Press Release Distribution
 

Members Login  |  Register  |  Why Join?   Subscribe to Newsletter Newsletter   RSS Feeds RSS Feeds

Video Releases    |    Pricing Plans    |    Today's News    |    News By Category    |    News By Region    |    News By Date    |    Business Directory    |    Private Branding
All Press Releases for September 27, 2008 »
RSS Feeds RSS Feed     Print this news Printer Friendly     Email this news Email It    Create PDF PDF Version    Bookmark del.icio.us    Diggs



Security Expert Offers 6 Opportunities To Learn From National Bank Security Breach
In this economy, companies are looking at new media channels to expand their brands and have turned to us to help them find new revenue sources online. 
x-small text small text medium text large text


    TORONTO, ON,September 27, 2008 /24-7PressRelease/ -- A laptop containing personal information on the majority of National Bank's mortgage clients has been stolen from their offices, demonstrating that Canadian banks are as fallible as any other organization while presenting the added risk of losing large amounts of financial and personally identifiable information. The privacy of customer information is protected by Canadian law, unfortunately numerous companies still fail to adopt secure practices.

Claudiu Popa is a recognized security expert and Informatica's president, a trusted corporate advisor on matters of compliance, privacy and security: "as a leader in security awareness and consulting, we welcome high profile cases like this for the sole reason that we have for a mandate to educate executives as well as the Canadian public. This is an excellent time for this organization and others to adopt better security practices."

The following six failures contributed to the security breach that threaten to victimize the firm's mortgage clients:

1.The laptop was stolen from an insecure office, indicating a lack of physical office security.

2.If the company's policies included anti-theft devices for mobile computers, they were not being enforced.

3.The laptop contained a large database of personally identifiable and financial data on numerous clients, which should never leave the office servers. Instead, such data should be accessed over the network or remotely, one record at a time.

4.A password was reportedly used to 'protect' the computer. Without strong encryption, such a basic measure is entirely inadequate for the protection of corporate and private information.

5.The data within the database linked client names to their mortgage data, unfortunately identifying their financial details in the process. Companies should not aggregate such information but instead spread it across a number of databases to protect against unauthorized disclosure.

6.The amount of information about the breach may be inadequate for potential victims. Both the public and the firm's customers need to understand, by example that by correlating this information with other data, practically any type of fraud could be committed.

Mr. Popa added: "The company's insistence that the impact of the security breach will be minimal and that the information was basic is unfortunate, but given that Canadian law does not currently require the disclosure of such breaches, clients should consider themselves lucky to have been notified and should remain vigilant about their financial affairs for years to come". Canada's planned adoption of breach notification standards has been delayed for years, but its future adoption is considered by many as a significant benefit to Canadian customers.

About Informatica Security Corporation
Informatica Security and Privacy is a leading information risk management consulting firm focused on providing unmatched expertise to enable client organizations to control and mitigate information security risks, meet compliance challenges, alleviate the effects of wrongsourcing and adopt proven standards and best practices for exceptional governance. The firm's FlexSecure risk assessments and professional audits, FlexProtect security management, STORM (Scalable Techniques for Operational Risk Management) and WorkLife Enterprise Risk Education solutions are proven best-of-breed solutions that scale to meet the business and compliance requirements of diverse industries.

For additional information, please contact Informatica at 416-431-9012 or visit http://www.SecurityandPrivacy.com and http://www.InformationSecurityCanada.com.

Informatica Security and Privacy, Informatica Education, Informatica Research, the Informatica logo, FlexSecure , FlexProtect and WorkLife , VirtualCSO and VirtualCPO are trademarks or service marks of Informatica Corporation. All Informatica white papers, proprietary research, Web site content, presentations, communications, policies and Informatica-branded documentation are Copyright Informatica Corporation and permission must be specifically granted for use by any party. All other brands or product names are trademarks of their respective companies, organizations or standards bodies.


For media enquiries and solution requests contact:
Claudiu Popa, CISSP, PMP, CISA
President & CSO,
Informatica Corporation
Toronto, Ontario, Canada
416-431-9012
Info@InformaticaSecurity.com
http://www.InformationSecurityCanada.com


---
Press release service and press release distribution provided by http://www.24-7pressrelease.com


# # #


Read more Press Releases from Claudiu Popa:
Other Press Release Headlines:


Press Release Service & Press Release Distribution News Supplied By 24-7PressRelease.com
Press Release Contact Information:
Claudiu Popa
Informatica Corporation

President & CSO,
Toronto
Toronto, Ontario
Canada 9012
Voice: 416-431-9012
E-Mail: Email us Here
Website: Visit Our Website
Disclaimer:
If you have any questions regarding information in this press release, please contact the person listed in the contact module of this page. Please do not attempt to contact 24-7 Press Release. We are unable to assist you with any information regarding this release. 24-7 Press Release disclaims any content contained in this press release. Please see our complete Terms of Service disclaimer for more information.