Friday, July 24, 2009

Forty-Four Percent of US SMBs Admit to Falling Victim to Cybercrime, According to Latest Panda Security Survey

29 percent of US small and medium-sized businesses lack antispam, 22 percent have no antispyware and 16 percent operate without a firewall - 50 percent lost time or productivity as a result of being infected - 39 percent of respondents said either they or their employees have not received training about IT threats that could affect them. http://finance.yahoo.com/news/FortyFour-Percent-of-US-SMBs-prnews-2714742551.html?x=0&.v=1

Wednesday, July 22, 2009

Social Networking Sites Must Improve Their Security, Says Security Firm

IT security and data protection firm Sophos has called upon social networking websites such as Twitter and Facebook to do more to protect their millions of users, as new research is published examining the first six months of cybercrime in 2009.http://finance.yahoo.com/news/Web-20-Woe-Sophos-Threat-bw-957043460.html?x=0&.v=1

Monday, July 13, 2009

What CEOs Don't Know About Cybersecurity: A new study hints at how often cyberthreats aren't communicated to the boss.

Forbes Magazine: Being the chief executive has its privileges. And one of them may be a blissful ignorance of your company's data breach risks.

According to a study to be released Tuesday by the privacy-focused Ponemon Institute, companies' chief executives tend to value cybersecurity just as--if not more--highly than their executive colleagues. But ... the CEOs interviewed in Ponemon's survey seemed especially unconcerned about cybercrime as a source of data breaches. While 31% named stolen PCs or thumb drives as a source of data loss, only 3% cited malicious hackers as the top threat for their company's data security--about a fifth as many as the lower level employees who cited cybercriminals as the most important threat.

http://www.forbes.com/2009/07/13/poneman-cybersecurity-breaches-technology-security-poneman.html?partner=alerts

Thursday, July 9, 2009

Taking On Small-Business Identity Theft

Business Week: It's a big problem that companies are loath to discuss. But California's amended identity theft laws show that offering protections to smaller companies on par with those for individuals helps tremendously.

http://www.businessweek.com/bwdaily/dnflash/content/jul2009/db2009079_858536.htm

Sunday, June 14, 2009

An Emerging Information Security Minimum Standard of Due Care

This Guide is a revised version of a paper that first appeared in 2005 in Information Security Management Handbook, Fifth Edition, Volume 2.

The paper examines the emerging body of law surrounding an enterprise’s responsibility for securing information, together with the emerging body of information security management principles and practices for doing so. Seven key information security management elements are identified which we believe constitute an information security minimum standard of due care. Enterprises failing to implement these seven management elements could face significant legal exposure should they suffer a security breach resulting in damage to a 3rd-party.

The paper applies explores the application to information security of appellate rulings in several negligence cases to the questions of Duty of Care and Breach of Duty: Kline v. 1500 Massachusetts Avenue Apartment Corp, United States v. Carroll Towing Co, Texas & P.R v Behymer, T. J. Hooper v. Northern Barge and People Express Airlines v. Consolidated Rail Corp.

http://www.citadel-information.com/

Wednesday, June 10, 2009

Information Security Standard of Due Care

A very short overview of emerging information security laws, regulations and practitioner standards. http://www.citadel-information.com.

Sunday, June 7, 2009

Saturday, June 6, 2009

Citadel Guide: Effectively Managing Information Security Risk

A guide for senior executives having responsibility for designing and implementing a cost-effective program program to secure critical information assets.

http://www.citadel-information.com/

Tuesday, February 10, 2009

Average cost of a data breach in 2008 grew to $202 per record, Ponemon Study Says

DarkREADING: Data Breach Costs Rose Significantly In 2008, Ponemon Study Says. Companies report average loss of $6.6 million per breach, study says.

The average cost of a data breach in 2008 grew to $202 per record compromised, an increase of 2.5 percent since 2007 ($197 per record) and 11 percent compared to 2006 ($182 per record), according to the study. The average total cost per reporting company was more than $6.6 million per breach -- up from $6.3 million in 2007 and $4.7 million in 2006 -- and ranged from $613,000 to almost $32 million.

http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=213000466