Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Tuesday, August 14, 2018

New post for PNC's former CCO

New post for PNC's former CCO


By Patty Tascarella – Senior Reporter, Pittsburgh Business Times
Aug. 14, 2018

PNC Financial Services Group’s former chief communications officer is the new CMO at cybersecurity firm SonicWall and is based in Dallas.


David Chamberlin resigned from PNC in late June after more than two years as CCO. He had joined Pittsburgh’s biggest bank in 2015 as senior vice president and director of internal communications.

PNC (NYSE: PNC) has not announced Chamberlin’s successor as CCO. Chamberlin had previously served as executive vice president and general manager at the Dallas office of PR giant Edelman’s, and led its data security and privacy group. Before that, he had worked for SonicWall CEO Bill Conner at Nortel.

Chamberlin said he was pleased to reconnect with Conner and members of leadership team, return to cybersecurity, and to formally expand into marketing.

“It’s been something I’ve wanted to do for a while, especially since I’ve done a good deal of it during my career overseeing marketing, advertising, social and sponsorships at various times,” Chamberlin said.

Thursday, December 01, 2011

A question of transparency How is the threat of WikiLeaks changing corporate reporting?

In a post-WikiLeaks world, has the concept of confidential information become redundant? Serge Debrebant examines the issues facing companies whose secrets could become public knowledge at any moment

In July 2009, when Iceland was in the midst of a financial crisis, local television reporters discovered a cache of potentially explosive documents. The paperwork suggested that major shareholders of Kaupthing, the country’s biggest bank, had borrowed large sums of money unsecured by any significant assets shortly before the bank collapsed. Although the records did not indicate any wrongdoing, they revealed a potential conflict of interest.

The reporters worked intensively on a feature for the evening news, but five minutes before the start of the show, the authorities intervened and forbade the station to air the report. The station complied, but, by way of protest, the anchorman advised viewers to take a look at the documents themselves. For several minutes of live airtime, he showed the name of the website on which they could be found: wikileaks.org

The information will come out, it seems. But, as businesses are quickly learning, WikiLeaks speeds upthat process — and often skirts the old obstacles that companies used to be able to throw up.

Founded by Julian Assange and other activists in 2006, the website states that its purpose is to uncoverunethical behavior in governments and corporations. It does so by enabling whistle-blowers to send it internal documents anonymously and without fear of being detected. The most widely read scoops to result from this enterprise have been about international affairs — notably the Afghanistan files and us diplomatic cables — but the goings-on of the business world have also been a focus. In recent years, WikiLeaks has targeted large companies, with a particular focus on the banking sector.

Last November, Assange told Forbes magazine that about half of the documents that WikiLeaks possesses relate to the private sector. in the same interview, he announced that the next target would be “a big us bank.”

WHISTLE BLOWING MADE EASY

Whistle-blowing is neither a new phenomenon, nor is it restricted to WikiLeaks. However, the website has made it easier for disgruntled employees to reveal company data. In addition, the digitization of theworkplace plays into the hands of those with a mind to steal sensitive data and share it online.

For companies, the probability that internal documents might show up in the public domain has increased exponentially in the space of a decade. “Every company is a potential target,” says David Chamberlin, Director of issues & Crisis management at us public relations agency MSLGROUP.

Those who don’t recognize this learn it the hard way.

In 2008, Swiss bank Julius Baer discovered that Rudolf Elmer, a former employee, had published on WikiLeaks internal documents from a subsidiary based in the Cayman islands. Elmer worked there from 1994 to 2002, when he was fired. There ensued a long fight with his former employer. He accused Julius Baer of helping wealthy clients to avoid taxes by transferring money offshore. The bank quickly tried to obtain an injunction, and a judge in California complied, ordering that WikiLeaks’ domain name be shut down. it was — but, almost instantly, mirror sites appeared, and with them the very material Julius baer had wanted to suppress. Two weeks later, the judge vacated the injunction.

Julius Baer’s decision to take legal action had backfired. Not only were the documents still accessible, but the injunction had also raised the profile of the case at a time when American and European governments were trying to crack down on tax evasion. The US media published the numeric address of WikiLeaks, allowing readers to access it directly, and several press and civil rights organizations defended the website in the name of freedom of speech. Without Julius Baer’s intervention, the spat with Elmer might have gone unnoticed. Instead, it became the victim of one of WikiLeaks’ first big scoops.

The bank had experienced what technology journalist mike masnick christened the “streisand effect.” in 2003, actress barbra streisand tried to suppress the publication of photographs of her house in California, only to discover that the public outrage over her legal intervention led half a million viewers to the website on which they were posted. As Philip Gawith, managing Partner at the London-based communications agency Stockwell Group, puts it: “There will always be a place for a legal response,

but in a digital world, you need to be more careful.”

STOPPING THE LEAK

How, then, are companies supposed to deal with WikiLeaks? The most obvious step is to try to prevent the leak in the first place. A survey conducted for the software company SailPoint in 2009 showed that only 14% of organizations felt they had adequate controls in place to prevent leaks. Grady summers, who leads Information Security Program Management Services at Ernst & Young, observes that many companies do not pay enough attention to data security. He lists inappropriate access control, understaffing and outdated crisis response plans as the main issues — issues that are getting an ever-higher profile. “WikiLeaks has made IT security a boardroom issue,” he says.

When Summers advises companies, he outlines a four-step plan. First, he helps the company to identify sensitive data. Then, he helps it to come up with a data governance policy with appropriate access control and proper training of employees. Data loss prevention tools that control data movements help to enforce the policy. Finally, a crisis response plan empowers executives to react quickly in case a data breach occurs.

But proper IT security doesn’t rule out leaks. “Nothing is secure,” says Chamberlin, and a look at the data WikiLeaks has published so far confirms this view. It includes not only highly sensitive data such as customer details or secret reports, but also emails, phone transcripts and other material that would not necessarily be considered highly confidential, yet could still embarrass a company or government.

In Chamberlin’s view, it is important to tackle the root causes of unethical behavior and think about the values of a company and the way they play out in what executives do and say. “If there isn’t a level of integrity and consistency, it’s likely to lead to significant problems, because everybody’s watching,” he says.

RESPONSE STRATEGIES

All the professionals interviewed for this article agree that when a leak occurs, the response has be to swift and precise. Companies such as Ernst & Young offer exercises to test how well a crisis plan works. “It has to involve all relevant departments: iT and legal, but also human resources and public relations,” says Summers.

Although often overlooked, PR plays a key role. “You need to get your version of events out,” says Gawith. Even if a company is still trying to verify the accuracy of the leaked documents, it should quickly start communicating. “When people think you live in denial, they respond badly,” he adds. “Sometimes, the mere act of communication matters more than precisely what you say.”

A close look at the documents might also lead to a response strategy. In the case of Julius Baer, the bank was able to show that Elmer had forged a few of the published documents, which helped the bank to question his credibility.

If the leaked documents turn out to be real, and point to real problems, it is better to acknowledge the revelations and explain how the company wants to improve its operations, than to blame WikiLeaks or smear the whistle-blower. “You have to explain how to fix things so that they don’t happen again,” Chamberlin says. And of course, in the aftermath, a company has to turn words into actions in order to rebuild trust.

HELPING THE MARKETS FUNCTION

Such an outcome would be exactly what Assange and his collaborators hoped for when they founded WikiLeaks. In the Forbes interview in November 2010, he explained that he “loves markets” and that “in order for there to be a market, there has to be information.” From his point of view, WikiLeaks acts as a beneficial corrective to company secrecy and enables markets to function properly. Transparency enables stakeholders and consumers to make an informed decision that ultimately leads to more ethical business practices than before. “WikiLeaks means it’s easier to run a good business and harder to run a bad business,” he said.

In the long run, the work of WikiLeaks and other whistle-blower websites may prompt companies to communicate more openly with the public, shareholders and customers. “It‘s a tendency that i had observed before WikiLeaks,” says Gawith. “People take a greater interest in how businesses are run than they did 10 years ago.”

Ethical consumerism is the most prominent example of this trend. Fair trade certification systems guarantee transparent supply chains, while NGOs such as the environmental investigation Agency, with its investigations into illegal logging, have forced companies to change their behavior. in that respect, WikiLeaks is just one of a number of factors that are contributing to a trend toward greater transparency in business.

Monday, August 31, 2009

What You Must Know About Data Breaches And how to protect your company

by Joe Carberry & David J. Chamberlin
08.31.09, 01:45 PM EDT

Right now, in a part of your organization you may seldom think about, a devious computer hacker from another part of the world may be removing millions of electronic files containing personal employee and customer information. Are you confident your organization is prepared to handle the fallout from that breach when it is uncovered?

Last year at least 650 organizations reported being the victims of data breaches, and the number continues to rise. According to the latest research from the Ponemon Institute, only 36% of C-level executives are confident their organizations won't suffer data breaches in the next 12 months. Meanwhile the average cost of a data breach has risen to $6.7 million, according to the July 2009 issue of Digital Transactions, and that's without counting the legal, regulatory and reputation damage that inevitably follows such an event.

To read the whole article, click here.

Biggest Breaches of 2009

A Review of the Types and Trends of Data Breaches Involving Financial Institutions
August 28, 2009 - Linda McGlasson, Managing Editor


There have been 356 data breaches so far in 2009, according to the Identity Theft Resource Center (ITRC). And 46 of those breaches have involved financial institutions - up from 34 at this same time last year.

In reviewing these 46 incidents (see interactive timeline w/details of each breach), one finds goods news and bad, according to ITRC executive director Linda Foley.

The good news, Foley says, is that, based on percentages, financial institutions consistently have lower percentages of data breaches than other organizations. "This means they're doing a better job of controlling and protecting their data," she says.

The bad news is when financial institutions - or their third-party service providers -- are breached ... it's big. Example: the Heartland Payment Systems breach, which resulted in the compromise of 130 million credit and debit cards. Financial data -- bank account numbers, social security numbers, and other personal identifying information - is invaluable to hackers, and its loss is costly to consumers.

