Protecting Sensitive Data: How Secure is Your Wireless Network?

In previous articles we discussed how laptop computers and the office copy machine increase the risk of data security breaches. Another significant risk to an organization’s sensitive data is the wireless network. Since today’s workplaces are increasingly “going wireless,” the Federal Trade Commission recommends taking the following steps to protect wireless networks.

Understand how a wireless network works. Going wireless generally requires connecting an internet access point to a wireless router, which sends a signal through the air, sometimes as far as several hundred feet. Any computer within range can pull the signal from the air and access the internet. Unless precautions are taken, others can “piggyback” on the network or access information on the computer.

Use encryption. Encryption encodes the information so that it’s not accessible to others. It is the most effective way to secure a network. Two main types of encryption are available: Wi-Fi Protected Access (WPA) and Wired Equivalent Privacy (WEP). WPA2 is strongest so it should be used whenever possible. Since some older routers use the less secure WEP encryption, consider upgrading to a newer, more secure router. Note that wireless routers often come with the encryption feature turned off, so be sure to turn it on.

Use anti-virus and anti-spyware software. Since hackers are constantly developing new ways to attack computers and networks, security software is necessary. This software needs to be updated periodically so systems should be set to update automatically whenever possible.

Change the name of the router. The name of the router (often called the service set identifier or SSID) is likely to be a standard, default ID assigned by the manufacturer. Change the name to something private and unique.

Change the router’s pre-set password. Manufacturers typically assign a standard default password to a wireless router. Default passwords should be changed. Visit the manufacturer’s website to learn how to change the password.

Limit access to the wireless network. Every computer that is able to communicate with a network is assigned a unique Media Access Control (MAC) address. Wireless routers usually have a mechanism to allow only devices with particular MAC addresses to access the network. However, since MAC addresses can be mimicked, don’t rely on this step alone.

Turn off wireless network when it’s not being used. A wireless network cannot be accessed when it is turned off.

Be cautious when using a public wireless network. Many cafés, hotels, airports and other public places offer wireless networks for their customers to use. These “hot spots” are convenient, but they may not be secure.

Organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you’d like to subscribe to our weekly newsletters please click here.

Prevent Data Security Breaches by Protecting Laptop Computers

While laptop computers can increase workforce productivity, they also increase the risk of harmful and costly data security breaches. Since a lost or stolen laptop can jeopardize sensitive information, the Federal Trade Commission recommends the following preventative measures to protect laptop computers and the personally identifying information it contains.

Treat laptops like cash. People don’t leave their cash unattended, not even for a minute. When traveling, cash isn’t usually checked with luggage and it isn’t left in the backseat of the car. Keep the same watchful eye on the laptop as you would on cash.

Lock laptops with a security cable. Whether in the office, a hotel or some other public place, a laptop security cable should always be used. Attach it to something immovable or to a heavy piece of furniture, such as a table or a desk. Security cables work similarly to bike locks. You can purchase them at Office Depot, Amazon, Staples, etc.

Be on guard in airports and hotels. The confusion and shuffle of security checkpoints can be fertile ground for theft. Keep an eye on the laptop when going through airport security. Hold onto it until the person in front of you has gone through the metal detector, and wait for it to emerge on the other side. When staying in a hotel overnight, a security cable may not be enough. Store the laptop in the room safe. If leaving a laptop attached to a security cable in a hotel room, consider hanging the “do not disturb” sign on the door.

Consider an alarm. Depending on security needs, a laptop alarm can be an excellent security device. Some laptop alarms sound when there’s unexpected motion, or when the computer moves outside a specified range. A program that reports the location of stolen laptops upon being connected to the internet can also provide additional security.

Consider carrying laptops in something more discreet than a laptop case. When taking a laptop on the road, carrying it in a computer case may advertise what’s inside. Consider using a suitcase, a padded briefcase, or a backpack instead.

Don’t leave laptops unattended. Though colleagues may seem trustworthy, avoid the temptation to leave laptops unattended, even for a minute. Laptops should be taken whenever possible. If taking the laptop is not an option, use a cable to secure it to a table or desk.

Don’t leave a laptop in a car. Parked cars are a favorite target of laptop thieves. If leaving a laptop in a car is the only option, keep it locked up and out of sight.

Don’t put laptops on the floor. Whether at a conference, coffee shop, or registration desk, laptops should not be left on the floor. If it is necessary to put the laptop down, place it between your feet or up against your leg so you remember that it’s there.

