Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Law Enforcement Wants to Learn from Cybersecurity | Main | Trusted Computing Platform Vulnerability Presentation Blocked at Black Hat »

Compliance is Less Expensive than Data Breaches - Gartner

Beefing up security is cheaper than cleaning up a data breach according to Gartner, at least when talking about PCI levels of security. Start with credit card data. Don't keep it on a point of sale terminal, they're too easily compromised. Don't use WEP encryption on wireless networks that transmit credit card data. It's hard to believe but, according to Avivah Litan of Gartner, many retailers are using the "Why Even Pretend your encrypted" encryption standard on their POS networks.

According to In Data Breaches Start at the Gas Station, Analyst Says:

Implementing security is cheaper in the long run than having a data breach, which can be expensive and hurt a company's reputation. Gartner calculates that a data breach costs companies around $300 per exposed account because of investigations, fines and lawsuits. On the other hand, beefing up security costs around $16 per account for the first year, and that cost falls over time, according to Litan.

Retailers must get a handle on their managed device security. Other organizations are finding better ways to work with customers and partners by allowing remote access through unmanaged devices, the least retailers can do is improve managed device security. For more on this topic, there is a new article at the Messaging and Web Security community on protecting remote access from unmanaged devices.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/340

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net