Data Breach Incidents Up for 2008
The Identity Theft Resource Center (ITRC) has issued a press release indicating that the number of breach incidents in 2008 already surpass those in all of 2007.
The ITRC had recorded, as of August 22nd, 449 data breaches in 2008. The total number of breaches for 2007, for the entire year, was 446. In both cases, the actual number of breaches are likely higher due to under-reporting and lack of detection. These breach figures speak to incidents, not the number of entities involved in each event or the number of people affected by them.
Linda Foley, founder of ITRC, attributes part of the growth of the breach list to the ability to access Attorney General notification lists in three states, which outline data breaches that don’t always make it to the mainstream media. Linda also believes that more companies are pro-activiely auditing their systems and identifying breaches that were previously undetected.
The current breach list at the ITRC, which reflects more than 22 million compromised records, is also only a partial list of the problem. In more than 40% of breach events, the number of records exposed is not disclosed or known. Although figures of records breached are often more newsworthy, breach events themselves are a more usable statistic for research purposes, ITRC notes.
Of the 449 breaches in 2008, 11% of them have been the result of contractor breaches. That’s an obvious huge area of concern for businesses to identify, and for security policies to step up.
PogoWasRight asks some very pointed questions about the need for a full disclosure law, the role of the federal government in breach situations, and who exactly is responsible to ensure affected individuals in any case are notified of a breach. The same author also talks about the correlation between breach notification, types of breaches, and fraud.
Via emergent chaos ; image ppdigital @morguefile







One Comment on “Data Breach Incidents Up for 2008”

October 10th, 2008 at 3:55 pm
These data breaches and thefts are due to a lagging business culture. I found some fresh and original thinking from the author of “IT Wars” - http://www.businessforum.com/DScott_02.html - I urge every business person and IT person, management or staff, to get hold of a copy of “I.T. Wars: Managing the Business-Technology Weave in the New Millennium.” It has an excellent chapter on security, and how to scale security for any organization, any budget. It also has a plan template with all considerations. Our CEO has read this book. Our project managers have read it. Our vendors are required to read it (they can borrow our copies if they don’t want to purchase it) – it helps them to understand our values and practices. Any agencies that wish to partner with us: We ask that they read it. Do yourself a favor and read this book – BEFORE you suffer a breach.