Don’t keep passwords with the laptop or in its case. Remembering strong passwords or access numbers can be a challenge. However, leaving them in the laptop carrying case or on the laptop is like leaving keys in a car. In the event a laptop is lost or stolen, don’t make it easy for a thief to access sensitive information stored on the device.

Create ‘Uncrackable’ Passwords

The best passwords are over 6 characters, include upper and lowercase letters, and use numbers and symbols. Passcreator.com can generate a password that is nearly impossible to crack. However, this would mean you probably won’t remember it on your own. So, if you have to write any of your passwords down keep that document separate from your laptop. You can write them down on a piece of paper and keep them in your wallet. You can store them on Google Drive. Just be sure to password protect the doc! You can also store them on an Excel spreadsheet and protect the workbook to make it harder for a hacker to view its contents.

Encrypt sensitive data. The consequences of a lost or stolen laptop can be minimized by encrypting the data stored on the device so that it cannot be accessed by anyone without the proper authorization.

Organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to subscribe to our newsletters please click here.

Protecting Sensitive Data: Don’t Forget the Copy Machine

Collecting personally identifying information from clients, such as names, social security numbers and credit card numbers, is common practice. This means that protecting against a data security breach is (or should be) a priority for virtually every organization. Unfortunately, when it comes to implementing data security measures, many organizations overlook a significant and somewhat obvious threat: the copy machine.

Commercial copiers have come a long way, and though they may not look it, they are powerful computers. Today’s generation of networked multifunction copiers are “smart” machines capable of copying, printing, scanning, faxing and emailing documents. To manage incoming jobs and heavy workloads, these copiers require hard disk drives capable of storing a lot of information. And, since they are often leased, returned and then leased or sold again, the Federal Trade Commission (FTC) recommends including copy machines in an organization’s data security plans.

Understanding security options is the first step to controlling the risks posed by copy machines. Most manufacturers offer data security features with their copiers, either as standard equipment or as optional add-on kits. These features typically involve encryption and overwriting.

Encryption is the scrambling of data using a secret code that can be read only by particular software. Copiers offering encryption encode the data stored on the hard drive so that it cannot be retrieved even if the hard drive is removed from the machine. Since encryption is typically an automatic feature with many copiers, specific steps or processes are generally not necessary.

Overwriting changes the values of the bits on the hard drive that make up a file by replacing existing data with random characters. By overwriting the drive space occupied by a file, its traces are removed, and the file can’t be reconstructed as easily. This is different from deleting or reformatting, which doesn’t actually alter or remove the data.

Depending on the copier, the overwriting feature may allow a user to overwrite after every job, periodically or on a preset schedule. Users may also be able to set the number of times data is overwritten; generally, the more times data is overwritten, the safer it is from being retrieved. The FTC recommends overwriting the entire hard drive at least once a month.

Finally, security measures must be taken before returning, selling or discarding a copy machine. Check with the manufacturer, dealer, or servicing company for options on securing the hard drive. Some may offer to remove the hard drive so that it can be disposed of, stored or destroyed pursuant to an organization’s own security policies and procedures. Others may undertake the task of overwriting the hard drive. These services may involve an additional fee, so check the lease or purchase agreement before deciding how to proceed.

Copiers are often the center of an organization’s operations. They have “seen” and saved countless documents with sensitive, confidential or personally identifying information. This is why protecting the copy machine should be a part of every organization’s data security plans.

Organizations should also consider protecting against data security breaches with insurance. Various insurance products are available to protect against privacy injuries, such as identity theft, resulting from security breaches and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that proper coverage is obtained and that no gaps remain.

If would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to learn more about insuring against data security breaches, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Protecting Valuable Business Papers and Records

Businesses often prepare an inventory of valuable property to simplify the process of filing an insurance claim in the event of a loss. For some reason, papers and records rarely make the list, even though losing these documents could disrupt business operations. Fortunately, insurance is available to cover the unbudgeted and often significant costs of dealing with a loss of business papers and records.

Valuable Papers and Records (VPR) coverage is a type of property insurance that covers the cost to research, replace or restore information that is lost when papers and records are damaged or destroyed. This insurance generally covers papers and records owned by the insured or in the insured’s care, custody and control, and it is often found in property insurance and small business owners’ policies. Large or unique risks may require a separate, stand-alone policy.

Notably, since VPR covers the cost of reproduction, it is not intended to protect items that cannot be replaced or duplicated because they will only be valued at the cost of blank material of substantially identical type. So, if an original Declaration of Independence is lost, the insurer will cover the cost of a blank piece of paper. To ensure maximum protection, irreplaceable items must be listed separately under the policy and possibly appraised so their value can be determined. In some cases, a separate insurance policy may be necessary.

