Thursday, April 01, 2010

If you ever wondered who company A was, it was JCPenney. It is now reported in media, that JCPenney was "Company A" in the Albert Gonzalez trial. JCPenney Has Dodged a Huge Bullet... Until Now

Monday, March 29, 2010

According to an article in eWeek - March 29, 2010
Educational Credit Management reported the theft of portable media with Social Security numbers, names, addresses, and other information belonging to some 3.3 million people.
Millions of Student Loan Records Stolen in Data Breach

Tuesday, January 26, 2010

Two health care providers this week experienced significant data losses of personal health care information, one is BlueCross, the other is University Medical Center, UMC. Insurer BlueCross BlueShield told thousands of members this week that a thief stole 57 computer hard drives from call center inChattanooga. See an article in internet news here: http://www.internetnews.com/welcomead/

UMC has for more than three months losing personal information of traffic accident victims including social security numbers, birth dates. According to UMC, this has been leaked by someone at University Medical Center. See article in the Las Vegas Sun here: http://www.lasvegassun.com/news/2010/jan/25/umc-patient-info-leaks-likely-date-back-july/

Monday, January 25, 2010

A video on data loss prevention, rights management usage, RMS, file classification infrastructure in Windows Server 2008 R2, FCI, and RSA Data Loss Prevention, DLP is now available: Video: http://edge.technet.com/Media/Securing-Sensitive-Information--How-MSIT-uses-ADRMS--RSA-DLP/

Friday, December 18, 2009

North Korea may have stolen sensitive information from an unsecured USB, see this article: http://joongangdaily.joins.com/article/view.asp?aid=2914211. The USB contained information from a secure military network, and got exposed when the USB was accessible via the internet. A good reason why data loss prevention with enterprise rights management is crucial for improved security.

Tuesday, November 24, 2009

Updated white paper on how Microsoft IT does Data Loss Prevention, DLP using Rights Management Server, RMS, and RSA DLP: http://technet.microsoft.com/en-us/library/bb897856.aspx

Wednesday, November 18, 2009

According to BBC, T-Mobile staff sold personal data: http://news.bbc.co.uk/2/hi/uk_news/8364421.stm

Wednesday, October 21, 2009

A new Showcase Study on Microsoft IT's use of RMS and RSA DLP has been completed and posted at http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000005319
A new white paper has been published to show how MSIT uses FCI in this MSIT Showcase Study http://vepcdn.microsoft.com/prod/images/64/Area/214/2676/9fd29bc1-bd16-42fe-a39e-f1d91d62aa60.pdf.
According to an article in http://darkreading.com, a Ford engineer allegedly stole 4,000 sensitive files by copying and downloading to a USB device before seeking employment with a Chinese competitor of Ford

Monday, July 27, 2009

Network Solutions hacked, 573,000 accounts compromised

According to an article in Washington Post, Network Solutions was hacked, and information from 573,000 accounts were accessed by the hackers. http://www.washingtonpost.com/wp-dyn/content/article/2009/07/24/AR2009072403527.html

Friday, July 17, 2009

Twitter found itself having business secrets exposed here: http://www.techcrunch.com/2009/07/16/twitters-internal-strategy-laid-bare-to-be-the-pulse-of-the-planet/ after a hack of a username and password. The information stolen includes strategic meeting minutes, personal information and more.
The breach at Lexis Nexis where PII was stolen, is linked to the Mafia according to this article from internetnews.com: http://www.internetnews.com/security/article.php/3829911/LexisNexis+Breach+Linked+to+Mafia.htm

Tuesday, July 07, 2009

According to this article in Washington Post, SSNs can be guessed easily using publicly known information: http://www.washingtonpost.com/wp-dyn/content/article/2009/07/06/AR2009070602955.html. It is also covered inhis article from Fast Company explaining how information users post on Facebook can be used to reverse engineer their SSN: http://www.fastcompany.com/blog/chris-dannen/techwatch/facebook-new-algorithm-can-guess-your-ssn
Methodology for deploying a protection program for sensitive information:


Titus Labs has announced that they are capable of using the new File Classification Infrastructure provided in Windows Server 2008 R2.

Tuesday, June 23, 2009

According to Principal AnalystForrester Research Chenxi Wang, Ph.D. Enterprises lack data leakage protection solutions for Web 2.0 applications. The answer is to deploy DLP and DRM technologies in the enterprise.
I have started a twitter, o_O, you can find me by searching for Opedal, and I am building a face book, you can find me by searching for Olav Opedal
A new feature in Windows Server 2008 R2, is really interesting. It allows for tagging meta data to files stored in file shares, and allows for search, retention management, classification and protection. Information about File Classification Infrastructure in Server 2008: http://blogs.technet.com/filecab/archive/tags/File+Classification+Infrastructure+_2800_FCI_2900_/default.aspx