Click here to monitor SSC

John Magnabosco

SQL Server Development and Data Security

Laptops with Wings

Published Thursday, May 28, 2009 4:03 PM

I have been subscribing to the OSF Data Loss Feed for well over a year. This feed provides me with brief blasts of information about data loss events that are reported around the world. These data loss events consist of sensitive data that is stolen, lost or carelessly disclosed. This has been a very interesting and eye-opening feed to receive.

One of the ways that sensitive data has a habit of being lost is through stolen laptops. The Open Security Foundation's Data Loss DB site reveals that stolen laptops are 22% of the reported data loss events since OSF has been tracking them.

Below are the reported data loss events directly related to stolen laptops in the months of April and May of 2009:

April 2, 2009: Stolen laptop with personal data of 33,000 children.
April 8, 2009: Stolen laptop with 1,892 Social Security Numbers and other personal data.
April 10, 2009: Stolen laptop containing financial account numbers.
April 13, 2009: Stolen laptop with personal data of potentially 14,380 patients.
April 23, 2009: Stolen laptop with personal data of 1,392 patients.
April 23, 2009: Stolen laptop with 1,000,000 Social Security Numbers.
April 30, 2009: Stolen laptop with 225,000 Social Security Numbers and other personal data.
May 5, 2009: Stolen laptop with 1,000 Social Security Numbers.
May 7, 2009: Stolen laptop with personal data of 2,000 patients.
May 13, 2009: Stolen laptop with 47,000 Social Security Numbers and other personal data.
May 28, 2009: Stolen laptop with personal data of 109,000 members.

It is interesting that majority of these incidents relied solely on the laptops being password protected to secure the data or made the assumption that the thief was unaware of the data that was contained within them. It certainly is not a comforting thought for the 1,434,664 + people that were affected by these incidents.

A study by the Ponemon Institute, a research organization that focuses on privacy and information security, indicated that the average cost of a lost laptop is $49,246, with only $1,582 of that figure being the replacement cost of the hardware. These costs include: Detection, investigation, intellectual property loss, productivity loss, legal costs and regulatory costs. An average of $39,297 is directly related to the costs of the data breach itself.

The portable nature of the laptop is its appeal and vulnerability. It is quite tempting to save client data on a laptop so that it may be accessed when you are away from the office. Password protecting files is better than leaving them wide-open; but also consider implementing additional methods of protection. The aforementioned study noted that the use of encryption reduces the cost of a data breach by an average of $20,000. Food for thought.

by Johnm

Comments

No Comments
You need to sign in to comment on this blog

About Johnm

John Magnabosco manages the Data Services Group at one of the fastest growing companies in the United States. He is also a Co-Founder of the Indianapolis Professional Association for SQL Server (IndyPASS), Co-Founder of IndyTechFest, the author of the book titled "Protecting SQL Server Data" and contributing author of "SQL Server MVP Deep Dives Volume 2".
<May 2009>
SuMoTuWeThFrSa
262728293012
3456789
10111213141516
17181920212223
24252627282930
31123456
How to Kill a Company in One Step or Save it in Three
 The majority of companies that suffer a major data loss subsequently go out of business. Wesley David... Read more...

Migrating from OCS 2007 R2 to Lync: Part 4
 Having migrated the rest of our users and legacy resources across and started getting ready to... Read more...

Automated Script-generation with Powershell and SMO
 In the first of a series of articles on automating the process of building, modifying and copying SQL... Read more...

Seth Godin: Big in the IT Business
 Seth Godin has transformed our understanding of marketing in IT. He invented the concept of 'permission... Read more...

Using SQL Test Database Unit Testing with TeamCity Continuous Integration
 With database applications, the process of test and integration can be frustratingly slow because so... Read more...