Home ME Facebook ME LinkedIn ME Twitter map of ME logo

MET

CONTACT US | SUBSCRIBE | NEWSLETTER | RSS

 
Welcome, Guest |   Sign In   |   Register  
 
Print Email Page RSS Feeds

Posted Date: 6/30/2009

A Day At The Breach

By  Ben Halpert
Bzzz. Bzzz. Bzzz. Bzzz.

I glance at the clock as my BlackBerry dances across my nightstand. It's 3:16 a.m.

"Who could be calling me at this unsightly hour?" I mumble.

I pick up the BlackBerry.

"Hello?" I ask in a groggy voice.

"Sir, I'm sorry to wake you, but we've been hacked, all our customer records have been stolen and posted online...I mean all of them. And the database is empty, we lost everything"

"This guy could be an auctioneer at a livestock auction," I say to myself, still trying to wake up.

"We've been hacked!" John screams in the phone.

"Slow down, that part I understand."

John proceeds to provide the detail once again at a more comprehensible speed.

"John, have you initiated the computer incident response plan?" I ask.

"Yes, you are my second call." John explains. "The technical computer security incident response team members are on their way in to the datacenter now."

"Great! I should be in there in less than an hour."

As I finish getting dressed, I grab my copy of the incident response plan from my closet safe and began calling the assigned points of contact. I brief representatives from legal, public relations, IT operations, physical security, and information security operations.

The adrenaline is kicking in now. "I guess I'll skip my first cup of coffee," I think as I walk past the kitchen and head out the door. "Time to work on staying off the cover of the Wall Street Journal."

How will you react if you receive a similar call? Are you prepared to appropriately respond to a breach or compromise of organizational or client information?

While the incident above is a work of fiction, data breaches of client information are all-too-frequent events. According to the 2009 Data Breach Investigations Report from Verizon Business, 285 million records were compromised in 2008. And incidents such as the one described above do occur, such as the recent Virginia Prescription Monitoring Program compromise. If you need help comprehending what 285 million records really means, consider that the size of the US population is roughly 306 million.

If your organization has yet to develop an incident response plan or a computer incident response team, take a look at the resources provided by the Carnegie Mellon CERT. And don't forget to simulate your plan to ensure that it meets the operational realities of your organization.



Ben Halpert, CISSP, is an information security researcher and practitioner and writes monthly about security. Comments, questions and requests can be sent to him at editor@mobileenterprisemag.com; please include SECURITY in the subject line.


Rate this Content (5 Being the Best)
12345
Current rating: 0 (0 ratings)

 


Show Off the Rugged: Next Gen Devices Modernize the Field
5/15/2013 2:00:00 PM (EST)
Moderator:
Dorene Rettas, Publisher, Mobile Enterprise
Panelists:
Michael Ho, Regional Service Manager, Canon Canada Inc.
David Krebs, VP, Enterprise Mobility and Connected Devices Practice, VDC Research
Mika Majapuro, Product Marketing Manager, Honeywell
Wes Rupel, Co-Founder, President and Chief Technology Officer, Allegro Mobile Solutions
Savino Griesi, Co-Founder and Chief Executive Officer, Allegro Mobile Solutions
View On Demand

Mobilizing Your Ecosystem through BYOD and MAM
3/28/2013 2:00:00 PM (EST)

Moderator: 
Lori Castle, Editor In Chief, Mobile Enterprise

Panelists:
Chris Marsh, Principal Analyst, Yankee Group
Gabriel Weiss, Head of Interactive Marketing Technologies, Mitsubishi Electric

View On Demand

Mobile Engagement: Leveraging Cross-Channel Communications to Improve Business Operations Mobile Engagement: Leveraging Cross-Channel Communications to Improve Business Operations
5/15/2013
As enterprises recognize the need for a mobile strategy, there are many challenges to capitalizing on the opportunities. This paper explains why enterprises can and should embrace mobile engagement to help solve customer, partner and employee communication challenges.
Download Now

Mobile Application Management - Meeting the BYOD challenge with next-generation application and device management Mobile Application Management - Meeting the BYOD challenge with next-generation application and device management
5/1/2013
Discover how a well-designed Mobile Application Management (MAM) solution enables IT teams to achieve fine-grained control over mobile applications across a range of devices, over every type of network and deployment mode, without impinging on users' privacy rights or damaging end users' personal property.
Download Now


MEDIA KIT | CALENDAR OF EVENTS | EDITORIAL CALENDAR | PRIVACY STATEMENT | TERMS & CONDITIONS | ABOUT US | CONTACT US | PARTNER PAGE
All materials on this site Copyright Edgell Communications. All rights reserved.