Granted, there aren't any other breaches on the Heartland scale, but there still have been some significant ones: Namely, an incident in February, when a defunct payments gateway was found to hold roughly 19,000 active credit card numbers. And then in May, a Countrywide insider breach resulted in potential compromise to 4,000 account numbers. And then there are the many breaches where the number of records exposed is unknown.

What happens when organizations are breached? Opening new lines of credit is the most frequent financial crime, with 67 percent of identity theft victims reporting this happened to them in 2008, Foley says. Last year, fraud cost consumers $1.8 billion, according to the Federal Trade Commission, and 26 percent of consumer complaints were related to identity theft.

Types, Timeline of Breaches
Including Heartland -- the poster child for 2009 data breaches -- the 46 financial services-related breaches tracked by the ITRC this year are divided into seven types:

* Insider theft: 12 breaches;
* Skimming: 8;
* Missing paper documents: 10 of the breaches
* Exposure of data on the Internet: 4;
* Accidental breaches: 2;
* Stolen or missing hard drives/laptops: 5;
* Outside network intrusions: 2;
* Unknown cause: 3.

A review of breaches shows that May so far has been the busiest month of 2009 with 10 reported breaches. March is the second-busiest month, with 8 reports, while August so far has seen 7.

Breach data is collected by the ITRC through multiple ways, including from state attorneys general offices, news media and other data breach reporting entities. To see the ITRC's entire analysis of data breaches across industry, visit the nonprofit organization's website.

Examples of Breaches
Each of the 46 breaches involving financial institutions is detailed in the accompanying timeline and listing. Here is just a sampling of the types of incidents the ITRC has collected:

Insider Theft - A man posed as an Air Force reservist got 4,000 account numbers from Countrywide Financial in Forth Worth, TX and used them to steal $500,000 over a two-year period. Investigators tracked the case to his accomplice, a female customer service rep at Countrywide. Along with the account numbers being used, personal identities were compromised in the scheme, say investigators, who arrested Isaac McCrumby, 29 an unemployed R&B singer, in April. McCrumby used a fake Air Force ID to cash the bogus checks and pass bad credit cards.

Skimming - A band of thieves rigged Sovereign Bank ATMs in Staten Island, NY in May with skimmers so that they could steal account and password information from bank customers. The thieves placed hidden cameras to film victims typing in PIN codes.

Paper Documents Missing/Found - On Aug. 4, a Holiday Inn in Wichita, KS reported finding client records from a defunct local mortgage-brokerage firm, Morrison Financial Corp., in its dumpster. Information included Social Security numbers, bank accounts and photocopies of drivers' licenses and checks. The mortgage company shared parking with the hotel.

Accidental Exposure - In January, AES, the service provider for Student Loan Xpress, says it "inadvertently transmitted names, addresses, SSNs and dates of birth to another student loan lender" with which AES contract. The other lender said it destroyed all information mistakenly received.

Exposure Via Internet - A major credit card company, CompuCredit/Aspire is investigating how 120 customer credit card statements made available online on May 11. Account information including SSNs was involved. Further information from CompuCredit reveals it was a computer processing error that created a single image file of 120 account statements.

Hardware Stolen/Missing - Two desktop computers were stolen from the office of Sullivan and Schlieman Wealth Management, LLC, a financial advisor in Alpharetta, GA on March 27. In a letter to the New Hampshire Attorney General's office informing the AG of the breach, the company says that personal information of LPL Financial clients including names, addresses, financial account information and Social Security numbers "may have been breached." LPL Financial in Westlake, OH was not notified of the theft and exposure until April 29. Affected clients were notified in May.

Unknown Cause - Bank of America Corp. and Citigroup Inc. have issued new credit and debit cards to Massachusetts customers after running into data-safety concerns. Charlotte-based BofA and Citigroup each recently issued replacement cards to consumers in August, telling them in letters that their account numbers may have been compromised by an undisclosed third-party.

How to Handle a Breach
For financial institutions, a breach can be devastating to reputation and the trust, so communication is key, says David Chamberlin, director of issues and crisis management for MLSWorldwide, a public relations firm that has handled data breach communications for large breaches, including the recent Radisson Hotels & Resorts incident.

"In any crisis, it is natural to want to avoid criticism and blame," Chamberlin says. "However, communicating in a timely and honest manner will ease fear and suspicion among customers, and help reduce the odds of escalation in news media and online."

This communication will also help demonstrate one of today's most important tenets of business: transparency. "One of the easiest ways to lose customers in a crisis is to fail to acknowledge the situation at hand," Chamberlin says. "Consumers will forgive mistakes, but rarely will they absolve an organization that does not act responsibly."

Even if an institution is not to blame for the breach, it still has a responsibility to protect its customers. "As such, demonstrating responsible behavior can help manage the crisis - and is a necessary first step to rebuilding reputation following a crisis," he says.

For more on breaches, see:

* Data Breach Trends - Mary Monahan, Javelin Strategy & Research
* 'Watch Your Business Partners' - Bryan Sartin of Verizon Business on the Latest Data Breach Trends