated the personal information like how they HAVE to treat VISA credit card information (That still doesn’t mean they will, case in point TJX), we would be much better off. The credit card industry has come together and produced a simple list of requirements; (https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml), the first of which is “Build and Maintain a Secure Network”. Wait, you mean this is a requirement? Wouldn’t you think that is a given? Don’t fool yourself. If you have ever found a company that took credit cards but doesn’t take VISA credit, think again about doing business with them because most likely they can’t (or won’t ) meet these simple standards.

Unless business HAS to meet certain standards (AND IS AUDITED BY A THIRD PARTY), your data is in jeopardy. You would be very surprised what I have seen as a security professional.

So back to Arnold. He is in a position to make change to affect people’s lives, not only in California, but possibly worldwide. Many states follow California, and let’s face it, many countries follow the US. I have always seen Arnold as the underdog, man against the bad world. My favorite movie of all time is Total Recall, where he saves the planet Mars. If I could speak to him, I would only say I wished you could see the blatant disregard of personal data I have seen, not with the companies I was/am with, but the companies they do business with, and shared information from other security professionals.

Laws don’t fix everything, but they do cause change. It would be a shame to think that every company would have to make the headlines before they made the changes required to secure personal information. Without laws, this is what will happen. Meanwhile, your information is not only in your state, but in every home office of every company you do business with. A little multiplication, and the 45K people for just one state for one year, now think of the odds of your information being exposed. If you do business on the Internet, use a credit card in a restaurant or retailer, your odds are not good. Someone will use that card, your information, or otherwise get at the data because of the fact there are weak controls, or for the smaller companies, no controls in place since they won’t fall under any of the other control standards such as SOX, HIPPA, or PCI. That's where a law comes in to play. It gives security professionals like myself the grease to make internal changes.

Arnold, you have shown us that the sword is mightier than the pen.

Currently rated 4.5 by 2 people

  • Currently 4.5/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags: , ,

GrapeVine | Network Security | political

Comments

10/7/2008 3:46:14 PM

Perry D

This story hit the spot. See the SANS for today 10/7/08:

STUDIES AND STATISTICS
--Reported Data Breaches in US on the Rise
(October 6, 2008)
According to statistics compiled by the Identity Theft Resource Center,
there have been 516 reported consumer data breaches in the first nine
months of 2008, exposing 30 million records; in 2007, the total number
of reported breaches was 446. Extrapolated from the numbers so far this
year, the total number of reported breaches in 2008 could top 680.
Eighty percent of the breaches involved digital media; the remaining 20
percent involved data recorded on paper. Of the incidents this year,
36 percent occurred at businesses, 21 percent occurred at educational
institutions, and 16 percent on military or federal government systems.
Twenty percent of the reported braches were due to lost or stolen
digital media storage devices, 17 percent were due to insider theft and
13 percent were exposed through hacking.
voices.washingtonpost.com/.../...in_2008_expo.html

Perry D us

11/24/2008 12:58:01 AM

Busby SEO Test

thanks i really enjoy reading you're article!!

Busby SEO Test us

1/1/2009 11:00:17 AM

Busby SEO Test

Thank for this informations

Busby SEO Test id

1/1/2009 11:00:55 AM

Busby  Test

Thank for this informations

Busby Test id

1/14/2009 12:51:15 AM

SEO help Tools

A one man army - defeated by business - everyone loses nice and great post

SEO help Tools us

1/23/2009 2:20:34 AM

Debt reduction expert

Nice stuff..Keep up the fine work.

Debt reduction expert us

2/3/2009 5:24:50 AM

Inventory Management Software

yeah.. the article is so good Smile

Inventory Management Software gb

2/20/2009 9:52:55 AM

London to Paris Tours

Couldnt agree more... sadly money talks...

London to Paris Tours gb

3/7/2009 9:24:31 AM

Urban Net Zone

thanks for sharing your stories, nice writings

Urban Net Zone us

3/12/2009 11:13:07 AM

funny sayings collection


This is exactly what I was looking for. Thanks for sharing this great article! That is very interesting Smile I love reading and I am always searching for informative information like this! You are bookmarked!
Thx,

funny sayings collection us

3/15/2009 11:06:59 AM

how to write good

nice! interesting! Smile

how to write good us

3/24/2009 7:43:08 AM

chicken soup recipes

Yeah, when money talks, rules are bendable!

chicken soup recipes us

4/27/2009 10:05:02 AM

Leadership Theory

Thanks for writing this great post!! In theory I'd like to write posts of this quality too... but unfortunately I don't really have enough time!

Leadership Theory gb

4/27/2009 12:08:56 PM

Chrome Plating

Thanks for writing this great post, I must say your blog looks really good on Google Chrome. I think blogengine and chrome plating are very compatible, (moreso than firefox).

Chrome Plating gb

5/1/2009 9:00:49 AM

Moving tips

love u all
thank u for the great show

Moving tips bz

5/1/2009 9:01:13 AM

movers

Couldnt agree more... sadly money talks...

movers by

5/21/2009 7:50:35 AM

business franchise

Hey - nice blog, just looking around some blogengine.net sites, seems a pretty nice platform. I'm currently using Wordpress for a few of my sites but looking to change one of them over to blogengine.net as a trial run. Anything in particular you would recommend about it? Cheers, Matthew

business franchise gb

5/22/2009 9:24:20 AM

costa

Identity theft is increasing and the worst part is that most of are not even aware about it.

costa us

5/27/2009 8:30:24 AM

Loan Modification Service

That's great, I never thought about A one man army - defeated by business - everyone loses like that before.

Loan Modification Service in

6/12/2009 8:23:33 AM

Internet Marketing Company

Wow, I never knew that A one man army - defeated by business - everyone loses. That’s pretty interesting...

Internet Marketing Company us

6/12/2009 8:28:06 AM

Internet Marketing Company

Identity theft is increasing and the worst part is that most of are not even aware about it.

Internet Marketing Company us

6/16/2009 10:11:22 AM

Terry Walker

Good post, but have you thought about this type of information before?

Terry Walker us

6/16/2009 6:39:48 PM

jammer

great posting
love it

jammer am

6/18/2009 4:55:17 PM

tukang nggame

I like it and I think you make a good point. Thanks for taking the time to share this with us

tukang nggame us

6/20/2009 7:54:48 AM

Life insurance

This is exactly what I was looking for. Thanks for sharing this great article! That is very interesting.....

Life insurance us

Add comment


(Will show your Gravatar icon)  

  Country flag

biuquote
  • Comment
  • Preview
Loading



Copyright © 2008 Charles Corcoran
Powered by BlogEngine.NET 1.4.0.0
Theme by Mads Kristensen

About the author

A little crazy, a little conservative, with a dose of normalness sprinkled on for good measure. I try to spend my life trying to get out of the box I'm used to thinking myself into!

Recent posts

Recent comments

Comment RSS

Page List

    Disclaimer

    The opinions expressed herein are my own personal opinions and do not represent my employer's view in  anyway.

    © Copyright 2008