Creating a Culture of Security
Why are businesses still plagued by poor data security? Why do we constantly read stories about security breaches, data theft and customer lawsuits stemming from confidential information getting lost or falling into the wrong hands? I say it is because many enterprise managers view security as the method for protecting their information infrastructure, rather than focusing on the protection of the data itself. Organisations, and their clients, are better served when management and staff establish a ‘culture of security’ protecting valuable data and infrastructure resources.
Professional criminals who steal market valued sensitive data, such as credit card data and customer identities, are committing an ever-growing percentage of computer crimes. Sometimes the criminals are inside the enterprise and sometimes insiders and outsiders work together to steal and resell valuable company data as we have seen recently in reports on call centre fraudsters in India and Scotland.
Corporate executives, for the most part, continue to be more reactive than proactive when it comes to securing critical corporate and customer data. When security breaches, such as those that happened at ChoicePoint, Bank of America, TJX and AOL (see box below), make the headlines, the mandate ‘keep us out of the press’ is handed to security managers. The mandate frequently carries no additional budget to deliver the security that is required for the task at hand.
ChoicePoint’s breach was in February 2005 when over 145,000 customers affected.
In February 2005, Bank of America lost computer data tapes containing personal information on up to 1.2 million federal employees, including some members of the US Senate. In May 2005, over 670,000 accounts were affected by another breach.
In December 2006, a security breach at TJX involved credit card data being stolen. Millions of TK Maxx card accounts are thought to have been affected, and some account details have since been used fraudulently. Around 23% of these fraudulent transactions took place outside the US, including the UK.
In August 2006, over 600,000 AOL users had their search queries (over 20 million of them) posted online. The New York Times was able to trace the identity of a Georgia woman based on her search queries.
The cost of security breaches has, for years, been calculated based on the direct cost of remediation. However, classic models to determine the appropriate level of security spending were developed before companies had to publish press releases whenever they had a security breach.
As industry regulations and laws become ever more explicit in terms of best practice security procedures, so do potential liabilities. Plus, we must factor in damage to company brands, declines in stock price, customer loss (and the legal and notification costs). This all means that adequate funding for data security measures become a recognised cost of doing business.
Once an organisation, as a whole, recognises the professional and personal value of the data resource it develops and maintains, it will no longer be an issue of resolving an irritating and potentially embarrassing problem. It will become the key strand in the protection of the informational ‘lifeblood’ of the enterprise.
As more companies develop increasingly detailed security policies and hire compliance officers, security managers continue to report that regulations and security policies are not translating into behavioural change. If anything, security managers report only sporadic enforcement of security policies and growing confusion related to the ownership of the data protection problem in some larger enterprises. In some organisations, there are many different departments and teams that own some part of the data security/privacy problem, with the result being difficulty in reaching decisions and deploying technology and process change.
It is time to acknowledge that security policies and technology alone – without ‘buy-in’ from staff, and enforcement by management – will not resolve the need for regulatory compliance, nor the safety of customer, partner and employee information.
Security tools will play their role in securing sensitive data from acquisition by the enterprise until its storage and deletion. However, it remains the task of management to make real-world assessments of risks to data, how those risks are best mitigated and how these assessment decisions are promulgated and enforced throughout the enterprise. But ultimately, as I see it, the real challenge is in establishing an enterprise-wide cultural shift in the protection of data – not the network infrastructure that supports our manipulation of information. Where staff and management view their data resources as central to the health and success of their organisation, the right tone will be struck.
But how do you develop an enterprise-wide security architecture, and a shared set of software tools and procedures, matched to the regulations in-play and the levels of control effectiveness required for effective compliance? When managers ‘matrix’ regulation requirements against actual business functions, and eliminate security control redundancies, they ‘right-size’ data security management to the actual needs of the organisation. They also gain the best control of the costs incurred for meeting the imperatives of continuous compliance.
Continuous compliance is about managing commonalities – technology, policy and procedural commonalities. A regulation and legislative compliance strategy based on risk-based prioritisation is valuable, so why not start with agreed-on risk analysis and threat profiles top-down, rather than specific regulation dictate-up?
The first, and most important, step is to recognise that data security must be enterprise-wide. Data security management applies to internal databases, applications and files. It is not only a network-perimeter firewall but also a broadly distributed, centrally managed, security plan, with clearly defined and audited policies. Foster a culture of security, in which employees understand that protecting sensitive data is central to the firm’s, and their own professional success. First, determine if you have a data-asset problem:
If any of these conditions exist, then a potential compliance problem exists as well. There are other tests but these are three critical proofing points.
Once an organisation knows what to protect, and how to comply with applicable regulations, compare the steps that need to be taken to meet the actual dictates of the compliance regulations. You can wring out cost when you know exactly what you must do to comply with specific rules for specific kinds of information – fit the compliance activity to the need-for-regulator-to-know.
Establish simple data inventory metrics to determine the level of confidentiality for sensitive information. When managers view compliance from this perspective, enterprise security is no longer an ‘add-on’ but a contributing element to overall business goals.
Because so many privacy and compliance regulations overlap in protecting data, here are some additional recommended actions for a successful compliance programme:
Governments and regulatory groups have become increasingly aware of the imperatives for transparency in business transactions, and the business and social need for the protection of sensitive information. Legislation at state, national, EU and other regional levels continue to take up the resources of enterprises as they comply with laws addressing financial reporting, customer/client confidential data and people’s health records.
While a business manager may choose to view the current state of affairs as the result of bloodless bureaucrats placing undue burdens on the business community, the fact of the matter is that societies demand attention is paid to fairness and openness – both in business dealings, and security and confidentiality in the handling of individuals’ sensitive information.
There is every reason for the enterprise not only to respond creatively to this data security challenge but also to employ it as an engine for more transparent, efficient – and profitable – operation. The question becomes not how can I shed the regulatory weight, but how can I manage it most efficiently in my enterprise-wide operations – perhaps even getting a competitive edge over other businesses in the same market space. A culture of security helps establish an environment that is beneficial to enterprise as well as its customers.