computer encryption software

Phishing Attack Top Data Security Motivator – HIMSS Survey

June 23rd, 2015

The key findings after interviewing 297 healthcare leaders and information security officers across the industry of the survey are –

  • Two-thirds of respondents experienced a significant security incident in this year
  • Healthcare organizations also reported using an average of eleven different technologies to secure their environments
  • More than half said that their facilities have hired a full-time professional to manage the information security functions.
  • Eighty Seven percent reported that their information security had increased as a business priority at their organizations over the past year.
  • Many believes that current security tools will not be sufficient to protect the industry against the types of security threats their organizations expect to face in the future

“The recent breaches in the healthcare industry have been a wake-up call that patient and other data are valuable targets and healthcare organizations need a laser focus on cyber security threats,” HIMSS Vice President of Technology Solutions Lisa Gallagher said in a statement. “Healthcare organizations need to rapidly adjust their strategies to defend against cyber-attacks. This means implementing threat data, incorporating new tools and sophisticated analysis into their security process.”

Other finding included –

  • 87 percent of those surveyed said antivirus/malware tools have been implemented to secure their healthcare organizations’ information security environment
  • 80 percent reported using network monitoring to detect and investigate information security incidents
  • 64 percent said that a lack of appropriate cyber security personnel is a barrier to mitigating cyber security events
  • Internal security teams identify more than 50 percent of information security threats

“Indeed, respondents were widely likely to indicate that more innovative and advanced tools are required to secure their environments in the future,” HIMSS stated. “Furthermore, they indicated that healthcare organizations must operate from a perspective which presumes their organization’s perimeter has already been breached.”

Alertsec strengthens security

Alertsec has created a web based encryption service that radically simplifies deployment and management of PC encryption by using industry leading Check Point Full Disk Encryption (former Pointsec) software.

Organizations, especially corporate giants, have to have an information security policy in place that proves they have taken the necessary steps and measures to safeguard the information they gathered. If these policies are not adhered to, the regulators may prosecute.

Alertsec Xpress is used by organizations that have recognized the need to protect their information. Customers range from single-user sole traders and consultants to multinational companies with a large number of offices around the globe. Over 4 million users worldwide use Alertsec Xpress’s Check Point Full Disk Encryption.

 

Phishing attack leads to data breach

May 2nd, 2015

Partners Health Care System, Inc. suffered data breach when it learned that employees had fallen victim to a phishing scheme, providing sensitive information to unauthorized individuals. Affected information includes names, addresses, dates of birth, telephone numbers, and Social Security numbers in a few cases. Moreover, patients’ clinical information, such as diagnoses, treatment received, medical record numbers, medical diagnosis codes, or health insurance information, could also have been exposed in a few cases.

“Responding to the ‘phishing’ emails created an opportunity for unauthorized access to the workforce members’ email accounts within the Partners HealthCare network,” the statement read. “When we learned of this, we took steps to secure the email accounts and contacted law enforcement.”

Partners’ affiliated hospitals and institutions are also potentially affected which includes Brigham and Women’s Hospital, Brigham and Women’s Faulkner Hospital, Massachusetts General Hospital, North Shore Medical Center, Partners Continuing Care, and Newton-Wellesley Hospital.

“We deeply regret any inconvenience this may have caused you,” Partners said in its statement. “To help prevent something like this from happening in the future, we have reinforced workforce member education regarding ‘phishing’ emails and are enhancing our existing technical safeguards to protect patient information.”

The hospital mentioned that notification letters are sent to the affected individuals. They believe that there is no indication of affected information being misused.

Get your personal as well as office laptops encrypted by Alertsec

Unencrypted laptops present a major risk of data loss. 80% of information theft is due to lost or stolen laptops and other equipment. About 50% of network intrusions are performed with credentials gathered from lost or stolen devices. The penalties for a data breach are severe not only in terms of the monetary fines imposed on the organization, but also the potential loss of trust from customers and suppliers. Encryption software greatly enhances the security of your organization’s data as the information is not compromised if a laptop is lost or stolen.

Alertsec Xpress is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.

Passwords under threat at Linode

April 20th, 2013

One of the leading VPS hosting company Linode came under a vicious hack attack, that posed serious threats to its customers. Luckily for them, Linode had been proactive in safeguarding its customers’ credit card information. They had been successful in thwarting the attack. According to a blog post that was published soon after the incident, the company’s officials identified and blocked all suspicious activities on the networks.

