Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Searching for Legal Definition of Spyware | Main | Basics of Event Correlation »

AT&T Laptop Theft - Physician Heal Thyself?

Would you listen to a doctor who told you to clean up your act while he puffed on a cigarette and sipped scotch in the middle of the day? I wonder if AT&T customers will feel similarly about their managed encryption service after an AT&T laptop containing unencrypted personal data (including salaries and bonuses) was stolen from an employee's vehicle.

NetworkWorld gives details of the incident, including excerpts from an email sent to affected employees as well as a Q&A session. This isn't exactly the kind of buzz you'd like after launching a managed encryption service.

If network professionals don't follow their own advice why would anyone else? I've argued that education is a key component of data loss prevention. AT&T seems to agree (from NetworkWorld):

Q8. How could this have happened?
A. This was a criminal act by an unknown person. AT&T is taking proactive measures to remind employees of the need to protect company property to avoid such incidents in the future.

Training complements, doesn't replace, encrypting confidential data. And, this one can't simply be blamed on "one bad apple" who didn't encrypt his/her laptop if there turns out to be a pattern of storing confidential information in unencrypted form on mobile devices. Saying there are policies in place isn't enough either. Writing policies is like wearing buttons with political slogans - it's the follow through that really matters.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/760

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net