Avoiding data theft: The inside story
Does your company have an internal data security policy in place? Many businesses focus on protecting data from outsiders and external security threats while data theft from insiders is often overlooked. Computer networks provide employees with greater access to information, but also require safeguards to ensure that only authorised users can view documents and files. Here are some tips from IBM to help reduce the risk of internal data theft in your business...
|
Many companies focus their data security efforts around keeping outsiders from hacking into their networks, but a more genuine threat for many small businesses is data theft by insiders. A disgruntled employee or simply a mischievous co-worker may try to access or alter confidential information such as customer lists, trade secrets, or payroll or other financial data. This kind of fraud can damage your business as much as any other kind of theft. While computer networks provide your employees with greater access to information, they also require you to put in place safeguards that ensure that only those authorised to view documents and files can do so. The following steps can help reduce the risk of internal data theft, and should be part of your company's data security policy. Create a sound password policy Avoid words that can easily be guessed by co-workers - things like family member names, references to hobbies and interests, and other terms that people who work with you are likely to know. Also, never write passwords down where others can find them. Ideally, passwords should be a combination of letters, numbers, and upper and lower case characters. Finally, make sure that users change their passwords frequently, and avoid making new passwords similar to old ones. Limit information access Similarly, label certain commonly-accessed files (such as your customer database) as "read only" so they can't be altered or copied. Never leave a computer unattended This prevents someone from using the computer and network privileges without their knowledge. Remove old users immediately But even an employee who leaves on good terms might try to download customer lists, product information, or other data that gives your business its competitive edge. If users have a separate remote password, remember to cancel those to keep former employees from dialing in to your network from home to download important information. Further Information
|
March 2006
|

