Most Read
- The Almost-Meteoric Rise of SaaS on Wall Street
- Financial Firms Try to Protect Themselves Against the Insider Job
- Wall Street Plays Musical Chairs With C-Suite Executives
- Online Brokers Woo Active Traders With Service, Support and Tools
- Financial Firms Struggle To Keep up with AML Demands
- 5 Steps for Stopping the Insider Threat
- Hedge Funds Continue to Attract Investors But Face New Challenges
- Fidelity Introduces E-Signature for RIAs to Automate Account Opening
Investment Firm's Massive Data Breach Caused by File-Sharing
A huge data breach at an investment firm has thrown the spotlight on the dangers of allowing employees to use popular online file-sharing software such as LimeWire, after an incident saw an employee use the service to trade music or a movie, and unwittingly expose his organization's entire database to potential criminals.
An employee at Wagner Resource Group, a McLean, Va-based investment firm used LimeWire late last year from his company computer, and in doing so, inadvertently opened the private files of his firm to the public.
This exposed the names, dates of birth and Social Security numbers of about 2,000 of the firm's clients – including a number of high-powered lawyers and Supreme Court Justice Stephen G. Breyer, the Washington Post reported.
The breach was only discovered six months later -- when a reader of a washingtonpost.com blog found the information while actually searching LimeWire. The reader notified the Post's Security Fix blog, which then alerted some of the Wagner clients, the Post said.
Phil Neray, VP at database security company Guardium, says most companies have policies in place preventing their employees from using LimeWire, "as it's hard to imagine a legitimate business use for this or other Peer-to-Peer file-sharing applications."
"But even when companies allow them to reside on networks, they need to enforce policies around the use of these applications," Neray says.
In addition, companies need to have content monitoring controls in place to enforce these policies. "Most companies on Wall Street have policies, but they're only just now getting to use the technology to enforce these policies," he says.
Phylyp Wagner, founder of the Wagner Resource Group, called his firm's breach "devastating."
"I didn't even know what peer-to-peer was. I do now," he told the Washington Post.
The bottom line, Guardium's Neray says, is that while companies can't prevent peer-to-peer file sharing applications or other technologies from entering a work environment – they need to put controls in place, including real-time monitoring, to make sure these are used in an authorized manner.
Posted by Melanie Rodier at 04:36 PM
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
Greg MacSweeny Columns
Greg MacSweeneyWall Street Plays Musical Chairs With C-Suite Executives
Amidst mass layoffs, top-notch technology talent is even easier to find. Meanwhile, CIO-le...
Prime Brokers Select SWIFT For Trade-Date Matching Platform
Enigmatec Receives $14 Million in new Funding
As iPhone Applications for Capital Markets Emerge, Hedge Funds First to Adopt
Larry Tabb Columns
Larry TabbNow Is the Time for Firms to Position Themselves for the End of the Economic Downturn
Downturns happen -- the industry will survive. But firms need to adjust to changing market...
Clearing and Settlement Top-of-Mind for Front-Office Execs
Risk Management IT Comes to the Forefront in the Wake of Subprime Credit Crisis
In a Tumultuous Economy, Wall Street Must -- and Will -- Find a New Model
CHECK THIS OUTNovell Real Time Linux Webcast SeriesIn order to succeed, companies must be able to respond quickly, deliver superior value and quality of service, and carefully manage their costs. In this series of brief webcasts, you will learn how SUSE Linux Enterprise Real Time from Novell enables organizations to respond quicker by delivering low latencies, deliver increased value with fast response times, and better manage costs. |
EventsLive Events:Navigating the New World of Risk on the Street October 07, 2008 Buy-Side Trading Summit 2008 November 16-18, 2008 Accelerating Wall Street 2009 March 18, 2009 Web Events: CEP Beyond the Trading Desk September 17, 2008 |
|
Marketplace |
Career CenterReady to take that job and shove it?
|
Most Recent Job Posts:
* Assurant Health seeking Siebel Solution Delivery Lead in Milwaukee, WI
* Rho Trading Securities seeking Network and Systems Technician in Chicago, IL * JK Group, Inc. seeking Programmer / Analyst in Plainsboro, NJ * Sibley Memorial Hospital seeking Chief Information Officer in Washington, DC * ISES, Inc. seeking SAS Oracle Clinical Developer in Clinton, NJ For more tech jobs in the industry, visit Wall Street & Technology's Career Portal. |










