Epsilon says the breach was limited to names and e-mail addresses, and that other sensitive information, such as credit card numbers, were not exposed. Still, “any time you have an organization that loses the contact information of customers for some of the biggest banks in the world, that’s a big deal,” Brian Krebs, editor of Krebs on Security, a website that specializes in online security and crime, told The New York Times. “You’ve just given the bad guys a road map between the banks and their customers.”
The breach is particularly alarming in the wake of a recent AVG survey that found six out of seven small businesses in the United States and United Kingdom have no Internet security measures in place. This lack of security means credit card numbers, confidential reports, e-mails and other information a business would never want made public or destroyed could be vulnerable to attacks. To protect sensitive data, distributors large and small need to put security measures in place. Those efforts start with knowing where data is stored and who has access to it, says Michael Kleeman, a network security expert at the University of California, San Diego. Additionally, companies should consider encrypting data. “If the data is grabbed, you want to make it difficult to utilize,” says Kleeman.
To better protect their data and systems, here are some steps 'companies' should take:
- Install and update anti-virus software on all company computers and perform all hardware and software updates on time.
- Institute written policies that govern employee computer use. These policies can include prohibiting personal e-mail use, allowing only routine attachments to be downloaded and requiring employees who download a virus or detect something suspicious to report the problem immediately.
- Set up a company firewall and business class router.
- Regularly create back-up files of all important data and store them in a safe or other secure location offsite.
No comments:
Post a Comment