California offers a revealing example

Californian law requires organisations to reveal breaches of security that involve customer data...

Written by Madeline Bennett

The list of companies falling victim to - and then going public about - data theft continues to grow. The latest case, discovered by security staff at MasterCard, involves a breach at one of the credit card provider's data processing partners, CardSystems Solutions. According to MasterCard, security flaws in the data processor's systems let an unauthorised individual access card data - putting up to 40 million MasterCard, Visa and American Express users at risk.

CardSystems is now under the scrutiny of the FBI and the Federal Financial Institutions Examination Council banking regulator in the US. These agencies are carrying out separate investigations to assess whether CardSystems' computer systems and internal controls met government security guidelines.

This must be a frightening prospect for any organisation, as the investigations could uncover unknown vulnerabilities or other breaches. They are also likely to affect the firm's daily operations and put pressure on its manpower and other resources if it has to help the agencies to retrieve required information.

CardSystems joins information clearing house ChoicePoint,  Bank of America and the universities of California and Stanford in reporting recent data breaches. Even the US government's Federal Deposit Insurance Corporation (FDIC) has joined the party - a case all the more awkward as this agency was set up to "preserve and promote public confidence in the US financial system".

What is notable is that all these organisations are based in the US. Some may reason that firms in the US are much more lax in protecting their customers' data and so fall victim to security breaches more often; or that our US counterparts are less concerned about their public reputations and the potential damage to share prices that could result from news of security breaches.

However, the reality is that legislation in some US states forces businesses to disclose security breaches involving customer data. The Security Breach Information Act was passed in 2003 after a California state government computer storing payroll information on 200,000 workers was breached. The law requires organisations to disclose IT security breaches that lead to the exposure of any California resident's personal data - whether the firms are based in the state or not.

As other states prepare to adopt similar regulations this year, there is speculation that the law will be rolled out nationwide in the US in the near future. But while the US is tackling security breaches and forcing organisations to come clean - California is already looking to remove a loophole so that data exposures via theft of backup tapes or paper records will also have to be reported - the UK government has been slow to act. We have yet to implement a similar law to reassure the UK public that if firms fail to protect personal information the incidents can't be swept under the carpet.

But this could change soon. If the US law goes nationwide, a European version is likely to follow. Although UK firms won't welcome the idea of joining CardSystems in facing rigorous scrutiny, they might be encouraged to take a little more care of security. It might also become easier for IT managers to get funding for any oft-requested IT security improvements that have so far failed to interest the board.

Have your say, here:

Tags:

reader comments

related articles

 

Data breaches cost UK firms £1.4m

Security breaches have far reaching implications for businesses finds report 27 Feb 2008

Canadian government exposes health data

Officials claim no criminal activity suspected 27 Nov 2007

Apple issues Safari for Windows update

3.1.2 update addresses four security vulnerabilities 20 Jun 2008

related whitepapers

today's top stories

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation