CNNMoney.com
Companies Economy International Corrections Pre-market trading After-hours trading Winners/losers/actives Bonds Currencies Commodities Money Magazine Retirement Mutual Funds Taxes Ask the Expert Money 101 Autos Loan Center Best Places to Live Calculators Mortgage Rates Personal tech Big Tech blog Techland blog Sectors and stocks Fortune 500 techs Tech Talk 100 best places to launch Ultimate resource guide Small biz makeovers FSB 100 Fortune 500 Technology Investing Management Rankings Main Create portfolio Edit portfolio Create Alerts Edit Alerts
How to hacker-proof your business
Is the information stored by your company secure? Here's how to make sure your confidential data remains top secret.
By Kevin Poulsen, Business 2.0 Magazine

(Business 2.0 Magazine) -- You're savvy. You've read lots of network security horror stories, so you've taken all the usual precautions. You've installed firewalls, password-protected your gear, and created offsite backups.

But is that enough?

gatefold_01_usb_key.03.jpg
Photo GallerylaunchSee more photos

Probably not, because "information security" has practically become an oxymoron. The technologies that make today's corporations more efficient and effective also make them more vulnerable to attack.

Leakages tend to occur at the seams of an organization's defenses: A backup tape falls off a truck on its way to storage, or a laptop loaded with private data vanishes from the trunk of a car.

Targeted threats are evolving as well. The glory days of the lone hacker toiling away in his bedroom are a thing of the past; today's more sophisticated intruders have organized themselves into syndicates to conduct Mission Impossible-style "ops" - they actually call them that - to pilfer information from your network.

Don't count on your shiny new firewall to shield you, because it can't protect all your critical information, and data spills are very costly.

On top of the expense of investigating and cleaning up after a breach, your company may face potential Federal Trade Commission fines, civil liability, state action, and punishment in a competitive marketplace that frowns on sloppy information management.

The cost of alerting customers that you've lost their private information - a procedural requirement in many states - is itself nothing to sneeze at. After a hacker accessed records on 1.4 million state residents, California's Department of Health and Human Services spent $700,000 on mailing costs alone to alert the victims. Add to that the expense of offering your customers free credit monitoring and replacing the ones who flee to competitors, and a breach that exposes a mere 100,000 consumers can cost a company $23 million, according to security vendor Vontu.

The case for preventive medicine is strong. But how can you begin to defuse the threat? Read on for a detailed look at the information security hazards found within a typical office workplace.

Where is your company the most vulnerable?

A step-by-step guide to protecting your company from data theft.

Kevin Poulsen is a senior editor at Wired News. Top of page

To send a letter to the editor about this story, click here.

YOUR E-MAIL ALERTS
Follow the news that matters to you. Create your own alert to be notified on topics you're interested in.

Or, visit Popular Alerts for suggestions.
Manage alerts | What is this?
© 2008 Cable News Network. A Time Warner Company. All Rights Reserved. Terms under which this service is provided to you. Privacy Policy
Copyright © 2008 BigCharts.com Inc. All rights reserved. Please see our Terms of Use.
MarketWatch, the MarketWatch logo, and BigCharts are registered trademarks of MarketWatch, Inc.
Intraday data delayed 15 minutes for Nasdaq, and 20 minutes for other exchanges. All Times are ET.
Intraday data provided by ComStock, an Interactive Data Company and subject to the Terms of Use.
Historical, current end-of-day data, and splits data provided by FT Interactive Data.
Fundamental data provided by Hemscott.
SEC Filings data provided by Edgar Online Inc..
Earnings data provided by FactSet CallStreet, LLC.
* : Time reflects local markets trading time.† - Intraday data delayed 15 minutes for Nasdaq, and 20 minutes for other exchanges.• Disclaimer