<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alertsec Xpress Data Security Blog &#187; Non-governmental organization</title>
	<atom:link href="http://blog.alertsec.com/tag/non-governmental-organization/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.alertsec.com</link>
	<description></description>
	<lastBuildDate>Tue, 07 Feb 2012 04:29:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security Breach at Shell Reveals Personal Employee Information</title>
		<link>http://blog.alertsec.com/2010/02/security-breach-at-shell-reveals-personal-employee-information/</link>
		<comments>http://blog.alertsec.com/2010/02/security-breach-at-shell-reveals-personal-employee-information/#comments</comments>
		<pubDate>Sat, 27 Feb 2010 23:45:18 +0000</pubDate>
		<dc:creator>Bogdan</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Lawsuits and settlements]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Greenpeace]]></category>
		<category><![CDATA[Non-governmental organization]]></category>
		<category><![CDATA[Royal Dutch Shell]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Shell]]></category>

		<guid isPermaLink="false">http://blog.alertsec.com/?p=736</guid>
		<description><![CDATA[Security breaches can happen anytime, anywhere, and can affect practically anyone in an organization. In the past, we&#8217;ve covered several examples where breaches revealed customer&#8217;s passwords and social security numbers. Today, we explore a different type of breach- one which leaked the personal details of 170,000 employees and contractors of Royal Dutch Shell. This incident is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.alertsec.com/wp-content/uploads/2010/02/Royal-Dutch-Shell.bmp"><img class="alignright size-full wp-image-737" title="Royal Dutch Shell" src="http://blog.alertsec.com/wp-content/uploads/2010/02/Royal-Dutch-Shell.bmp" alt="" width="223" height="207" /></a>Security breaches can happen anytime, anywhere, and can affect practically anyone in an organization. In the past, we&#8217;ve covered several examples where breaches revealed customer&#8217;s <a href="http://blog.alertsec.com/2010/01/rockyous-sour-rhapsody/" target="_blank">passwords</a> and <a href="http://blog.alertsec.com/2010/02/data-security-breach-incident-at-ceridian/" target="_blank">social security numbers</a>. Today, we explore a different type of breach- one which leaked the personal details of 170,000 employees and contractors of Royal Dutch Shell. This incident is important because it provides a perfect example of how storing unencrypted data on company computers can be dangerous and have serious consequences that can strike a company from the inside.</p>
<p>The situation is particularly difficult for the infamous oil corporation- the database of names and personal contact details has been e-mailed to several non-governmental organizations, including Greenpeace, Friends of Earth, and Shell Guilty. Shell has attempted to prevent the NGOs from publishing the information, explaining that in doing so, they would be breaking the law. Additionally, Shell is launching a full scale investigation in an effort to figure out how their employee information ended up accessible to third-parties. While it&#8217;s difficult to guess at the techniques used by the hackers involved, one thing is clear- Shell computers aren&#8217;t protected by full disc encryption services and, as a result, are much more vulnerable to online threats.</p>
<h2><span style="font-weight: normal;">Shell&#8217;s Information is a Serious Problem</span></h2>
<p><span style="font-weight: normal;">Understandably, Shell is trying to prevent the security breach from being seen as a serious problem. An article from <a href="http://business.timesonline.co.uk/tol/business/industry_sectors/natural_resources/article7025711.ece">TimesOnline</a> included a statement from the company:</span></p>
<blockquote><p>Yesterday Shell sought to play down the leak. A statement said: &#8216;Certain data concerning Shell employees and other individuals on our internal address list has been disclosed to some external parties. The data is mainly business-related.&#8217;</p></blockquote>
<p>While there may be some truth in the statement&#8217;s claims about much of the information being publicly available and not damaging the company, it&#8217;s likely that Shell&#8217;s employees feel differently. According to a report by the <a href="http://news.bbc.co.uk/1/hi/business/8512390.stm">BBC</a>, some of Shell&#8217;s workers had their private home telephone numbers leaked. Even if no personal telephone numbers were leaked, the breach brings attention to the poor status of computer security at Shell. Employees can&#8217;t work well knowing that their personal details aren&#8217;t well-protected. This last complication is troublesome, at least for Shell, which will need to improve the way it does business in order to reassure its employees that their private information is safe. Dealing with the aftermath of a crisis, such as Shell&#8217;s security breach, can be extremely costly and in many cases, a damaged reputation can&#8217;t ever truly be recovered, regardless of how much money is spent.</p>
<h2><span style="font-weight: normal;">Lessons to Learn</span></h2>
<p>Ironically, Shell&#8217;s security breach came at a convenient time- had Shell discovered the breach in April, a new set of laws (covered <a href="http://blog.alertsec.com/2010/02/the-cost-of-a-data-security-breach/" target="_blank">here</a> and <a href="http://blog.alertsec.com/2010/02/organizations-need-to-comply-with-strict-data-regulations/" target="_self">here</a>) would have allowed the company to be charged fines of up to £500,000. However, even without the monetary cost, Shell lost something extremely valuable: the trust of its employees. Shell workers are much less likely to remain loyal to a company which isn&#8217;t proactive about protecting its internal information.</p>
<p>In order to earn and maintain the trust of its workers, a company needs to employ solutions which are easy to use and keep data secure. Had Shell been using our Alsertsec Xpress <a href="http://www.alertsec.com/index.php?page=ov_about_alertsec" target="_blank">computer security software</a>, the company may have avoided the embarrassing security breach and kept its positive reputation among employees. Our software is specifically designed to keep all business parties happy and secure- it encrypts data, making it much more challenging for the others to access it.</p>
<p><strong><span style="text-decoration: underline;">Further Reading<br />
</span></strong> <a href="http://business.timesonline.co.uk/tol/business/industry_sectors/natural_resources/article7025711.ece">Shell investigates posting of personal data</a> [TimesOnline]<br />
<a href="http://news.bbc.co.uk/1/hi/business/8512390.stm">Shell security breach reveals employee details</a> [BBC]</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/10ecf020-cfa3-4406-b1b7-9fb71e294077/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=10ecf020-cfa3-4406-b1b7-9fb71e294077" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.alertsec.com/2010/02/security-breach-at-shell-reveals-personal-employee-information/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

