22 Feb 2007
Nationwide Building Society's recent loss of a laptop that exposed sensitive personal details of 11 million customers highlights the need for a fundamental reassessment of enterprise security, it was claimed today.
Rob Bamforth, principal analyst with Quocirca, said that the incident highlights "elemental deficiencies" with traditional IT security practices.
"The fundamental issue with the Nationwide data theft was that the whole database was loaded on the laptop," Bamforth said today at the NetEvents symposium in Evian.
"The blunder shows the serious issues around the defragmentation of data. The more you fragment data and keep it separate, the more you can protect your assets as there is less to lose.
"This shows that it is not enough to rely on specific security tools such as encryption. Enterprises need something more fundamental than security software and hardware. What you need is a fundamental rethink."
Bamforth added that taking action such as trying to secure firewalls around data centres missed the fundamental changing nature of data mobility.
"Enterprises are just too porous for data. Devices such as 2GB and 4GB memory sticks cost peanuts now so the extraction of data is so simple," he said.
"To fight this enterprises need to revise policies and procedures. This is all about data flow or data management rather than a security."
However, James Collinge, director of product management at security firm TippingPoint, argued that traditional security technologies are evolving to cope with the new threats.
"Today we can look for malicious traffic and perform some kind of function on that traffic. Ultimately we want to do that with content such as social security numbers," he said.
"We want to enforce policy in real time at the microsecond level. But we will not see this anytime soon."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Software Developer / Web Developer (C# ASP.Net) – Leeds...
Required for my Market Leading Client. The position requires...
PHP Web Developer - Nottingham - £20K My client is...
IT Trainer / E-Learning Designer - London - This leading...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Policies & Tools
A classic case of data leakage. There are tools and then there are policies.... The first question that needs to be asked is whether or not having the complete customer data base was an infraction of corporate policy, if the answer is "no" then no tool will help. The best approach is a sound information security/information protection policy followed up with the proper control/enforcement tools. And for those not infosec savy, Firewalls, IDS/IPS systems nor Anit-Virus solution will help control this type of risk.
Posted by: Network Consulting 22 Feb 2007