Showing posts with label Breach. Show all posts
Showing posts with label Breach. Show all posts

Monday, February 18, 2019

Friends Don’t Let Friends Hire Their Friends

Friends Don’t Let Friends Hire Their Friends
Jeff Hyman, Forbes 
Balancing relationships in and outside of the workplace can be a difficult juggling act; however, when a friend is hired in the workplace, that makes the juggling even more difficult.  This new co-worker who is seen as an emotional confidant outside of work, might receive office favoritism and act as a person to confide in.  Northwestern Business School professor Jeff Hyman believes that mixing friendships and work isn’t the best practice, but gives several steps/things to consider if you are going to hire a friend.    

Monday, February 4, 2019

Are Your Passwords Strong Enough?

Are Your Passwords Strong Enough?
Adam Levine, Inc.
The use of passwords to protect online accounts isn’t going anywhere soon.  According to a study last year by SplashData, however, of the 5 million passwords that were compromised by hacks last year, many of those hacks occurred because the user created “weak” passwords, such as ‘password’, ‘sunshine’, or the ever-popular ‘12345’.  Read more about why strong passwords are so important, and learn six simple rules in selecting passwords to protect information.  

Tuesday, January 1, 2019

Dolvin Notes - January Video Picks


Dolvin Notes - January Video Picks For You

How to Protect Yourself
How to minimize the impact related to a data breach 


Sunday Driver
How self-driving cars could become a reality

Design Guru
How a Harvard professor uses toys and origami to transform design


Friday, January 20, 2012

Zappos customer data accessed in security breach

Zappos is apparently one of the latest data breach victims.  Or, perhaps their customers are the latest victims.  Zappos feels that that the information was limited in scope, because the entire credit card number was not exposed (that is what they believe).  Many data thieves compile information from many sources to build complete profiles on people.  It just takes some patience and time to put together information that can be sold to the highest bidder.  It is a volume business and the 24 million customers are just bigger targets now.



You may read the CNET article by clicking this link:


There is no perfect solution, the mice get smarter and the traps more complex, but in time unless there is a proactive approach, “they” will get in and the damage will be done.

Here is the big message in the article and it applies to everyone, not just Zappos:

"We've spent over 12 years building our reputation, brand, and trust with our customers. It's painful to see us take so many steps back due to a single incident" Hsieh wrote in the letter.

An organization builds their reputation one satisfied customer at a time.  It takes years of effort to ensure your customers are happy.  It is evidenced by the referrals you get.  Then, in an instant your well earned reputation is gone. 

The data breach notification is the tip of the ice berg.  The piracy may have actually been going on for a time and the breach turns on the lights.  Other times it may be a single event.  As far as your customer cares, it puts them in jeopardy.  The only thing slightly in your favor is that people not directly affected are becoming numb to these news stories.  Never thinking it would happen to them, until it does and your company gets the blame and loss of business.

The bad publicity comes. The regulators come.  The forensic people come.  The remediation comes.  Then you try to rebuild your business. 

What comes after an event like this is what should have been in place in the first place.  A Written Information Security Program (WISP) plan.  You may think of a WISP plan in these simple terms.  It is a fire drill for a data breach.  You plan, practice, and protect hoping that you will never use what you have learned, but in the case when it is needed, it saves your life. 

A WISP plan is not a static document that sits on a shelf collecting dust.  That is what makes it different and what satisfies and creates a defensible position with the regulators.  A WISP plan involves a risk analysis of your organization and appropriate, best practice, measures are implemented.  It is different and scales for each organization.  Every company has some exposure, some more than others.

No one can promise you anything, not even us, but you should contact Dolvin Consulting to determine your Risk Quotient.  You cannot hide your head in the sand.  It is your responsibility to find out what you can to protect yourself and your customers, supplier, and employees.  Contact us today to see how we can help you mitigate the risks associated with the private information you are responsible for.



Friday, December 23, 2011

Santa Claus’ Workshop, Naughty/Nice List Databases Hacked

Proprietary Data and PII of Billions Exposed.  The Grinch, Disgruntled Elves, Anonymous Lead List of Suspects in Data Theft.





