Sunday | 12 October, 2008
Computerworld
Insider threat being blown out of proportion?
Intellectual property should be a high priority
John Peters (Network World) 20/03/2007 12:56:06

Related Features
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Process Trip 04/02/2008 13:07:03

    Why Maritz Travel revamped key business processes — and how business and IT came together to make it work
    When Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture
  • +

    Doing Your Sums on . . . Build, Buy or Rent 05/11/2007 13:32:30

    You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?
    CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

I've read the recent news about intellectual property breaches at large companies and wondered if the need to protect this data is being blown out of proportion or if my company should be concerned about who has access to what on our network.

To those who say that protecting intellectual property (IP) isn't a high priority, I'd ask them where their organization would be without it. In today's competitive marketplace, IP sets companies apart from their competitors, giving them an edge in the marketplace. Recent breaches of intellectual property at large corporations demonstrate the value of IP and the need to know where IP is on the network and where it goes.

A recent survey by the Enterprise Strategy Group (ESG) found that one-third of enterprises surveyed acknowledge loss of sensitive data in the past 12 months and another 11 percent were unsure if such a breach had occurred.

Also, a new Ponemon study noted that nearly 60 percent of U.S.-based businesses and government agencies believe they are unable to effectively assess or quantify insider threat risks within their organizations, leaving them open to breaches of private data, failed audits, and potential fraud.

Clearly, companies need to define their IP, know where it is, and who has been accessing it. While this may seem like a daunting task, it's much better than the alternative of losing millions due to a breach. The ESG survey found that a portion of the problem with protecting IP lies in the way that companies secure and monitor sensitive data. Moreover, IP is still not treated with the same security precautions that are associated with personally identifiable information (PII), which falls more heavily under federal regulations.

While many people can easily define what falls under the PII umbrella (fixed formats like social security numbers and credit card information), defining IP leaves many, including security professionals, in the dark. Yet before an enterprise can protect its IP, it has to know what its IP is, where it is located, the ways in which it can leave the organization, and the best way to protect it. These steps seem easy enough, but dealing with them can be a challenge. Moreover, the ESG study found that IP can leave the network in many different ways. One-third of companies' sensitive data and IP exists in application databases where it can be centrally secured and managed. An additional one-third resides in file systems. This is contrary to past reports that indicated e-mail is the number one source of confidential data.

With company secrets unsecured on the network, it's no wonder that about 80 percent of companies identified the biggest threat to their data as internal, due either to malicious or negligent insiders or to faulty controls and oversight. What's surprising is that while nearly 60 percent believe IP is likely to leak out of their company via traffic such as email or the web, about 25 percent admit they are not inspecting such traffic.

The solution to this challenge is to define and detect IP by location and format. The best solutions should give organizations the chance to customize their own definitions of IP and identify it as it moves across the network. Clearly, random, manual inspections of IP, which is the method most used by those in the ESG survey, will not provide the level of protection needed. The ability to automate the detection of sensitive data in files, emails, databases, and shared portals is a critical step in protecting the data. When enterprises can automatically discover all their IP, when they can apply all their policies across all formats and all ports, they can do a better job of preventing data leaks.

John Peters has built a distinguished executive management career in Silicon Valley. As CEO of Reconnex, he is responsible for the leadership, strategic direction, and successful growth of the company and its employees. He has been CEO of several venture-capital backed companies including PocketThis, an application software provider to mobile carriers; Yipes Enterprise Services, an enterprise-focused provider of Ethernet network services within and between cities; Netli, a software-intensive network service business; and Sigma Networks, a provider of broadband metropolitan area services.

More about Sigma, Sigma Networks, VIA
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

How to Beef Up Your Sales Pipeline

Our economy may be heading towards a recession. Sales rates are dropping. Promotional campaigns are proving less effective than you would like. So how do you continue to grow your business and bring home the sales in such an environment? Download this white paper now to find the answers.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links