Please wait while the page is being loaded Skip this advertisement >
Friday | 5 December, 2008
Stolen Laptop Prompts Call for Internal Reviews
Jaikumar Vijayan 24/04/2000 12:01:01

FRAMINGHAM (04/24/2000) - If your firewalls, intrusion-detection software and encryption technologies make you feel safe, think again.

As the recent incident involving the theft of a U.S. State Department laptop demonstrates, having the best protection against external crackers means little if sensitive data is allowed to simply walk out the door.

"Statistically, 60% of computer crimes happen inside [companies]," noted Winn Schwartau, founder of the security consultancy Interpact Inc. in Seminole, Florida.

"Putting all your efforts on intrusion detection at the perimeter of the network is a failing policy if that is all you are going to do," said Schwartau, who is releasing a book on security issues, called Cybershock, later this month.

The State Department last week said the FBI is leading an investigation into the disappearance two months ago of a laptop that might contain highly classified material. Last month, a laptop containing sensitive data about Northern Ireland was stolen from an agent of Britain's MI5 internal security bureau.

Laptop theft poses a major risk when it comes to compromising corporate data, and it will only get worse with the increase in the use of handheld devices, said Chris Christiansen, an analyst at International Data Corp. in Framingham, Massachusetts.

Safeware, The Insurance Agency Inc. in Columbus, Ohio, estimates that 319,000 laptops were stolen in the U.S. last year.

People are walking around carrying "corporate passwords, internal phone lists, memos and details on proprietary projects" that could cause damage if it were to fall into the wrong hands, Christiansen warned.

A virtual flood of products for securing laptops and tracking them down when stolen is available from vendors such as Absolute Software Inc., SAFlink Corp., Targus Inc. and Quantum Power Labs Inc.

The Toronto offices of insurance firm Jardine Lloyd Thompson Canada Inc. used one such product to quickly track down a laptop that was stolen from an employee's car last year.

Today, the company has the software installed on all laptops and has instructed its employees not to leave notebooks unattended. "But generally speaking, the larger the corporation, the more difficult it becomes to police these things," said Rick Smith, the firm's vice president of information technology.

Taking Practical Steps

"If you are concerned about sensitive information being carried on mobile devices, you want to be able to impose control on who can access that information," via measures like encryption, said Eric Hemmendinger, an analyst at Aberdeen Group Inc. in Boston.

Laptops are by no means the only source of risk, though, analysts warned.

Security risks include people who inadvertently unleash viruses on corporate networks, disgruntled employees, indiscriminate access to corporate facilities and a lack of controls over who gets access to the Internet. So it's a mistake to rely solely on technology to reduce security risks, Schwartau said.

Instead, Schwartau warns in his book, corporations need to focus on employee education and awareness training, putting security policies in writing, shredding materials such as personnel lists, erasing hard disks prior to disposal and periodically checking company passwords to make sure they're not easy to crack.

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101

Email archiving is emerging as a critical new application for managing email. Learn how to reduce and manage online and offline email storage, add powerful tools for legal discovery and compliance and extend native exchange recovery capability by reading on.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links