MichaelPeters.org

  • CRM
  • PMP
  • 0
  • 1
  • 2

MichaelPeters.org - Your Personal CXO, LLC

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

Reasonable Duty of Care: Data Security and Privacy

0

By Michael Peters on January 31st, 2013

ata breach, breaches, reasonable duty, IT security, Privacy, Hacker, Default password, litigious society, Reasonable Duty of Care, Data Security

You’ve see it in the news all too frequently now in our technologically interconnected world; companies are being breached seemingly at-will by hackers, malicious insiders, competing company entities, and nation states. The terrible truth is that companies and consumers are losing the battle. The cost of these breaches is rising as consumers are beginning to hold companies responsible for the mishandling of their personal and private information.

Terrible Truth: The average organizational cost of a data breach increased to $7.2 million and cost companies an average of $214 per compromised record. (Source: Ponemon Institute)

Any company that collects, communicates and manages a customer’s private information has a reasonable duty to provide for the security and confidentiality of that information. This is especially true of organizations that are compensated for these confidential services. Consider for a moment what types of confidential information you manage for your clients and then consider whether the security and privacy measures you have protecting that information are reasonable and appropriately maintained.

Terrible Truth: 96% of breaches were avoidable through simple or intermediate controls according to a recent study. (Source: US Secret Service)

Implementing security infrastructure such as a firewall or installing anti-virus software on your work computer or mobile device are important steps towards demonstrating reasonable care, but not all. What are some other security and privacy measures a company should consider? How about basic technology maintenance such as software patches and adhering to simple security best practices such as strong information access controls for starters!

Software updates on your network infrastructure devices such as firewalls are no less critical than your work computer. Software patches are released by vendors to eliminate operational and security problems associated with those products. If you neglected the maintenance of those products, you’d run a significant risk that some hacker will exploit that weakness and take control of your company or steal confidential information. Do you realize that if a hacker breaks into your company firewall by exploiting a software bug or using a weak password, that that hacker could intercept and eavesdrop on all of your activity and messages passing through that firewall? It’s true! Do you realize that many passwords, even default passwords are commonly known and published on the Internet for anyone to use? All of these commonly used passwords are integrated into hacking tools used to break in systems with breathtaking ease. Do you think that using passwOrd as your password is secure? Guess again! I guarantee a hacker will not need to.

If you are responsible for the security and privacy of a customer or client’s confidential information, don’t overlook the fundamental security measures that are the catalyst for the majority of security breaches today and yet are so avoidable. Information security is a complex undertaking and given the dynamic threat-scape out there, it’s no surprise that many companies are unknowingly neglecting some of the security fundamentals like maintaining firewalls software patches or some other security task that is relatively out of sight, out of mind. When in doubt about what you should be doing, enlist the assistance of qualified security professionals. I assure you, in today’s litigious society, neglecting security basics could cost you your business.

Stay secure my friends!

If you are interested in contacting us for more information about the content and services offered by Your Personal CXO, LLC or for media interview inquiries or aggregation requests, please use the following contact methods:

By phone: 1-762-822-4174
By email: retainme@yourpersonalcxo.com

Share this:

  • Email
  • Print
  • Digg
  • Google +1
  • LinkedIn
  • Twitter
  • Tumblr
  • Pinterest
  • Reddit
  • StumbleUpon
  • Facebook
  • CXO, Law, Lazarus Alliance, Your Personal CISO
  • ciocisocsocyberlawleadershippoliciesprivacyrisk managementsecurity it
  • Search

  • Your Personal CXO

  • The Security Trifecta

    Hire the experts to implement The Security Trifecta in your organization. Click for more information!

  • Louisville Metro InfoSec

    The Louisville Metro InfoSec is the premier ISSA information security conference!

  • External Services

  • Thousands of other great people can't be wrong! Enter your email address to subscribe to this blog. -

  • Affiliates

  • RSS SBN RSS

    • Secure Configurations for Firewalls, Routers, and Switches – Critical Control with an ROI!
    • Motive and motivation are the ONLY skills a real hacker needs
    • Gun Fight at the OK Corral
    • Senator’s wife lashes out at (probably) fake women chasing her man on Facebook
    • Red Dawn: Protecting small organizations from attacks
  • RSS The Register

    • Icahn doubles down on Dell offer with $14 per share buyback scheme
    • Kiwi telco Two Degrees to roll out 4G in 2014
    • TypeScript 0.9 arrives with new compiler, support for generics
    • Google mounts legal challenge to surveillance gag orders
    • It's time to suck the marrow from the NBN debate
  • Categories

    • Books
    • CXO
    • Featured
    • HORSE Project
    • HORSE Project V1
    • Kickback Cafe
    • Law
    • Lazarus Alliance
    • Life Learner
    • Obsolescence
    • Projects
    • Remember
    • Securing the C Level
    • Syndication
    • The Security Trifecta
    • Uncategorized
    • Your Personal CISO
  • Archives

    • March 2013
    • February 2013
    • January 2013
    • December 2012
    • November 2012
    • October 2012
    • September 2012
    • August 2012
    • July 2012
    • June 2012
    • May 2012
    • April 2012
    • March 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011
    • January 2011
    • December 2010
    • November 2010
    • September 2010
    • August 2010
    • July 2010
    • June 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • May 2008
    • April 2008
    • January 2008
    • December 2007
    • July 2007
    • June 2007
    • May 2007
  • Get the app!

    Your Personal CXO now on Android!

  • Get the app!

    The HORSE Project now on Android!

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

More on Your Personal CXO, LLC

  • EXTERNAL

    • AppHappening
    • CheckSavvy
    • Dynamic Clinical Systems
    • eLance
    • HORSE Project
    • Maprehend
    • Quest for Tech
  • Meta

    • Register
    • Log in
    • Entries RSS
  • Recent Posts

    • The Policy Machine
    • Top 1% Most Viewed LinkedIn Profile
    • Reasonable Duty of Care: Data Security and Privacy
    • Security Overlooked: Weathering the DDoS Storm
    • Please Vote for this blog!
  • Top Links

    • clouds (70)
    • No Title Given (57)
    • mba-mdp (47)
    • site (30)
    • peters-wgu-sbit-infosec (25)
    • CISSP-MDP-2013 (23)
    • An Introduction (21)
    • http://michaelpeters.org/?page_id=336 (21)
    • LinkedIn.com (19)
    • CMBA-MichaelPeters-2007 (17)

Copyright © 2013 MichaelPeters.org - MICHAELPETERS.ORG - Your Personal CXO, LLC

 
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.