Article

Storing Data in the Shadows and the Cloud

Jan 01, 0001

In the rush to embrace developing technologies, organizations and their employees often unwittingly increase the risks of data loss. The convergence of cloud computing and powerful employee mobile devices means the goals of securing sensitive data and maintaining regulatory compliance are becoming more difficult.

 What CFEs Should Know About Emerging Threats to Data Security  

 

July 2013  

By Zach Capers, CFE 

 

In the rush to embrace developing technologies, organizations and their employees often unwittingly increase the risks of data loss. The convergence of cloud computing and powerful employee mobile devices means the goals of securing sensitive data and maintaining regulatory compliance are becoming more difficult. Many employees today incorporate personal devices into their daily work routine, often storing precious company documents on the same smart phones that access various social media apps, and are routinely left in movie theaters, taxis and restaurants.

 

All too often, fraud examiners’ efforts to prevent the theft of intellectual property and customer records are undermined by constantly evolving technological trends and a lack of awareness of the relative risks. While many data breaches are the result of malware or aggressive hacking techniques, a significant portion of exposed data is the result not of theft, but of negligence. Headlines commonly allude to incidents of important files being lost due to a stolen laptop or a dropped USB stick. Today, data can be stored in countless mediums, including but not limited to:

 

USB flash drives

Memory cards

Internal/fixed hard drives

External/portable hard drives

Network attached storage

Magnetic tape

Copy/fax machine memory

Mobile devices (phones, tablets, audio players, video game systems)

CD/DVD/Blu-ray discs

Cloud storage

 

Bring Your Own Device 

Adding to the challenges incurred by disparate data storage methods is the phenomenon known as bring your own device (BYOD), which has swept across the business world after the mass migration to smart phones and tablets in recent years. Far removed from the heyday of the company-provided cell phone or laptop, today’s employees increasingly utilize their own mobile devices, paid for out of their own pockets. This situation is advantageous to the company from a cost perspective, and pleasing to employees who would rather not be forced to use an employer-issued device. Additionally, personally owned devices tend to be better cared for and used more effectively. Determining who pays for mobile services, discerning the line between personal and business information, and ensuring the security of mobile data are among the many challenges posed by BYOD.

 

A Primer on the Cloud 

One of the most inescapable recent buzzwords in business and technology is the cloud. The cloud is a metaphor for the storage and utilization of data online, rather than on local storage. Public cloud-providers typically offer several storage and hosting options that can be purchased in any amount, for any length of time. Software as a Service (SaaS) is a method of delivering business applications via the cloud, rather than installing them directly on a user’s device. SaaS allows the smooth remote deployment of software, updates and maintenance. The primary benefits of using the cloud are a cost-effective alternative to building-out IT infrastructure, and the convenience of on-demand data availability from anywhere the Internet can be accessed. Moreover, utilization of the cloud allows a scalability and manageability of data resources previously unavailable.

 

The cloud’s rapidly growing use has been due in part to its reciprocal relationship with the ever expanding portable device market. While the use of this technology has been driven by early-adopters and power-users, now even the most technologically impaired seem to have some sort of smart phone, e-reader or tablet with capabilities not conceived of only a short time ago. With the cloud and powerful mobile devices, business travel is suddenly more convenient, working from home is a breeze and sharing data is virtually effortless.

 

Rapid Adoption of Cloud Computing 

The cloud storage industry is a juggernaut, with estimates that it will become a $100 billion market by 2016. The utility offered by cloud computing, and the resulting demand, has culminated in the near commoditization of mass data-storage. In recent months, large cloud service providers such as Amazon, Apple, Microsoft, and Google have been engaged in a price war with the resulting competitive rates making cloud storage more attractive than ever. While many consumers are simply looking for the lowest price assuming that all providers are offering essentially identical services, businesses and government agencies often have specific needs, security concerns, and regulatory issues to contend with. A recent survey of small to medium-sized businesses shows that, among those companies not currently using cloud storage, the primary concerns are data security, lack of control, reliability, and compliance.

 

While the cloud is commonly referred to as one all-encompassing homogeneous entity, it actually consists of an immense number of separate services provided by third-parties, all with differing and often unknown security practices. This is particularly relevant to the use of these services by government agencies and industries with a need to adhere to regulations such as FISMA or HIPPA. Several organizations, including the Unified Compliance Framework and the not-for-profit Cloud Security Alliance, have sought to streamline regulatory compliance and develop industry standards related to such trends as cloud storage and BYOD. These concerns are now resulting in the development of private and hybrid cloud systems that require less reliance on third-party cloud vendors.

 

The Emergence of Shadow IT 

As the speed of technological innovation increases, so too does the demand placed on the IT department of many organizations. With most IT personnel already stretched thin, and financial pressures often preventing the expedient migration to the technology required to stay competitive, employees are seeking ways to alleviate the pressure. One solution to meet growing technological needs is the development of shadow IT. An end-run around traditional IT and its accompanying security policies, shadow IT can consist of anything from the unauthorized use of free cloud services, such as Dropbox, to the unapproved development of entire enterprise applications.

 

Shadow IT can be a means for business units within large organizations to more freely develop new projects and engage in more efficient mobile and cloud computing. Employees often feel that they can utilize shadow IT systems to get their jobs done more effectively than if they were to go through the traditional bureaucracy of IT requests and oversight. The downside, however, is that sensitive data is often duplicated, loaded onto unsecured mobile devices, or shared through various unencrypted cloud services. That this is being done beyond the purview of IT makes maintaining the integrity of an organization’s data a herculean task.

 

Minimize Risk 

The following are 10 steps that can minimize your organization’s risk of compromised data:

 

Provide regular training sessions to increase data risk awareness and ensure that every employee feels a tangible responsibility for keeping data secure.

Categorize all data to determine who should have access to what information and on which storage mediums it is allowed to be stored.

Develop written policies regarding the use of cloud services.

Conduct thorough risk assessments prior to cloud migration.

Implement encryption on sensitive data stored in the cloud.

Establish formal programs to regulate BYOD.

Employ mobile application management (MAM) software to secure mobile devices remotely.

Restrict admin privileges where possible.

Consider software to monitor the data transmission of all ports.

Disable auto-run on company machines to prevent infections from BYOD thumb drives and assorted mobile devices.

 

The innovation and collaboration engendered by cloud computing and BYOD is revolutionizing the way business is conducted. Despite challenges, organizations will continue to adapt to these technologies, and fraud examiners must remain vigilant in helping to protect against vulnerabilities related to their use. Wider awareness of data security risks and the development of comprehensive industry standards will ensure that enhanced productivity can be achieved with the confidence that compliance is maintained and sensitive data is protected.

 

For more information on emerging issues and updated information related to cloud security, visit the Cloud Security Alliance.