VPR coverage is ideal for most businesses, including:

  • accountants
  • law firms
  • architects and engineers
  • physicians and medical offices
  • businesses that regularly produce and rely on important documents, such as files, receipts, invoices, lists, contracts, etc.

When shopping for VPR coverage, it is important to know what the policy does and does not cover. Although definitions may vary, ‘Valuable Papers and Records’ are generally defined to include documents, manuscripts and records that are inscribed, printed or written, including abstracts, books, deeds, drawings, films, maps and mortgages.

VPR policies do not typically cover money or securities. Importantly, once papers and records are reduced to electronic format or saved on some form of electronic media (CDs, hard drives, tapes, disks, etc.), they are generally excluded from coverage under a VPR policy, and need to be insured under an Electronic Data Processing policy.

The cause of the direct physical loss or damage to the papers and records must be a covered loss under the policy. Losses caused by errors in processing or copying, earth movement, war, neglect, nuclear hazard and various events involving water are typically not covered. Since even the broadest policy forms have exclusions, it is important to review them carefully.

Coverage limits should be enough to cover the cost of replacing or reconstructing lost information through research or transcription from other sources. While VPR generally covers items kept at the premises listed on the policy’s declarations, papers and records kept at an unlisted location may be subject to a lower limit (sub-limit) or may be excluded from coverage altogether. Make sure the policy lists all locations where papers and records may be stored.

In addition to VPR insurance, businesses may consider storing papers and records in a facility with the reputation, amenities and expertise needed to offer maximum protection. According to Carlos Diaz of Value Store it, “Not all storage facilities offer a comprehensive approach to this risk. Not all solutions are the same.” Some additional services to look for in a storage facility include:

  • Professional and responsive staff
  • Physical features/amenities (fire and security system, climate control, etc.)
  • Experience in handling and storing similar papers and records
  • Comprehensive Solutions (digitizing, e-filing, bulk shredding, etc.)
  • Ability to comply with applicable laws (HIPAA, Gramm-Leach-Bliley, etc.)

Be sure to visit the storage facility and check references, and before moving in, confirm coverage by checking the VPR policy. If it has lower limits for papers and records stored off-premises or excludes coverage altogether, the storage facility may need to be added to the list of covered locations.

Though protecting against the loss of papers and records is rarely high on the list of priorities, it should be. Those who underestimate the importance of papers and records may one day recognize they are not just valuable, they are invaluable.

If you would like to learn more about protecting your valuable papers and records, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Protecting Your Business from Cyber Liability Risks

Almost every business relies on computers, networks and electronic data to support their business operations and serve their customers. What most business owners don’t realize is the substantial exposure associated with their use of electronic platforms and the data those platforms host. Today, Cyber Liability insurance is available to business owners for the exposures associated with their use of electronic platforms.

Most businesses are not aware that standard Commercial General Liability policies do not contemplate these types of claims, leaving companies with significant gaps in coverage for cyber-related perils. Any business that collects or handles confidential information, stores client data, uses email, generates revenue online, relies on the internet for transactions or uses a network to conduct its business is in need of this important coverage.

Cyber Liability insurance is designed to protect the insured against direct and indirect loss to the Company’s assets as well as third party claims of negligence. Losses can be caused by hazards such as the transmission of virus/malicious code, denial of service attacks, physical theft of a computer/device, accidental release of an insured’s confidential data and attacks by hackers. First party coverage under the Cyber Perils policy includes:

  • Loss of data
  • Loss of business income
  • Electronic theft
  • Cyber extortion
  • Security event costs

Third party claims of negligence can include allegations that an insured:

  • Permitted the unauthorized disclosure of confidential information
  • Failed to secure a Network against attack
  • Committed an act of defamation

Of particular interest to many businesses are data breach security concerns. Recent studies have shown that over 70 percent of all data security breaches are experienced by small to medium sized businesses and the cost of a breach can be staggering. The average cost for a data breach claim is over two million dollars. These damages include the cost of data reconstruction, customer/client notification and credit monitoring. This leaves small businesses most at risk because they are unlikely to have the time and resources necessary to handle a data breach security event.

Given the variety and complexity of these occurrences, an experienced insurance agent should be consulted to ensure that proper coverage is obtained and that no gaps remain. If you would like to learn more about insuring against data security breaches, contact us.