Outdated security systems leave personal data vulnerable: watchdog
03.06.2008 17:01
Shopping
- Source: cbc.ca
Many Canadian companies continue to leave their customers' personal information vulnerable to theft, neglecting to bolster online security systems with basic upgrades, the Office of the Privacy Commissioner said in a report released Tuesday. Privacy commissioner Jennifer Stoddart said many companies continue to leave laptops unprotected without proper firewalls and encryption. She also noted a lack of proper privacy training leaves companies open to attacks. The report said that just one-third of businesses had educated their staff about their responsibilities to safeguard consumers' information under the Personal Information Protection and Electronic Document Act (PIPEDA), Canada's private sector privacy law which governs the use, collection and disclosure of personal information. "Too often, large corporations underestimate both the value of personal information and the risk that thieves will target it," Stoddart said in the report. "As a result, we see deficient safeguards, lackadaisical privacy and security policies and procedures — and, of course, data spills." TJX Cos. breach deemed the “largest-ever online burglary”The report singled out the TJX Cos. data breach — in which more than 94 million credit and debit cards were exposed — as particularly "staggering" and the "largest-ever online burglary." A probe by the privacy commissioner's office found the Massachusetts-based parent company of Winners and HomeSense collected too much information, kept the data for too long and relied on weak WEP encryption technology to protect its wireless local networks. The privacy commissioner also found the hackers did not use sophisticated equipment to break into the computer system. "It's believed that thieves armed with an antenna and a laptop computer and some specialized software settled in outside a Marshall's in Miami and broke into the store's poorly protected wireless local area networks," the report said. The report suggests the breach will cost TJX Cos. hundreds of millions of dollars. Also in 2007, Talvest Mutual Funds, a subsidiary of CIBC, reported losing a hard drive containing the personal data of nearly half a million customers. OPC calls for mandatory reportingStoddart also in the report recommended adding an amendment to PIPEDA that would force companies to report when a data breach occurred. Such an amendment would help consumers to protect themselves and might motivate companies to take security more seriously, she said. The privacy commissioner responded to 7,500 PIPEDA inquiries and closed 420 investigations in 2007, according to the report. The bulk of the breaches reported concerned financial institutions, while companies in the telecommunications, insurance and retail sectors also filed reports. According to the anti-fraud call centre Phonebusters, there were 9,972 incidents of identity theft in 2007, with losses totalling $6,430,823.75. Story Tools: E-MAIL | PRINT | Text Size: SMLXL | REPORT TYPO | SEND YOUR FEEDBACKRelatedInternal LinksIN DEPTH: Identity theftFirms must try harder to guard personal data: Privacy CommissionerTJX breach was preventable: privacy commissionerExternal LinksPrivacy Commissioner of Canada(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window) Consumer HeadlinesOutdated security systems leave personal data vulnerable: watchdogMany Canadian companies haven't bolstered their security systems, leaving customers' personal data vulnerable to theft, according to the privacy watchdog.Green thumbs meet red ink as fuel costs soarNurseries and garden centres say they're feeling the pinch as fuel costs continue to increase — and it's only a matter of time before customers see price increases.Auto-rebate program to run over budget, documents suggestInternal estimates from Transport Canada suggest Ottawa underestimated the amount of money needed for the clean-car rebates by as much as $65 million.Raise food production 50% by 2030: UN chiefWorld food production must increase by 50 per cent by 2030 if it hopes to meet rising demand, the head of the UN told world leaders at a food summit in Rome Tuesday.Flower power over coffee beans, anti-Tim's protesters sayDemonstrators used flowers and soil Monday evening to protest a proposed Tim Hortons franchise in a western Newfoundland city. Consumer Life FeaturesMAPGas pricesYOUR FUEL REPORTShare your storyHow do you plan to fuel your future?INTERNETAlways onlineSlew of new portable gadgets constantly connected to webBLOGFood BytesHave my cake and eat it tooBLOGComm-OdditiesDesigner's ashes buried in Pringles canPeople who read this also read …
|