The biggest security story of 2010 is the WikiLeaks posting of diplomatic cables that rocked the U.S. government — more than once. The document leaks shed a blinding light on enterprise data security at a whole new level. But what can small and midsize businesses (SMBs) learn from the security fiasco? Plenty.
Similar to enterprise policy, SMBs should build best practices around measuring and monitoring who accesses their data and deny access based on rules, said Justin Strong, a product marketing manager at Novell. Data encryption and an automated way to enforce encryption when dealing with USB flash drives and other removable storage devices are the key to avoiding this type of leak.
“It is extremely important to educate employees on the dangers of RSDs — Removable Storage Devices. Never use an unknown USB stick or other form of removable media –these can frequently have malware on them,” Strong said. “Second, costs, which are top of mind with all SMBs, shouldn’t prevent you from implementing a basic set of security policies. Even baseline solutions can go a long way.”
Information Security Matters
Oliver Lavery, director of security research and development for nCircle, said the main lesson for every business in this mess is that information security matters. The government and many of the companies that are opposing WikiLeaks are just shooting the messenger, he said.
“The problem isn’t WikiLeaks at all, and shutting them down is pointless. Once the information had been (taken by users), they could have uploaded it to BitTorrent, or any number of other online forums. The problem is that there was a systemic failure to protect information that was classified as secret,” Lavery said. “Don’t make the same mistake with critical data inside your organization. Once the information has been (taken), you have lost control and it can be made…