Well... just imagine it was your company that was breached.  Santa probably has a healthy bank account and can weather the storm of bad publicity.  After all if his organization fails, there is always mom and dad to do the shopping and delivery.  It is not like there is a lot of competition.  Where else are kids going to write at holiday time?

Maybe you do not consider your information all that valuable.  Perhaps your company has no proprietary information.  Is there employee information?  What about customer credit information?

What happens to your business’ reputation? 

It is hard enough finding a business, partner or supplier that you trust in the first place.  As a business, how hard is it to keep your customer’s happy?  What effect would a data breach have on your existing relationships?

It is very difficult to calculate the costs of a data breach on a business.  At least one that survives and does file for bankruptcy to protect itself.  The finance team can add up the fines, the cost of auditors and regulators, the pots of coffee consumed during the investigation, but what about the loss of reputation?

There is no perfect solution.  The criminals keep getting smarter and the mouse traps more sophisticated.  What you can do is prepare.  That is the role of a Written Information Security Program (WISP) plan.  It creates a defensible position with regulators. It is like a fire drill for data breaches.

Many companies provide technology solutions, but few provide a solution that will be approved by regulators.  Dolvin Consulting and Cyber Security Auditors and Administrators (CSA2) work with your team to prepare, create and maintain a working WISP plan.  A plan that is reviewed, tested, and updated each year.  A plan that will help mitigate the risks and let you sleep at night.

The ball is in your court.  Contact us today to see how we can help become compliant.  Do not let what happened to Santa happen to you.

Friday, December 16, 2011

Study: Hackers and IT pros share personal information online

A recent study found that tech-savvy people disclose sensitive information to strangers they meet online, even though they should know better and found that Hackers apparently can be just as careless as their victims.




This study focuses on the phenomenon of disclosing private information to online friends who appear to be sharing your interests.  The sample consisted of 100 persons, half of them working in the IT security industry (chosen from a professional network), while the other half dwelt on 'the other side of the fence' - the hacker’s clique (selected from specialized forums for 'bad guys').

Two experimental profiles were created, using the same information (age, sex, interests), but different jobs - corresponding to those of the respondents. After being contacted, the participants were interviewed in order to determine what kind of information they would be willing to disclose to a person working in the same industry, but still unknown to them.

The results suggest that, no matter what side of the fence they are on, people will behave the same: as though the virtual environment creates a second life, entirely different from the real one - they are willing not only to accept unknown persons inside their group just based on a nice profile, but also to reveal sensitive information (about their company, themselves and other persons) after a short online conversation.  This applies to both categories of respondents even though they are aware of the risks such information disclosure would pose in real life.


Well I guess you just cannot trust anyone anymore.  Perhaps with all the social media forums available today we are trying to connect more in an impersonal world.  We should be connected more, we should have a greater sense of community.  What seems to be happening is that we are becoming more and more disconnected, like islands.

Was the appeal of the “Tests” were really people wanting to be connected?  Offer what people seem to want and need and you can get just about anything you want.  Kind of reminds me of some stereotypical sales people that care more for the bottom line than the consumer.

Have we learned anything (yet)?  Well yes, if it is the fact that your private information, yours or someone you are responsible for, is a valuable commodity for the industry that deals with stolen identities and funds.  Yes, that we can all be fooled.  Yes, that we need to be more aware.  Yes, that we need to recognize there is no perfect solution that will protect us from ourselves.

What can we do?  First, think.  Second, before you reply to an invitation or anything online or even in person, think.  Third, hire experts to help you think, because it is a big bad world out there and we all need help. 

Sometimes it is hard to think outside of the box when you are in the box.  That is where Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work best.  We work with your team to analyze your risk quotient and build a working Written Information Security Program (WISP) plan that addresses the volatile nature of information security.  Contact us today to see how we can help you sleep better at night.


Friday, December 9, 2011

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised | AIS Health

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised AIS Health

This is a well written article.  It identifies an ongoing issue that all organizations, not just those in healthcare struggle with on a daily basis.  How do we empower our employees, yet maintain control over social media to protect the private information for which we are responsible?



