About RSS
Search for: in 

Windows Watch - an XP & Vista blog

NetEvents 2007
NetEvents 2007
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Experts call for fundamental IT security rethink

Nationwide laptop theft highlights inadequacies of traditional security

Robert Jaques, vnunet.com 22 Feb 2007
ADVERTISEMENT

Nationwide Building Society's recent loss of a laptop that exposed sensitive personal details of 11 million customers highlights the need for a fundamental reassessment of enterprise security, it was claimed today.

Rob Bamforth, principal analyst with Quocirca, said that the incident highlights "elemental deficiencies" with traditional IT security practices.

"The fundamental issue with the Nationwide data theft was that the whole database was loaded on the laptop," Bamforth said today at the NetEvents symposium in Evian.

"The blunder shows the serious issues around the defragmentation of data. The more you fragment data and keep it separate, the more you can protect your assets as there is less to lose.

"This shows that it is not enough to rely on specific security tools such as encryption. Enterprises need something more fundamental than security software and hardware. What you need is a fundamental rethink."

Bamforth added that taking action such as trying to secure firewalls around data centres missed the fundamental changing nature of data mobility.

"Enterprises are just too porous for data. Devices such as 2GB and 4GB memory sticks cost peanuts now so the extraction of data is so simple," he said.

"To fight this enterprises need to revise policies and procedures. This is all about data flow or data management rather than a security."

However, James Collinge, director of product management at security firm TippingPoint, argued that traditional security technologies are evolving to cope with the new threats.

"Today we can look for malicious traffic and perform some kind of function on that traffic. Ultimately we want to do that with content such as social security numbers," he said.

"We want to enforce policy in real time at the microsecond level. But we will not see this anytime soon."


All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | University of east anglia
WEB DEVELOPER £22,332 to £27,466 per annum (Grade 6), with agreed progression to £28,290 to £33,780 (Grade 7). Pay award pending from October 2008. We are looking for an experienced Web Developer to join a ... more >
Berkshire, Reading, United Kingdom | Foster Wheeler
PDS/PDMS Administrator Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & LNG, refining, petrochemicals & chemicals, pharmaceuticals ... more >
Hertfordshire, United Kingdom | Tesco.com
Senior Business Analyst - Hertfordshire Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
London, United Kingdom | BP
 IT Leader -£ Competitive - London About BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. With ... more >
More job opportunities
ADVERTISEMENT