Showing posts with label business security. Show all posts
Showing posts with label business security. Show all posts

Thursday, June 24, 2010

How Much Should You Spend On Security? Gartner Offers Some Answers

Security drops to No. 9 on the list of IT priorities, research firm says Jun 24, 2010

NATIONAL HARBOR, MD. -- Gartner Security Summit 2010 -- Security is not as big a priority for enterprises as it was in 2008, but it's still grabbing a healthy chunk of the IT budget, a major research firm said Tuesday.

Speaking at the annual Gartner Security Summit here, senior analyst Vic Wheatman said that although security has dropped to ninth place on CIOs' lists of top priorities, spending is still strong.

After placing eighth on the 2009 priority list and fifth in 2008, security is continuing to drop on the hit parade, Wheatman said. But security still accounts for an average of 5 percent of total IT spending, he says.

Interestingly, the IT industry spends the most on security -- 11.3 percent of their total IT budget, Wheatman said. Banking and finance companies spend about 8.3 percent of their IT budgets on security; educational institutions spend less than 4 percent.

The average business spends about $525 per employee annually on security, Wheatman continued. The insurance industry spends the most: about $886 per employee. The transportation industry spends only about $155 per employee on security.

Wednesday, May 19, 2010

Valley restaurant dumps years worth of sensitive information in dumpster



“Last name Taylor, first name Gary, social security number 569…“

Tom Rezler is a business owner in this Tempe shopping center and can't believe what he recently found in nearby garbage dumpsters.

Thousands of pages of sensitive information apparently disposed of by a neighboring business called The Vine Tavern and Eatery.

“As a patron of the Vine and having used my credit card hundreds of times in there, I'm a little upset that my information is now privy to anyone that can find this stuff,” Rezler said.

The documents included people's names, social security numbers and dates of birth from restaurant applications.

There were checks with banking information and also credit card receipts from Vine customers, receipts that revealed a person's entire credit card number. azfamily

Monday, October 26, 2009

SecurityMetrics Services Over 100,000 PCI Compliance Calls Each Month


SecurityMetrics, a world leader in PCI security, today revealed that they service over One Hundred Thousand (100,000) retail merchant calls each month, counseling merchants worldwide on achieving PCI compliance. SecurityMetrics' PCI Site Certification Services for Merchants provides bank acquirers and ISOs (Independent Sales Organization) with a scalable program to accelerate PCI compliance among their strategic accounts and merchant portfolios.

SecurityMetrics' PCI programs give merchants simplified systems and free personalized technical assistance so that retail merchants, with little to no IT security experience, can quickly and easily validate and report
their PCI compliance status according to the Payment Card Industry (PCI) Data Security Standard (DSS).

"Consumers rely on retailers to secure their credit card information," said Brad Caldwell, CEO of SecurityMetrics. "As one of the first companies in the industry to deploy a successful mass merchant PCI program, we now have acquiring bank and ISO customers realize more than 90% enrollment levels across their merchant portfolio.

Our programs personally assist small business owners with little to no security backgrounds and scale to accommodate multi-national corporations that generate millions of transactions annually. All SecurityMetrics' security programs have one goal in mind: to simplify and accelerate PCI DSS
compliance and ensure sensitive credit card information is secure." Reuters

Saturday, September 26, 2009

Identity Theft Protection Tips For the Digital Age


As a small business owner, can you honestly say that your workplace is as safe from exposure to identity theft as possible? It’s a fact that the issue of identity theft is an increasing problem that is already quite widespread. It’s a good idea to periodically do a checkup on your business security policies and procedures to ensure that you have taken every possible step to keep your company’s data safe from identity thieves, as well as personally identifiable information that belongs to your employees and your customers.

1. Be Careful What You Throw Away

Identity thieves are skilled dumpster divers. If you or your employees throw away papers that include bank account numbers, social security numbers, and other information that can be used to perpetuate fraud, there’s a good chance that the data could end up in the hands of unscrupulous characters. Make it a firm policy to shred all waste paper that has any information that could possibly be used by people who might be looking to steal someone else’s identity.

If you only have a small quantity of this type of documentation, it will probably be feasible to handle shredding in-house, with shredders placed in strategic locations around your place of business. If your business generates a large quantity of documentation that contains protected information, it may be better for you to hire a document shredding company to take care of destroying throw away documents that may contain sensitive information.

2. Take Steps to Protect Data Stored on Company Computers

Verify that the virus protection and firewall software installed on your computer system remains current at all times. Make sure that you are using a quality virus protection program and set it up to run daily scans so that you can be as safe from computer viruses as possible. It’s also important to check for updates to your virus software and install them as soon as they become available.

It’s also a good idea to set up every desktop computer and laptop so that a password is required for login. This can help protect stored data in the event that the equipment is lost or stolen and ends up in the wrong hands. This is not a foolproof protection, of course, because skilled hackers can find their way around password protection in many cases. However, it’s certainly better than leaving computer equipment unprotected.

When your company upgrades computer equipment, it’s essential to dispose of your old equipment responsibly. Simply deleting files from your old hard drive is not sufficient to keep identity thieves from stealing your confidential data if the equipment is not properly disposed of. The only truly safe way to get rid of data from your old computer is to shred the hard drives. The same companies that provide document shredding services typically also offer hard drive recycling.

American Banking News