Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

Wednesday, October 03, 2007

New Risks Require CEO Action: Beyond Awareness...

Here was our favorite question sitting in the room at the National Press Club this week during a "Deja Vu" moment, as the Department of Homeland Security and the Federal Trade Commission kicked-off the 2007 National Cyber Security Awareness Month.

"What demands, mandates or filings might be made on your organization from external organizations - public, private or regulatory - during this kind of disruption? What will your customers expect from you?"

The statistics are getting more attention these days due to the real pandemic of ID Theft and transnational crime syndicates now turning to mechanisms of financial fraud. This has surpassed the drug trade in terms of the revenue potential and the ease of acquiring and accessing our personal identifiable information.

The purpose of this summit in conjunction with the National Cyber Security Division (NCSD) of DHS is to examine ways to develop an actionable, sustained national awareness campaign and prevention program to inform Federal, State, and local government, educational institutions, small business users. The focus continues on protection of key resources, critical infrastructure and personal sensitive information and identities from man-made and natural threats.

The presentation that was most refreshing and relevant was from the Honorable Deborah Platt Majoras, Chairman, Federal Trade Commission. She highlighted some of the recent enforcement actions and the continued emphasis on business to assure their reputations by staying out of the popular press. These remarks by Betsy Broder, Assistant Director of the Federal Trade Commission’s Division of Privacy and Identity Protection at an event last month, further address the growing concern by business to adequately protect consumers information:

Law Enforcement on Data Security
"One important way to keep sensitive information out of the hands of identity thieves is by ensuring that those who maintain such information adequately protect it. To further that goal, the Commission brings law enforcement actions against businesses that fail to implement reasonable security measures to protect sensitive consumer data. Public awareness of, and concerns about, data security continue at a high level as reports about breaches of sensitive personal information proliferate."

The awareness agenda continues because it is still a long way from getting the public and the Small and Medium Enterprise to recognize the fiduciary duty they have to their customers. Even this web site OnguardOnline produced by the consortium of government agencies working together to fight cyber crime and improve awareness still have not found all of the answers.

The Business Roundtable's new publication on "New Risks Require CEO Action" has been well recieved due to greater reliance on the Internet for Business Operations. Here are a few of the most important questions that CEO's can ask:

1. Have we considered the dependence of our vendors and supply chain on the Internet?

2. What degree of consumer confidence in our data, services or products may be affected by a disruption of the Internet or corruption of data and services that are dependent on the Internet?

3. Have we set in motion a strategy for attaining early warning information to better protect our customers and corporate assets as well as our suppliers and partners?

The World Economic Forum estimates a 10 to 20 percent probability of a breakdown of the critical information infrastructure in the next 10 years - one of the most likely risks it studied. Additionally, it estimates the global economic cost at $250 Billion, one of the largest cost estimates of the risks examined.

Friday, February 23, 2007

The Board Room: IT Strategy Focus...

A new survey or 400 directors published in the March/April issue of Corporate Board Member Magazine by Deloitte Consulting has some interesting insights. In regard to the use of Information Technology as important or very important to insure success in various areas of the business:

  • 69% say implementing the right IT strategy is "very important" in compliance.
  • 66% in learning about and retaining customers.
  • 57% in managing risk.
  • 50% in competitive positioning.

So how come only 14% say they are "completely and actively involved" in IT strategy?
Boards of Director's are in the dark and this won't be changing very dramatically unless you are the result of a significant incident such as T.J. Maxx:

According to The Boston Globe today, TJX Companies has stated that a data breach it revealed last month may have occurred a year earlier than investigators initially thought. The company operates the retail outlets T.J. Maxx, Marshalls and HomeGoods (2,500 stores in the United States), so the earlier date of the hacking may mean millions more customers were exposed. The company declined to give numbers, however.

TJX discovered the breach in December 2006, and it made news on Jan. 18, 2007. At that time the company reported that hackers may have made off with credit and debit information from transactions in the United States, Canada and Puerto Rico from some months in 2003 as well as transactions between May and December 2006.

Yesterday, according to the Globe, TJX said a systems review revealed that intrusions had occurred as early as July 2005, not May 2006.

This trickle of data breaches spread over time led some experts to judge the corporation’s computer systems outdated, weak and not up to card-company security standards.

Information Technology strategy and the amount of effort or time a Board of Directors spends on it is most likely determined by the CEO. If they trust the Chief Information Officer and what they are doing, then they leave it alone. This is becoming an area under greater scrutiny by Directors as these kinds of incidents occur on a more regular basis in the news. However, just because it's not in the news, doesn't mean that it's not happening today at your institution.

There is another war brewing between the banks, retailers and the credit card issuers about who is the guilty one. At the end of the day, consumers will lose. Even pressure by VISA and others to make sure merchants are in compliance with the laws around encrypting data and the storage of the data may not be enough. The retailers have already started their lobbying efforts:

As information security has become a major focus of consumers, governments and businesses alike, the care with which companies protect credit card data has become increasingly important. In many instances, the Achilles heel of data security is a lack of application controls.

Encryption alone is not the answer. With most of the encryption techniques, the same key is used to lock and unlock the data. The problem is: How do you secure these keys in the POS application? Once these keys are compromised, the "secured" data is no longer secure.

The best way to secure data is to not store data. A technology knows as “tokenization” offers a greater level of security by substituting a unique identifier (a token) for a card number, so the card data is never in the system. This token is a random unique value and has no way to be deciphered to gain knowledge of the associated card information. With tokenization, the merchant swipes the card data and sends the information through a gateway to a processor and receives back an approval. But instead of sending the card data itself back to the merchant and the POS system, it is converted to a token: a globally unique, randomized representation of credit card data that is 16 characters long. Only the token is stored in the system.

The token spans the lifetime of the transaction so it provides full support for tips, tabs and incremental authorizations. The merchant does not need the card number or data past the initial request, so storing this information is unnecessary. The entire liability to protect the card data is now on the gateway, where it should be. The primary objective of tokenization is to enable businesses to operate normally while not storing the sensitive data that is the target of data thieves. This technology also eases the burden of compliance for merchants. If no data is stored on site, the merchant has a significantly reduced PCI compliance burden.

The Board of Directors who discuss IT strategy on a regular basis perform better financially and those who don't may be paying the price.