SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

ChoicePoint CIO details 'lessons learned' from data breach

ChoicePoint CIO details 'lessons learned' from data breach

By:  Jon Brodkin  On: 11 Jun 2007 For: Network World (U.S.) Creator

Few companies know as well as ChoicePoint the consequences of failing to secure the personal information of consumers

COMMENT ON THIS ARTICLE

BOSTON - Few companies know as well as ChoicePoint the consequences of failing to secure the personal information of consumers.

A provider of information used in background checks, ChoicePoint was involved in a data breach more than two years ago that compromised the records of 163,000 people -- but has since transformed itself into what one analyst called a "role model" in data security and privacy.

On Monday, the organization's CIO explained how it recovered and offered lessons other enterprises that handle sensitive data can learn from ChoicePoint at the IDC IT Forum & Expo in Boston.

Too often, simple mistakes are the cause of data breaches, Darryl Lemecha, CIO and senior vice president of shared services at ChoicePoint, Listing a person's Social Security number on a mailing address label, or not securing data on a laptop that is later stolen or lost, are mistakes that have left some companies wishing they had thought more about security, he said.

"Encrypt all your laptops," Lemecha recommended. "Because they're going to get lost, they're going to get stolen. And make sure all your handheld devices have passwords on them and you have the ability to do a remote wipe [of data]."

In 2005, the records of 163,000 consumers were compromised after criminals pretending to be legitimate ChoicePoint customers sought details about individuals listed in the company's database of personal information.

ChoicePoint agreed to pay US$10 million in civil penalties and $5 million for consumer redress. The company, which recently reached a separate settlement with 43 states over the breach, also decided to limit the sale of information products containing sensitive consumer data, including Social Security and driver's license numbers.

In doing so, ChoicePoint walked away from what was a more than $15 million business serving small and midsize accounts, but the company felt it could not sufficiently determine the credentials of those customers in a cost-efficient manner, Lemecha said.

After the data breach, ChoicePoint worked backwards to determine the credentials of every one of its customers, he said. "The truth is, we assume every piece of information a customer provides us in the credentialing process is potentially fraudulent, and we validate it against other sources," Lemecha said.

ChoicePoint has been subjected to more than 80 external audits over the past 24 months, he said.

In April, Gartner analyst Avivah Litan told USA Today that "ChoicePoint transformed itself from a poster child of data breaches to a role model for data security and privacy practices."

Lemecha offered a five-step plan to CIOs looking to shore up their data security and privacy systems, based on what ChoicePoint has done.


Sign up for our Newsletters












Print |  Views: 948   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Jon Brodkin Jon Brodkin is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Aussies take their cue from Canada on breach notification
Aussies take their cue from Canada on breach notificationCanadian data breach notification guidelines - jointly created by the Information and Privacy Commissioners for British Columbia and Ontario - have made their way to the land down under. Last week, Australian Privacy Commissioner Karen Curtis released the Voluntary Information Security Breach Notification Guide, which aims to assist organizations in effectively responding to information security breaches.
Privacy Down Under: 'Garbage, trash or junk'
Privacy Down Under: 'Garbage, trash or junk'When it comes to privacy, Australians are left to choose between garbage, trash or junk, says Gartner's vice-president of research, Rich Mogull. There is no legislative protection in Australia and no market forces pushing organizations to do better, he explains. Mogull believes legislation should include strict penalties and a built-in mechanism that allows consumers to take legal action themselves.
Just how profitable is privacy?
Just how profitable is privacy?Like honesty, privacy is good policy. And it's also profitable. Proponents say proper privacy practices are also 'good for business'. Now it appears there's actual evidence to back up this proposition.
CIBC's could-be security breach raises BPM issues
what makes you feel better: knowing that your personal information has been lost by a major financial institution,
blog comments powered by Disqus