Database Security – Just How Safe is Your Personal Information?
I recently received a letter from my bank informing me that some of my personal information had been breached. While they did offer a one-year free subscription to Experian’s credit report monitoring system, they offered no explanation in regards to the type of breach, what specific information was stolen, and by whom.
I can’t say that I was very pleased with this outcome, and couldn’t help but feel resentful that my bank hadn’t taken any real measures to protect my sensitive information BEFORE it fell into the wrong hands.
I did a little research on this topic, and didn’t have to look very hard to find an alarming number of similar breaches (and these are just a few examples of the published ones!). They include:
1. July 2007 – A DBA contractor for a subsidiary of Fidelity Information Services was caught selling 2.3 million customer records, including credit card and bank account details.
2. July 2007 – An employee of a credit card processing company servicing the Disney Movie Club was caught by federal agents trying to sell credit card information.
3. December 2006 – Hackers gained access to a UCLA database containing personal information on 800,000 current and former students, faculty and staff, financial aid applicants and their parents (including those who did not even attend!). In this case, the university set up a dedicated website to help those affected by possible identity theft following the breach.
The good news is that there are now solutions that can prevent (or at least significantly reduce) this type of database security risk. In fact, we at RADirect are currently reselling a software offering from Sentrigo – the Hedgehog Oracle database security system (support for more databases coming soon). You can download a free 14-day eval license for the enterprise version.
If your business owns or maintains a database of personal information, please take real measures to protect it. It is the responsible thing to do, and represents a solid business practice.