I support the premise of policies for employees as many do not take the time to think beyond the moment to consider the consequences of their actions.  Many postings as the article points out are innocently placed.  Most people do not realize that enterprising people can take these separate pieces of information and place them together.  In the wrong hands that information is sold to the highest bidder.

The article points out: “There are people who have grown up having everything posted on Facebook, and having no privacy,” Drummond says. “They are posting more” with little thought to the potential impact.

The solution is not to single out any specific social media forum, but rather to invest in education for all workers.  Many simply are ignorant of the consequences.  At the organizational level, the education becomes part of a Written Information Security Program (WISP) plan.

Think of a WISP plan as a fire drill for a data breaches.  It is not a static, shelf sitting, and dust collecting binder.  A working WISP plan is reviewed annually or at any change in business or organizational process.  A WISP plan provides the foundation for a secure environment.  There is no one perfect solution.  Any plan that incorporates humans has the potential to break down.  In the event of a breach, there are well documented procedures that will mitigate damages and help create a defensible position for the regulators that are sure to be involved.

Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help companies of all sizes manage the risk associated with private information.  Those companies are typically concerned with the threat of lawsuits related to the loss of personal information as well as the loss of their customer base due to the degradation of their reputation.

We cannot promise you that you will never have any problems, but we will do our best to understand your challenges and help you create a working WISP plan that matches your risk quotient.   Contact us today to see how we can help you manage your risk.


Friday, November 25, 2011

Sample Business Associate Contract for HIPAA Compliance

There is no single document, web page, or resource that can provide you with a bullet proof contract that protects both the organization and a subcontractor or business partner.  The government has provided a sample that may cover a percentage of issues that should be addressed.



Click here for the government sample.


This plan is by definition only a guideline, but it is a place to start thinking.  What is missing is the Written Information Security Program (WISP) Plan.  A WISP plan is tailored to the risk quotient of an organization.  It is certainly not a one size fits all solution.  A comprehensive plan will address business partner access as well as the other risks associated with the business operations. 

A WSIP plan is a process not an event.  It is a living, breathing, changing set of documents that evolves with the growth and changes in your business.   Like the sample business partner it should not be done with a do-it-yourself process or attitude.  The idea of a doctor treating themselves should come to mind.  

A WISP plan should incorporate at a minimum Technology, Insurance, Legal, and most importantly Human Resources.  No internal person is likely to have enough expertise in all of these areas.  You need expert outside and objective eyes looking at your business operations.  That is where a resource like Cyber Security Auditors and Administrators (CSA2) helps. 

CSA2 is a resource of resources.  CSA2 has access to leading industry experts.  Experts that will help you prepare, plan and execute a real working WISP plan.  Think of a WISP plan as a fire drill for data breaches.  It may be painful to have to think about these things, but it will be a significantly less stressful exercise than a post breach forensic analysis, government regulated, fine levied eternity.

If you value the relationship and trust build over the years you have been in business with your employees, suppliers and customers, then plan now.  It will take a long time to rebuild trust that can be lost in an instant.  An instant that was preventable.  

There is no perfect  mouse trap and the mice keep getting smarter, so even a great WISP plan cannot prevent all disasters, but a good plan will allow quick response and create a defensible position.  Everyone needs a plan that is tailored to your level of risk.  Hopefully you will contact Dolvin Consulting to see how we can mitigate your risks.  Call now, the time invested is well worth the peace of mind. 

Friday, November 18, 2011

HIPPA Audits and Compliance

Alan Heyman, Managing Director of Cyber Security Auditors & Administrators LLC (CSA2) was contacted and quoted recently, because of his expertise in working with companies to help them determine their risk quotient. 

Automating HIPAA Compliance Tracking and Audit Preparation

The article is a quick read, but reading between the lines may take a bit longer.  Alan is of course talking about a Written Information Security Program (WISP) plan and a WISP-Vault which is a highly secured storage facility to keep the plan safe. 




