This Month Only! >> $20 off and a FREE SHRM tote with your membership and code TOTE2018!
Sign up for free email newsletters and get more SHRM content delivered to your inbox.
Is your employee handbook keeping up with the changing world of work? With SHRM's Employee Handbook Builder get peace of mind that your handbook is up-to-date.
Build competencies, establish credibility and advance your career—while earning PDCs—at SHRM Seminars in 12 cities across the U.S. this spring.
#SHRM18 will expand your perspective – on your organization, on your career, and on the way you approach HR. Join us in Chicago June 17-20, 2018
Experts say the keys are policy and education
Members may download one copy of our sample forms and templates for your personal use within your organization. Please note that all such forms and policies should be reviewed by your legal counsel for compliance with applicable law, and should be modified to suit your organization’s culture, industry, and practices. Neither members nor non-members may reproduce such samples in any other way (e.g., to republish in a book or use for a commercial purpose) without SHRM’s permission. To request permission for specific items, click on the “reuse permissions” button on the page where you find the item.
Even the CIA is vulnerable.
Recent reports of cyber attacks targeting the federal government and prominent organizations, including the CIA and the U.S. Senate’s website, the
International Monetary Fund (IMF),
Lockheed Martin and dozens of
others in 2011, have highlighted the need for corporations to make sure their enterprises are secure.
And now with Congress paying attention, so too should HR and IT departments, experts say.
“Sophisticated cyber attacks are increasingly becoming the greatest threat to the future of electronic commerce here in the United States and around the world, and that’s why Congress must take immediate steps to better protect the personal online information of American consumers,” Rep. Mary Bono Mack, R-Calif., said June 15, 2011, during a House subcommittee hearing where she unveiled legislation that would require companies to notify law enforcement within two days of discovering a data breach. Experts say there are dozens of laws requiring the reporting of data breaches nationwide, but Mack’s proposal would require companies to establish and maintain appropriate security policies to prevent data breaches and minimize the amount of data collected from individuals.
Secure and Fortify Electronic (SAFE) Data Act would require breached firms to notify the Federal Trade Commission as well. Companies that do not may face fines.
Her bill augments legislation passed by the House in 2009, but never acted upon in the Senate. “Maybe [the recent Senate attack] will give them a bit of an incentive over there,” Bono Mack said.
According to datalossdb.org, which tracks such breaches, in most cases hackers accessed customers’ names, contact information, e-mail addresses, passwords, credit card account numbers, vehicle identification numbers and other financial data. Some of it wasn’t even encrypted. Some of the breaches involved employee negligence or theft of company equipment. Most involved hacking.
A recent report by Ernst & Young reveals that although organizations have been dealing with opportunistic cyber attacks for years, many now find themselves the target of more sophisticated and persistent efforts. These attacks are focused on a single objective, often lasting over a long period of time until the desired target is obtained. They leave few signs of disturbance because they are designed to remain hidden to acquire as much sensitive information as possible, the report states.
In March 2011, U.S. weapons maker Lockheed Martin Corp. was hit by an unspecified cyber incident. On June 15, 2011, the CIA experienced a denial of service attack. In April 2009, spies breached the Pentagon’s $300 billion Joint Strike Fighter jet project, a costly weapons program. That same year, a security audit of the U.S. air traffic control system revealed it too was repeatedly hacked. The culprit: weak passwords and unprotected folders.
What HR Can Do?
“First thing you have to know is that it is going to happen. Expect it,” said Damon Petraglia, director of forensic and information security services for Chartstone LLC and a consultant for the electronic task force for the U.S. Secret Service.
Borderless Security: Ernst & Young’s 2010 Global Information Security Survey, the professional services organization found many companies are expecting attacks:
Security experts interviewed by the Society for Human Resource Management said it is imperative that corporations train employees about good online habits, institute online usage policies and, if possible, eliminate nonbusiness online activity. They also suggest that IT departments add a second layer of data security beyond firewalls, step up their authentication methods, and make data inside their network valueless to hackers.
HR should have IT departments assess their applications for security vulnerabilities and educate employees about good online habits as well.
“Vulnerabilities crop up in design, configuration and implementation,” Daniel Uriah Clemens of
Packetninjas LLC, an information security consultancy based in Alabama, told
SHRM Online. “Businesses need to know that while living in the digital world their business viability is based on the technology decisions they make.” Good companies “practice practical security disciplines, both offensively and defensively.”
Katie Johnson, head of marketing and client services for Awareity, a web-based security solutions firm, added, “The majority of data breaches are caused by or related to human error—failure to set up a system properly, unauthorized access, mistakes and errors, password security, social engineering [the art of tricking people into giving away confidential info], etc. It is important for organizations to ask, ‘Are all employees aware of changing and more sophisticated risks? Have we updated employees with situational awareness as more and more attacks target employees?’ All employees must understand their individual roles and responsibilities for protecting sensitive information,” she said.
“Good IT departments understand that strong information security programs do not stop upon completion of their risk management plans, disaster recovery plans, or security policies and procedures,” Johnson said. “It is critical to ensure constant updates and plan reviews.”
According to a March 2011 study released by the
Ponemon Institute, the average cost of a data breach in 2011 is $7.2 million—per data breach event. A data breach response plan is imperative, added Denis Kelly, chairman of the three-year-old
Identity Ambassador Commission, which certifies identity theft professionals. Kelly, author of
The Official Identity Theft Prevention Handbook (Sterling & Ross Publishers, 2011), has been working with congressional leaders on the SAFE Data Act.
“If the response plan is not developed prior to a breach, then all costs associated with the breach rise dramatically,” Kelly told
SHRM Online. He added that there are two primary considerations for breach management: internal and external.
“Internal is systems, structures or processes that led to the breach. External are the victims and the public perception. These components must be addressed in tandem and with a high level of coordination,” Kelly explained, adding that “once a breach is discovered, there should be a reasonable time—96 hours—from discovery to notifying victims.” He said that gives the company enough time to identify and assess the situation.
“Ensuring you have constantly reviewed and revised electronic-use policies, covering all aspects of employees’ potential use of corporate technology is key,” added Andrew Marshall, CIO of Technologies for Campus Apartments, the oldest student housing provider in the U.S.
“These policies have to be backed up with enforcement and education to ensure employees understand what is required and work within the guidelines,” he said, adding that “most security risk, knowing or unknowing, starts with an employee—whether it’s writing a password on a Post-it note [for anyone to see], using a password that they use on other noncontrolled sites, allowing someone else to use their ID, or unwittingly introducing a virus or malware. Not much of this can be electronically mandated, so the first line of defense is policy and education,” he said.
Aliah D. Wright is an online editor/manager for SHRM.
Related Articles, Video
You have successfully saved this page as a bookmark.
Please confirm that you want to proceed with deleting bookmark.
You have successfully removed bookmark.
Please log in as a SHRM member before saving bookmarks.
Please sign in as a SHRM member before saving bookmarks.
Please purchase a SHRM membership before saving bookmarks.
An error has occurred
Recommended for you
Join SHRM's exclusive peer-to-peer social network
SHRM’s HR Vendor Directory contains over 10,000 companies