Tuesday, September 26, 2006

When Cost of Smartcards is Too High

Very few companies will want to bear the high cost of re-badging their entire workforce. And, why should they? Integrating physical and data security is the desired goal. Smartcards represent a technology approach to achieving that goal. Integration can also be achieved through directory services (e.g. Active directory, LDAP) without having to re-badge. Here is how I advise my clients when they are confronted with budget constraints: i) Identify the assets that represent the greatest risk (e.g. top security government work); ii) Provide smartcards to the people who need to access those assets; iii) Protect all other assets using directory services. This is a practical approach to achieve convergence between physical and data security.

Monday, September 25, 2006

Three Hundred Data Breaches

We hear a lot about data breaches. It seems as though one is announced nearly every week. Well, it turns out that between February 2005 and July 2006 more than 300 data breaches were reported. That is almost 20 a week. Click on the link to see a listing of these data breaches:
http://www.privacyrights.org/ar/ChronDataBreaches.htm

It is useful to remember that we hear very little about the outcomes of these breaches. The lawsuits and penalties rarely appear in the press, yet the general counsel or representing attorneys know that the cost of the breach will occur in the cost of litigation, the penalties and shareholder value.