Posts Tagged ‘Data Protection Commissioner’

Data Breach: Popular Recruitment Website “RecruitIreland.com” data Breach

February 11th, 2011

To compromise customer sensitive details in a breach is quite embarrassing for a well known, user driven website. Especially, it becomes very tough if there are bunch of users logging in day and night to your website. Something similar has happened to the popular Irish recruitment website RecruitIreland.com which has been hit with a potential data breach and was temporarily disabled. The site is a member of the Thomas Crosbie Media (TCM) group of companies. RecruitIreland.com could have escaped from this situation, if it had used the laptop encryption software from trusted companies like Alertsec Xpress.

The website RecruitIreland.com has been forced to close temporarily as overall the 400,000 registered users’ email addresses have been compromised. As we talk about this incident, the site is now back online although it was offline after the company had learnt of the breach through several spam emails similar to the one below.

External Security Consultants

To identify and solve this problem, company has hired the services of an external security consultant. Tom Crosbie, the website’s managing director said, “The gardaí are investigating and the Data Protection Commissioner has been made aware of the breach”.

Officials of Recruitireland.com said in a statement, the website was shut down immediately at 2pm on 8th February 2011 after the breach was identified. Post that the concerned authorities including Gardai and Data Protection Commissioner were notified.

The Reason of Data Breach was Spamming

According to the reports database of company may have been harvested for spamming purposes. Users were receiving spam emails and advised not to reply, or comply with any requests for information such as bank account details. No other data, including CVs, usernames or passwords had been compromised, according to the website.

The company’s spokesperson said, “We take this incident and any attempted breach of our database extremely seriously” He also added that investigation is being done both internally and externally.

How Alertsec Xpress Would Have Helped

Although organizations world over are waking up to security issues, there is still a lot of work that needs to be done. Our idea at Alertsec has always been to create awareness about the massive impact of breach issues. We can only hope that after such cases of data breach, data security will become the key agenda for companies. They will start securing their organizational data by bringing in policies, using new software and improving their current practices.

This news exemplifies the need for data protection applications like Data encryption software and Laptop encryption. In an incident which highlights the need of a data security and recovery software, the threat could have simply been reduced to an insurance matter by a mere investment of $13/month. The information would have been secure with no loss what so ever. That is certainly a small price to pay compared to what can happen if you lose confidential or sensitive data. Alertsec Xpress offers a very good and easy-to-use laptop security service that includes more than the traditional software licensing model. Feel free to subscribe for your personal 30-day free trial.

Enhanced by Zemanta

Ireland Considering New Data Breach Notification Rules

June 11th, 2010
The island of Ireland highlighted on a blank m...
Data Security Concerns in Ireland

Close on the footsteps of its neighbouring countries, Ireland is also looking at the data protection rules with more details. According to these rules an organization should report a data breach incident to the authorities incase of any incidents involving loss of personal data of more than 100 people.

According to William Malcolm, a privacy lawyer with the law firm Pinsent Masons Ireland has had its share of high-profile data breaches which has spurred the creation of the code of practice.

As per the proposal by Ireland’s privacy regulator data losses will now be declared to Ireland’s Data Protection Commissioner in line the draft code of practice published by the Commissioner.

Can the organizations avoid reporting?

Yes, they can certainly avoid the report of data breach if their data is encrypted and protected by a strong password. In addition, they can also escape reporting if their devices are using a remote memory-wipe feature which is activated on the lost device.

Some experts foresee the masking of critical incidents as the problem with data breach notification guidelines. They believe that due to these rules there is a possibility that major incidents could get hidden and lesser known events exposed.

A couple of years ago, the government of Ireland had recommended the creation of an official guidance which would highlight the the time to report the incidents. The office of the data protection commissioner has published the proposed draftcode of practice on its Web site and starting June 18 it would be available for public comment.

According to Irish Data Protection Commissioner Billy Hawkes, “I have sought to bring forward a draft Code as quickly as possible after the Review Group report to respond to public concern in relation to organisations losing personal data under their control while at the same time not imposing an undue burden on those organisations”.

What if data loss involves less than 100 people?

If the loss incident involving less than 100 people includes sensitive personal data or financial information then that must be reported as well.

What would the report constitute?

The report would include the following:

  • Type of the data compromised
  • What action has been taken
  • How people have been informed or the reason for not informing people
  • What kind of actions have been taken to limit the problems for affected people.

Data Security with Alertsec Xpress

Why do data breach incidents happen in the first place? Perhaps your organization didn’t take the requisite steps or there was some level of negligence with the handling of data.

If you use a data security software a theft would simply be reduced to an insurance matter and cost of the hardware plus time to rebuild the laptop. That is certainly a small price to pay compared to what can happen if you lose confidential or senstive data. Alertsec Xpress offers a very good and easy-to-use laptop security service that includes more than the traditional software licensing model. Feel free to subscribe for your personal 30-day free trial.

Related articles by Zemanta

Enhanced by Zemanta