Advertisement
Promo

Security threats Toolkit

Lost laptop data needs P45-level protection

Leader ZDNet.co.uk

Published: 22 Nov 2006 17:52 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment
Lost laptop data needs P45-level protection

Laptop theft, like the poor and Windows security patches, will be with us always. If something's useful enough to be carried, it's tempting enough to be carried away.

Today's laptops are different to their forebears, though. They're as fast and capacious as yesterday's servers, and just as capable of carrying the data for an entire payroll — or customer base. At the same time, they're cheap enough to give to everyone. What could be more natural than for your database administrator to whisk away the database for a weekend's tweaking at home? Or more dangerous: after all, your company's value — and untold liability — lives in that data.

If the laptop is stolen and the information compromised, then that machine becomes just as expensive as your data centre. Yet while your data centre lives behind bolted doors deep in the bowels of a secure building, the laptop will follow its owner into bars, cafés, the back of the car and the front room at home. It cannot be made physically secure.

The answer, of course, is to protect the data. There are many ways to do this, few of them new. Encrypt the hard drive behind two-factor authentication. Configure the laptop as a thin client and leave the data behind locked doors. Buy an intrinsically secure laptop in the first place.

But the most important part of the equation is the wetware atop the keyboard. If you're responsible for carrying major company assets around in an easily thievable form, then it's your job to make sure they can't escape. It's a very great responsibility — and one easily disguised by the extreme simplicity of taking it on. One drag and drop, and you're in charge of information that could go wrong to the tune of millions of pounds.

If that doesn't scare you and the people you work with, you shouldn't be doing the job. At the moment, it seems too few people are scared, because too few people take the security measures available to them. That's why we keep running the stories.

Set a solid security policy for off-site data, include draconian penalties to staff and contractors, and check it's being followed. Provide the means to follow that policy as painlessly as possible, but set the penalties for evasion or carelessness at a truly terrifying level. That might sound harsh — it is harsh — but if you assume the responsibilities for the livelihoods of hundreds or thousands of people, the implications cannot be left unsaid.

Get it right and you'll still lose laptops. You won't lose any customers, and you won't lose any sleep. And you won't lose your job.

 

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
58 out of 109 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters