Small Business Resources, Business Advice and Forms from AllBusiness.com

Business Exchange

100 Million Personal Records Exposed: AppSecInc CTO Reflects on Data Security at Critical Milestone.

Application Security, Inc. CTO Aaron Newman Available for Comment on How Data Security Must Change in 2007

NEW YORK -- This morning, the Privacy Rights Clearinghouse (www.privacyrights.org) reported that more than 100 million personal records have been exposed since early 2005. On the occasion of this disturbing milestone, Application Security, Inc., (AppSecInc) (www.appsecinc.com) the market leader in database security, offers perspective on how data security must change as we prepare to enter 2007.

While the image of a computer hacker exploiting software flaws over the Internet from a foreign country strikes fear, the reality is much more complex - and ominous. In the past two years, reported data breaches more than doubled in 2006 when compared to 2005. The number attributed to "hacks" dropped, however, to less than 20 percent in 2006, from approximately 35 percent in 2005.

Massive data exposure often results from shortcomings in people, process and policy - as well as technology. As a result, AppSecInc CTO Aaron Newman recommends that vulnerabilities associated with data - not amorphous threats or specific technology weaknesses - be the critical starting point for ALL security initiatives. Mr. Newman is one of the foremost experts on database security and co-author of the Oracle Security Handbook. He suggests the following six steps are the right mindset for a security resolution in the New Year:

1. Trust no one. No one in an organization should be exempt from controls over how data can be accessed or used.

2. Inventory the most sensitive data, and don't even think about protective measures until you've completed a thorough discovery of sensitive data and where it resides.

3. Build a layered defense, prioritize efforts based on value and risk, and don't get seduced by silver bullets - there are none.

4. Document everything. It helps to bolster compliance at the same time.

5. Do something decisive, do it quick, and enlist others to help - even if you have to scare them into it.

6. Have vision and the courage of your convictions. The upside of rock-solid security is the ability to share data freely and with confidence, generating maximum value.

Mr. Newman adds, "The end of 2006 greets us with the cold, hard fact that at this level of exposure, we're playing with fire. With each breach, massive and widespread identity theft is headed toward epidemic proportions. In the past, security was dealt with in an outside-in mindset, defending the walled garden from intruders. But in today's reality, this leaves far too much room for error - or malfeasance. We must make 2007 the year of inside-out security - starting with the ultimate target of exposure, the database, and working our way out in a layered defense."

To speak with Mr. Newman or other AppSecInc executives on these and other database security-related issues, contact Christine Meyers at 781-687-1034 or via email at cmeyers@appsecinc.com.

About Application Security, Inc. (AppSecInc)

AppSecInc is the leading global provider of database security solutions for the enterprise with offices in North America and the UK, and a robust partner-reseller network in key markets like EMEA, Asia-Pacific, and Latin America. AppSecInc's products - the industry's only complete vulnerability management solution for the database tier - proactively secure database applications at more than 600 organizations around the world. Our security experts, combined with our strong support team, deliver up-to-date database protection that minimizes risk and eliminates its impact on business.

Please contact us at 1-866-927-7732 to learn more, or visit us on the web at www.appsecinc.com.

AppSecInc is a trademark of Application Security, Inc. All other company and product names are trademarks of their respective companies.

In addition, make sure to read these articles:

  • ICSA Labs Creates Web Application Firewall Product...
  • MECHANICSBURG, Pa. -- ICSA Labs([R]), an independent division of Cybertrust([R]), the global information security specialist, today announced the formation of the Web Application Firewall Product ......
  • CAN-SPAM Act Continues to Come up Short in Efforts...
  • Barracuda Networks Reports Continued Rise in the Amount of Spam and Other Email Threats MOUNTAIN VIEW, Calif. -- Despite the upcoming three-year anniversary of the ......
  • Watchfire Announces New Online Data Privacy...
  • Company Introduces New Program to Facilitate Expertise in Website Privacy Issues WASHINGTON & WALTHAM, Mass. -- Today at The IAPP's Privacy Summit, Watchfire[R], the market ......
  • AppSecInc CTO Addresses Critical Data Controls in...
  • Application Security, Inc. CTO Aaron Newman Available for Comment on Risks and Responsibilities Enterprises Face in Securing Databases NEW YORK -- In light of recent ......
  • Reckless with Records
  • According to research by the Privacy Rights Clearinghouse, a San Diegobased consumer advocacy group, the number of records containing sensitive personal information involved in security ......
  • Does FACTA Go Far Enough?
  • According to business executives, the U.S. federal law requiring companies to destroy documents that contain consumer credit information does not go far enough toward fighting ......
  • Encrypt Corporate Laptops, Experts Warn
  • Since June 2005, there have been at least 29 high-profile cases of misplaced or stolen laptops with data such as Social Security numbers, health records, ......
  • Employers get tough about laptop security
  • Another day, another story of stolen laptops filled with personal information.
  • DAVIS EXPECTED TO SIGN PRIVACY LEGISLATION...
  • Despite pressure from insurers to veto a controversial opt-in privacy measure passed by the Legislature last week, California Gov. Gray Davis is expected to sign ......
  • Application security.
  • According to the National Institute for Standards and Testing, software bugs could cost the economy as much as $60 billion. If that number strikes you ......
  • LifeLock Partners With MyPublicInfo, Inc.
  • Together the companies can provide consumers a risk factor and guaranteed protection TEMPE, Ariz. -- According to The Privacy Rights Clearinghouse, a non-profit group in ......
  • Rosenfield Gives Major Gift to Privacy...
  • The James and Frederica Rosenfield Foundation has awarded a significant grant to the Privacy Rights Clearinghouse, becoming a major benefactor of the non-profit consumer program....
  • StrikeForce Offers Early Christmas Present To...
  • With Cyber Thieves Preying on Consumers From All Angles, Including eGreeting Cards, StrikeForce Seeks Identity Theft Victims For Education Program EDISON, N.J. -- StrikeForce Technologies ......
  • Wanted: online privacy police.
  • Posting your resume online may put your privacy at risk. According to a recent report by the World Privacy Forum, the Privacy Rights Clearinghouse, and ......