When news of a major data breach, like the recent one at Capital One, makes headlines, the first response of many business owners may be to breathe a big sigh of relief that it wasn’t them. However, it’s critical that companies use these publicized breaches as a reminder to review their own systems and to see what lessons, if any, they can learn to improve their own data security.
In late July, Capital One announced that approximately 100 million people in the United States and approximately 6 million in Canada had been impacted when an individual gained unauthorized access to its systems and obtained personal information about both Capital One customers and those who had applied for a credit card in the past. It was later reported that a former software engineer for Amazon Web Services, a cloud computing provider used by Capital One, had accessed the data by exploiting a misconfigured firewall.
This serves as a reminder that many data breaches are not the result of anonymous hackers, but are committed by people who have legitimate reasons to access the data but choose to do so with bad intentions. One of the biggest lessons for companies in this breach may be that if there is a person within your organization intent on stealing your data, they will find a way to do it. However, that doesn’t mean there aren’t steps you can take to help protect your data.
Companies need to have a variety of systems in place to provide checks and balances on everyone with access to sensitive data to guarantee they are only accessing the data required to do their jobs and are not sending it to people who should not have it. Even small companies, where only one person manages IT, should regularly seek help from legal and technical professionals with assessing their policies and IT and data systems to make sure the policies match actual practices, protocols are being followed, and data is secure.
Companies also need to conduct as rigorous of a background check on employees with access to protected data as they do on people with access to the bank account and other financials. In this day, data is often one of the most valuable assets companies have, and needs to be protected as such.
Every company, no matter its size, is vulnerable to a data breach. However, taking the proper precautions can help minimize the risk and, should a breach occur, help them to identify it sooner and minimize the damage.
- Partner
Add a comment
Archives
- January 2022
- June 2021
- March 2020
- August 2019
- March 2019
- October 2018
- July 2016
- June 2016
- May 2016
- February 2016
- November 2015
- September 2015
- July 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- July 2014
- March 2014
- July 2013
- June 2013
- April 2013
- March 2013
- October 2012
- September 2012
- August 2012
- April 2012
- March 2012
- February 2012
- January 2012
- November 2011
- September 2011
- June 2011
- May 2011
- April 2011
- February 2011
- January 2011
- December 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2006
- February 2006
Recent Posts
- Rethinking Your Cyber Insurance Needs as Your Workplace Evolves
- Data Breach Defense for Educational Institutions
- COVID-19 and the Increased Cybersecurity Risk in a Work-From-Home World
- Like Incorporating Facebook into your Website? EU Decision Raises New Issues
- Lessons Learned: Key Takeaways for Every Business from the Capital One Data Breach
- Will Quick Talks to WRAL About Privacy Issues Related to Doorbell Cameras
- About Us
- Not in My House - California to Regulate IoT Device Security
- Ninth Circuit Says You’re Going to Jail for Visiting That Website without Permission
- Ninth Circuit Interprets “Without Authorization” under the Computer Fraud and Abuse Act
Topics
- Data Security
- Data Breach
- Privacy
- Defamation
- Public Records
- Cyberattack
- FCC Matters
- Reporters Privilege
- Political Advertising
- Newsroom Subpoenas
- Shield Laws
- Internet
- Miscellaneous
- Digital Media and Data Privacy Law
- Indecency
- First Amendment
- Anti-SLAPP Statutes
- Fair Report Privilege
- Prior Restraints
- Wiretapping
- Access to Courtrooms
- Education
- FOIA
- HIPAA
- Drone Law
- Access to Court Dockets
- Access to Search Warrants
- Intrusion
- First Amendment Retaliation
- Mobile Privacy
- Newsroom Search Warrants
- About This Blog
- Disclaimer
- Services