8January 2016Public reports indicate that approximately 319 million people have had their electronic records breached in the past couple of years mostly the result of cyberattacks on retailers, financial institutions, health insurance companies, doctors and hospitals, the federal government, the U.S. military, institutions of higher education and, ironically, data security companies. That's the equivalent of nearly every American receiving a notification that their personal information has been compromised. The information breached is wide-ranging and includes names, addresses, Social Security Numbers, credit card numbers, bank account details, medical records, payroll data and security file information. Illicit uses of this information include identity theft for any number of reasons, notably financial and medical fraud, as well as extortion or personal exploitation. Whatever the motivation, our new reality today is that data security is one of the greatest vulnerabilities facing corporations, the government and individuals. The risks to individuals are significant, as noted above. The risks to corporations are substantial as well and include financial risk, legal and regulatory risk, and reputational risk. How did We Get Here?Virtually everything is online. If you ask in a retail store whether they have a certain item, the clerk is as likely to look it up on a smart phone or tablet as they are to walk to the next aisle and search for it. We have become accustomed to an instant access to all kinds of information, from online purchase history to real-time bank account balances. This at-your-fingertips access is a great advance of modern life. It is also a key component that creates new vulnerability and associated risks as businesses operate within this third wave of computing. Sensing opportunity in others' vulnerability, hackers ranging from teenagers in their parents' basements to professionals working out of foreign government-backed offices are targeting our data 24-7-365. Despite the threat or perhaps because the threat is so vast most organizations are not fighting to keep hackers out as vigorously as hackers are fighting to get in. What should We do About It?Having suffered attacks themselves or witnessed costly and well-documented breaches of others, many organizations are systematically improving their protections in response to what's happening in the environment or, more purposefully, as part of an enterprise risk-management process. Companies large and small are beginning to ramp up the resources they devote to data security. The current average for such expenditures is about 8 percent of a given company's total IT spending.Clearly, better control over the environment within our organizations will help to reduce risk. But, as with most things in business, effectively addressing risk requires more than just hardware and software; it also requires dedicated human expertise. Five years ago, how many corporate C-suites included a Chief Information Security Officer, or CISO? Today, CISOs are among the most sought-after executives in the job market. For example, as part of a cybersecurity license standard Blue Cross Blue Shield implemented earlier this year, all Blue Cross and Blue Shield companies must identify a CISO as a point of accountability for data and cybersecurity. CISOs are not only in great demand; they are also extremely busy. In addition to the day-to-day rigor of intrusion detection, audits, double - and triple-user authentication, Risk Mitigation for Cyber Threats: A 21st Century Business ImperativeBy Robert J. Kolodgy, SVP Financial Services and Government Programs and CFO, Blue Cross Blue Shield AssociationIn My Opinion
<
Page 7 |
Page 9 >