There has never been a perfect mouse trap and the mice keep getting smarter.  You cannot engineer a perfectly secure environment when humans are involved.  A WISP plan is more than a fancy binder filled with out-of-date information sitting on a shelf in someone’s office collecting dust.  It is a process, not an event.  A real WISP plan is a living breathing environment which is kept up to date with the changes in your business.

Think of a WISP plan as a fire drill for data breaches.  You plan, prepare, and practice over and over so that in the case there is a data breach everyone stays calm and you implement the right corrective action in a timely manner.

You cannot keep the auditors away, but you can be prepared.  A working WISP plan creates a defensible position that will protect you and your business.  The preventative medicine might taste a little bitter, but is a lot less painful than cure.  You know the saying Ben Franklin made famous: “An ounce of prevention is worth a pound of cure”.  Ben made this observation long before there were computers or HIPPA concerns.

Every business has its own risk assessment and the solution is based on potential exposure.  You would prepare your home if you knew a storm was coming, so why not do the same with your business.  Start now by contacting us to see how we can help. 

Dolvin Consulting works with organizations that are worried about lawsuits related to the theft of personal information and are concerned about the loss of customers related to a data breach.

Friday, November 11, 2011

HIPPA Enforcement Promotes Compliance

Leon Rodriguez, the new director of the Department of Health and Human Services' Office for Civil Rights, describes his HIPAA enforcement agenda.


"As I've learned as a prosecutor and then as a defense lawyer, enforcement promotes compliance," Rodriguez says in an interview with HealthcareInfoSecurity's Howard Anderson. "The fact that covered entities out there know that they are at risk for penalties is something that, in fact, in many cases will promote compliance."


The full article can be found by clicking here.  Some excerpts are below. 


ANDERSON: In recent months, as you just alluded to, the Office for Civil Rights has significantly ramped up its HIPAA enforcement efforts.  Under your leadership can we expect to see your office announce more resolution agreements in civil monetary penalties and other enforcement actions?
RODRIGUEZ: I think you can expect that; absolutely you can expect that.

ANDERSON: The Office for Civil Rights recently hired KPMG to launch a HIPAA audit program. What would you like to see that program achieve, and is it possible that any of those audits will result in sanctions or penalties?
RODRIGUEZ: This is the first time we're doing it, so the first thing ... is for us to 'go to school' on how best we will run an audit program. In part, this is what you might call a pilot. We're going to look at it and learn: How do we use an audit program? How does an audit program best advance our enforcement goals?

The second purpose, and this is really different than enforcement, is to promote compliance among the covered entities that are subject to the audit.  Our first objective is not to go out there and start banging [organizations] with penalties; it's really to take a good look at them, find out where their opportunities for improvement are and help them improve.  Having said that, I think we know that there are cases where we're going to find some significant vulnerabilities and weaknesses.  And in those cases, we may be pursuing significant corrective action.  And in some of those cases, we may be actually pursuing civil monetary penalties.  But that's really not the primary goal of the audit program.



Rodriguez’s goal is to audit and learn, but even then he acknowledges they will pursue significant corrective action.  You can interpret the interview in several ways and they may all be correct to some extent.  What I suggest you walk away with is that the casual compliance days are over.  If you are found at-fault for a data breach, you will be subject to fines and other penalties.

In a post breach situation, there is no moderator.  Your organization will be held accountable.  Your client base will lose confidence in your operations and unless you are the only one performing that service, your clients will go elsewhere.  The publicity of the lawsuits will ensure a degradation of reputation and client base.

The only real course of action is to address your Risk Quotient in a pre breach environment.  Your organization will have the luxury of being able to take the time to plan and prevent data loss.  Preparation is like a fire drill for data security.  Plan and practice in the hopes you never need to use what you know.  But, if you do, then you will know what to do and when and the result will be a defensible position for the regulators.

Dolvin Consulting works with Cyber Security Auditors & Administrators (CSA2) and your organization to prepare, plan and implement a Written Information Security Program (WISP) plan.  The WISP plan is your key to sleeping well at night.  Contact us today to start a conversation that will help you connect with resources that can help with your compliance challenges.


