Analysis and Commentary, Incidents

Is PCI Enough Protection?

No Comments 30 April 2008

As we all saw, New England supermarket chain, Hannaford Bros., recently discovered a potential 4.2 million credit card data breach; despite the fact that they had been told they were PCI compliant. According to this WSJ article, the data was exposed while transmitted over the (unencrypted) internal network. Anyone familiar with the PCI Standard is aware that it provides explicit instruction to “encrypt transmission of cardholder data across open, public networks,” which was a control measure that was in place.

Continue Reading

Analysis and Commentary, Incidents

Poor Identity and Access Management may have led to breakdown at French bank

No Comments 05 February 2008

Ripped straight from Slashdot, we have some post-incident analysis of the losses at French bank Société Générale.  Was the failure of a simple IT chore to blame?

Continue Reading

Analysis and Commentary, Incidents

2008: More ID Theft

No Comments 21 December 2007

The identity theft scourge is only going to get worse in 2008 as perpetrators — in pursuit of easy money — get younger and pop up in developing countries.  Those are among the sobering conclusions of a new report on ID theft by the Identity Theft Resource Center.

Continue Reading

Analysis and Commentary, Incidents

Data Breaches On The Rise

No Comments 18 December 2007

According to a new survey by Deloitte & Touche LLP (“Deloitte”) and the Ponemon Institute LLC, personally identifiable information (PII) of customers and employees is being exposed — frequently and repeatedly — potentially putting hundreds of thousands of individuals at risk.

Continue Reading

© 2008 Brightfly, Inc.

Powered by You, the Community.