“Credit card numbers in our database are stored in encrypted format, using public and private key encryption,” Read one of the blog posts on the company’s website. Linode maintains that a group named Hack The Planet (HTP) claimed   responsibility for accessing   Linode Manager web servers, by exploiting an obscure vulnerability in Adobe’s ColdFusion application server. These vulnerabilities tended to in Adobe’s APSB13-10 hotfix (CVE-2013-1387 and CVE-2013-1388) which was belted out last week.

This is not the first time hackers have tried to get inside Linode .A year ago, sometime in the March of ’12 servers it hosted were hacked and the hackers got their bank balances full with bitcoins.

The susceptibility resulted in the group getting exposure to a web server, parts of Linod’s source code and finally its database. The company is reported to have been bending over backwards to safeguard critical information of its customers.

A customary investigation done by the company revealed that HTP did not get access to any other section of the company.

However, HTP has asserted it has access to those keys, however, as it was stored on the same server it compromised

The company also divulged a little information on how they function. Their database contains credit card numbers in an encoded format, using both public and private encoding. Since the private key is protected and the complex password is not stored on the network, it becomes next to impossible for hackers to get all the information

The private key is itself encrypted with passphrase encryption and the complex passphrase is not stored electronically.

“There were occurrences of Lish passwords in clear text in our database. We have corrected this issue and have invalidated all affected Lish passwords effective immediately. If you need access to the Lish console, you can reset a new Lish password under the Remote Access sub-tab of your Linode,” one of the officials maintained.

It is advisable for the customers of Linode to change their passwords in case they have used their Linode passwords on any service other than Linode.

How Alertsec can be of help to customers in such murky waters

80% of data loss is due to lost or stolen equipment. 50% of network breaches take place by using passwords from lost or stolen equipment. Laptop encryption is the solution to laptop theft problem. Small and big companies are now realizing the importance of tracking software. Alertsec offers laptop encryption service to secure your data.

Organisations are now made aware about their data security and are implementing data encryption techniques. Alertsec uses encryption software to protect data from breaches and theft.

Enhanced by Zemanta

Internet, social media least trusted industries for privacy

January 15th, 2013

Internet and social media ranked at the bottom on a list of the most trusted industries for privacy, according to the Ponemon Institute.

Released yesterday, Ponemon’s “2012 Most Trusted Companies for Privacy” was compiled from a survey of U.S. adults asked to name the five companies they trust the most to protect the privacy of their personal information.

Based on more than 6,700 responses, the Top 20 list did not include several tech players that had been on it in past years.

Apple failed to make the list for the first time in four years. Google, Best Buy, Facebook, Yahoo, Dell, and AOL also were gone from the Top 20 after scoring good or decent grades in the past.

Those results aren’t surprising, as many of those polled expressed concern about certain technologies. A full 59 percent of the respondents said they feel their privacy rights are diminished or undermined by social media, smart mobile devices, and geotracking tools.

Almost half the people surveyed said they received one or more data breach notifications over the past two years. And 77 percent of those people said such notifications hurt their trust in the organization reporting the breach.

A majority of those polled said they’ve shared personal information with an organization they didn’t know or trust, with most admitting they did it for the convenience of online shopping. And only 35 percent feel they have control over their personal information, a percentage that has dropped steadily over the past seven years, the report said.

Identify theft was seen as the most significant threat to privacy, followed by government surveillance and data breaches.

And what do people expect from companies that use their personal information?

Security protection was named the most important feature. But a majority also said they don’t want their data shared without their consent and they want the ability to be forgotten.

On a more positive note, Hewlett-Packard took second place in the rankings, just behind American Express.

Amazon was third, followed by IBM in fourth. eBay grabbed ninth place, with Intuit rounding out the Top 10.

Among other technology providers, Microsoft and Mozilla joined the list for the first time, ranked 17 and 20, respectively. Verizon, AT&T, and WebMD also numbered among the Top 20.

Get your personal as well as office laptops encrypted by Alertsec

Unencrypted laptops present a major risk of data loss. 80% of information theft is due to lost or stolen laptops and other equipment. About 50% of network intrusions are performed with credentials gathered from lost or stolen devices. The penalties for a data breach are severe not only in terms of the monetary fines imposed on the organization, but also the potential loss of trust from customers and suppliers. Encryption software greatly enhances the security of your organization’s data as the information is not compromised if a laptop is lost or stolen.

Alertsec Xpress is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.

Enhanced by Zemanta