Friday, November 4, 2011

Wells Fargo mixes up customer statements

Wells Fargo mixes up customer statements The Post and Courier, Charleston SC - News, Sports, Entertainment

There was a time that this would have been laughable.  As a bank customer you could understand that some machine was out of sync and documents where mismatched with envelopes.  In fact, in the “old” days when you actually received your canceled checks back with your monthly statement I remember receiving someone else’s canceled checks.  I contacted the bank and they were able to straighten out the mix-up.  It was not something we worried much about, back-then.



Today’s world is much different.  Data breaches are linked to identity theft.  Identity thefts create so many challenges for the victims.  Bad credit scores, denied loans, governmental actions and of course, lots of aggravation for the victim and what seems like little penalty for the culprit, if they are ever captured. 

The only party the government seems to be able to touch effectively is the original holder of the information, in this case the bank.  The regulators have their calculators lined up, charging fees and fines.  In a post breach situation, the offending organization is at the mercy of the regulators and courts.  In some cases there really is some negligence and the penalties are justified.  Sometimes these organizations become scapegoats for the industry.



Whenever an organization finds itself in a post breach situation it is like a roller coaster ride.  You just have to ride it out and pay whatever you have to make the problem go away and identify and remediate the vulnerability.

What a difference it makes in a pre breach situation.  You have the time to do audit and analysis, testing and documentation.  Parts in a well organized Written Information Security Program (WISP) plan.  Of course, there is more to a WISP plan than a technology audit.  WISP plans ensure that all aspects of information technology infrastructure, human resources, legal, and insurance issues are addressed.  The depth and expense of a WISP plan is tied to the complexity of the operation it is designed to protect. 

A WISP plan is not an event, it is a process.  A process too complex to be navigated alone.  That is why Dolvin Consulting has teamed up with industry experts Cyber Security Auditors and Administrators (CSA2) to work with your team to design, plan, and implement a working WISP plan so that you can sleep at night.  Contact us today.  We are here to help!

Friday, October 28, 2011

Encryption 101


For many people, the word "encryption" invokes images of spies, clandestine operations and World War II code breakers feverishly working to decipher enemy messages. Actually, encryption is a priceless security tool that any business can easily use to keep sensitive information confidential and safe from prying eyes.



This article from IT Security highlights some important information about encryption.  As the article title implies, this is a basic overview of what encryption is and how and why you might want to take advantage of this technology. 

What would be nice is a link to an Encryption 202 article.  The article would cover corporate compliance and policies.  When the information we work on contains private information, information containing names, addresses, email addresses, social security, or credit card information we expose ourselves and our companies to global risk.  When the computer or storage device contains proprietary information that would benefit a competitor, then you have potential losses that mount quickly. 

These loses can encompass government intervention, audits, lawsuits, fines and the degradation of your customer base.  When the mix includes these loses, then the stakes are much higher.  The first thing the regulators will look for is a Written Information Security Plan (WISP).  A WISP plan is security fire drill to prevent data loss and a checklist resource to be used in post breach situations.

A WISP plan ensures that your devices are protected by encryption in addition numerous other attributes, including human resources, legal, and insurance compliance.  We are not trying to make it hard for you to sleep, we just want you to follow the best practices in the industry.  Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help you to determine your risk quotient and build and maintain your WISP plan to match your risk.  Contact us today to see how we can help you.

Wednesday, October 19, 2011

BISD notifies parents of 15,000 students of data breach

BISD notifies parents of 15,000 students of data breach - KFDM-TV Channel Six

No one can really be sure that this information was not retrieved and will not be used for illegal activities.  How well will the parents and children sleep now, knowing that their private information was vulnerable. 



What confidence and creditability has been lost, because someone "thought" only principals could access the information.  Fortunately the student who discovered the breach notified the right people in a timely manner. 

If this was a business, would you want to want to do business with them?  Would you keep doing business with them?  It takes a long time to rebuild the trust lost in a few minutes, because someone thought they had a secure system.

It will be interesting to see if government regulators will now fine the school.  Most businesses will not have much choice.  You have to wonder if they have a Written Information Security Plan (WISP)? 

A WISP plan is more than a set of documents that sit on a shelf and collect dust.  It is a comprehensive plan to ensure data breaches do not happen.  Nothing is perfect and breaches do occur.  The WISP plan defines how to recognize a breach and what to do when one is discovered.  These plans must be updated every year and at any fundamental change in business operations.

If you are wondering what a WISP plan is and if you should have one, then you should and you should contact us as soon as possible.  Typically any organization that keeps private information about employees, suppliers, or customers is required to have a WISP plan.  Private information is a name, social security number, address, credit card number, or any personally identifiable piece of information.  To complicate matters more, each state has its own definition of what needs to be reported and how soon along with how much they are going to fine you.

Dolvin Consulting partners with industry experts Cyber Security Auditors & Administrators (CSA2) to determine your risk quotient and help you plan, develop, implement and secure a working WISP plan.  Contact us today to see how we can help you meet your compliance needs.  We are here to help.

Wednesday, October 12, 2011

Data breach exposes 4.9 million Tricare patients

A data breach affecting 4.9 million Tricare beneficiaries began when a government contractor left backup computer tapes in his car after parking it in downtown San Antonio one day this month. The worker had been given the job of taking the tapes from one federal facility to another when they were stolen.



“How does it happen? ... At one level, the answer's totally carelessness, obviously,” Stahl said.

“Let's take a medical facility. They've got a heart that needs to be transplanted into a patent and they give it to somebody to take from Point A to Point B. Is that person going to stop for eight hours along the way?” he said.

We are human and as humans we are subject to errors.  Errors in behavior, errors in judgment, errors in concentration.  It was on the way.  I was only going to stop for a few minutes.  What could possibly happen?  Who would even know what to do with these tapes?  No one will know. 

It just is not possible to know at this point where the system broke down, but there is a steady trend of these incidents.  It could also be that we are just hearing about them more now.  Bottom line is that you cannot be too careful or take enough care when handling information of this type. 

A Written Information Security Plan (WISP) establishes the guidelines for handling and securing private information.  A plan is only as good as its implementation.  That is why a WISP plan is not a static document that collects dust on a shelf.  It is monitored, updated, and reviewed every year and at any fundamental change in business operations.   It is not a catch all, but it is a necessity that the government looks for in cases like these.  A good WISP plan creates a defensible position. 

Dolvin Consulting works with industry experts Cyber Security Auditors & Administrators (CSA2) to assess your risk exposure and develop the solutions needed to protect your information and to give you the tools to manage your risk.

When your questions outnumber your answers it is time to contact us.


Friday, October 7, 2011

Attorneys General continue to increase legal standards for data privacy compliance

Many have written about it and several have contemplated it -- whether states will adopt private data security standards, such as the Payment Card Industry Data Security Standards (PCI DSS), and use them as legal standards that owners and holders of personal information (PI) must comply with.



That’s exactly what the Massachusetts Attorney General did when it recently filed suit against Briar Group, LLC and alleged, among several other things, that Briar was not PCI compliant at the time of its data breach in November 2009, affecting 53,000 MasterCard and 72,000 Visa accounts.

PCI DSS are private data security standards created by the Payment Card Industry Security Standards Council that apply to all organizations collecting credit cards. The Complaint alleged that Briar’s failure to implement basic data security measures on its computer system allowed hackers to gain access to Briar’s customers’ credit and debit card information.

Please see full article for more information.

Briar ultimately settled with Massachusetts through a consent judgment with the following penalties, in part:
Briar Group to pay State of Massachusetts $110,000;
Establish a Written Information Security Program;
Maintain PCI compliance and verify same within fourteen days;
Revise password management process; and
Implement various network system changes.


So here is a point that Briar Group or any company that is responsible for private information about their employees, suppliers or customers should consider.  Having a Written Information Security Plan (WISP) in place "Before" a breach happens is a worthwhile investment. 

So much so, that if they were compliant with a working WISP plan, they might not have been breached in the first place.  Fire drills save lives, because people are prepared and can stay calm in an emergency. 

A WISP plan prepares an organization.  The "plan" ensures that a company follows industry best practices.  Nothing is perfect, but the heavy fines and bad publicity are minimized by being prepared.  A WISP plan creates a defensible position.

Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work with organizations that are worried about the threat of lawsuits related to the loss of private information and concerned about the loss of their customer base from the erosion of confidence that results from data breaches.

Contact us today to see how we can help you sleep better at night.



Thursday, September 29, 2011

Las Vegas Identity Theft Case Ends After 15 Years - ABC News

Las Vegas Identity Theft Case Ends After 15 Years - ABC News



This article came to my attention on Twitter, and I would have to agree with one readers comment ( ) that "We need stronger protection for consumers and stronger penalties for businesses that allow our data to be stolen."

Worse than the identity theft, is the loss of time and energy spent trying to resolve this case with an unresponsive government that seems utterly clueless.  His case cannot have been unique.  Why did it take so long?

Until sometime in the future when we do not rely on this type of information we are all going to be potential victims.  Now is the time for businesses to batten down the hatches.  Invest in an audit and take the precautionary steps to protect the information your customers entrust with you.

Dolvin Consulting works with Cyber Security Auditors and Administrators (CSA2) to help businesses create and maintain a Written Information Security Plan (WISP).  We help you prepare for the worse, like a fire drill, in the hopes you never need to use what you know.  You cannot be too prepared and if the worse should happen you will have peace knowing that you did everything possible to prevent the breach and you have a solid plan to restore your customer’s faith your business.

Contact Dolvin today to see how we can help you prepare for future data breaches.  We have Forensic experts available if you have already been breached.   

Remember that an ounce of prevention is worth a pound of pain.  We help you sleep better at night.



Wednesday, September 28, 2011

Why Passwords are not Strong Enough



The risks associated with the use of password-only authentication are not new. In 1995, the US Computer Emergency Response Team (CERT) reported that approximately 80 percent of the security incidents they received were related to poorly chosen passwords. More than fifteen years later, two-thirds of organizations are still using just a password to secure remote access1.
With today’s threat landscape and the increased value placed on the information created and stored, systems that rely on static passwords for security are left vulnerable and at risk of being breached. In this paper, we will examine the need for strong authentication and explore the return on investment that can be realized in order to help organizations make an informed decision when contemplating their strategic move toward more effective security.

“One out of four employees write their passwords down on paper in order to remember them”. 

Okay, now we have to think.  Am I guilty of writing passwords down?  How do we keep track of so many passwords for so many sites?  So many companies that we do business with today have online sites that we use to improve our efficiency.

There are a number of tools and tricks to create and remember the passwords, but as we grow ever more dependent on technology, we will need new, better solutions.

In the mean time Dolvin Consulting works with security experts Cyber Security Auditors and Administrators (CSA2) to help your company prepare for and prevent data breaches.  Contact us today to schedule a risk assessment of your business.

Wednesday, September 21, 2011

Senator to businesses: Protect data or pay

Senator Richard Blumenthal says his data breach legislation will deter data breaches. IT security experts have their doubts



Senator Richard Blumenthal, D-Conn., says his newly introduced legislation, the Personal Data Protection and Breach Accountability Act of 2011 will protect individuals' personally identifiable information from data theft and penalize firms that don't adequately secure their customers' information. Naturally, there are skeptics.

The bill would establish "appropriate minimum security plans" for businesses with 10,000 or more customers to safeguard their customer information and hold those businesses accountable through fines should they fail to meet those standards. The bill also calls for more public/private information sharing.

Click here or the headline above for the full article.



Certainly "larger" companies should already have and maintain a Written Information Security Plan (WISP).  They should already be allocating budget dollars to their security plan.  But what about all of the other companies that operate with information that should be kept private? 

Best practice in the industry suggest that all companies should be addressing their particular risk assessment.  For some smaller companies it is a simple process.  As the company size grows, so do the complexities of risk management.

Dolvin Consulting works with industry experts Cyber Security Auditors and Adminstrators (CSA2) to help companies of all sizes calculate their risk exposure and take the appropriate steps to safe guard their client and employee relationships. 

Think of this as a fire drill for a data breach.  You hope you never need it, but you will be prepared for the worse.  Contact Dolvin today to see how we can help you get a decent nights sleep.