Coca-Cola Data Breach Highlights Importance of Laptop Security
Jan 01, 0001
Jan 01, 0001
By Mark Scott, J.D., CFE December 2014 A recent data breach involving Coca-Cola Enterprises Inc. highlights a threat faced by almost every organization: lost or stolen laptops can result in devastating data breaches. A data breach is an incident that involves the loss, theft or unauthorized access of sensitive information.
By Mark Scott, J.D., CFE
December 2014
A recent data breach involving Coca-Cola Enterprises Inc. highlights a threat faced by almost every organization: lost or stolen laptops can result in devastating data breaches. A data breach is an incident that involves the loss, theft or unauthorized access of sensitive information.
The Coca-Cola Breach
On January 24, 2014, Coca-Cola Enterprises Inc. announced that the personal information of about 74,000 employees, contractors and suppliers might have been compromised when several laptops containing unencrypted personal data were stolen from its Atlanta headquarters.
Although the laptops were later retrieved, a former employee filed a class action suit against Coca-Cola in November 2014 over the laptops breach, alleging, among other things, the beverage giant did not adequately secure the personal data and failed to notify the affected individuals quickly enough.
The breach will likely harm Coca Cola’s reputation and place its information security practices in the public spotlight.
The High Risk of Data Breaches
Organizations today collect, create, develop and store more sensitive and confidential information electronically than ever before, and, with the growth of workplace mobility and the surge of access to massive data storage capacity and processing capabilities, the risk of experiencing a data breach for today’s organizations is greater than ever before. According to a 2014 report by Experian Data Breach Resolution and the Ponemon Institute, 43 percent of U.S. companies experienced a data breach in the past year, up 10 percent from the prior year.
The High Cost of Data Breaches
Moreover, the cost of data breaches is on the rise. In its ninth annual Cost of Data Breach Study: Global Analysis, the Ponemon Institute found that the average cost that organizations incurred for each compromised record containing sensitive and confidential information increased from $136 in 2013 to $145 in 2014.
Data breaches incur not only high financial losses, but also lasting negative effects on an organization’s brand, reputation, productivity and competitive edge.
Data Breaches from Laptop Theft or Loss
Physical theft and loss of laptops are among the leading causes of data breaches, according to the 2014 Verizon Data Breach Investigation Report.
Thieves target laptops because they are small, portable items with high resale value, and they can contain treasure troves of lucrative information. Laptops are convenient, but the features that make them convenient (e.g., portability, data storage, processing power) make them susceptible to loss or theft. And when a laptop used for work-related purposes is lost or stolen, proprietary and sensitive information might be lost as well.
The High Cost of Lost and Stolen Laptops
The cost of lost and stolen work laptops is high and goes far beyond the price of device replacement. According to The Cost of a Lost Laptop, a 2009 study by Ponemon Institute, the average cost per stolen or lost laptop for an organization is $49,246. This cost is due primarily to losses associated with data breaches and the leakage of intellectual property.
Common Locations for Laptop Theft
Laptops are stolen from many different locations, but according to the 2012 Endpoint Security Report, the top places from which laptops are stolen in the U.S. are:
Measures to Enhance Laptop Security
Organizations have much to lose if a workplace laptop is lost or stolen, and management with employees who store sensitive work data on laptops must take extra measures to safeguard that data from unnecessary breaches due to theft or loss.
Below is a brief discussion of several measures to enhance laptop security.
Use Physical Security Controls
Management should encourage the use of physical security controls to protect laptops from theft, loss, vandalism, deliberate or accidental damage, and other physical threats. Examples of physical controls for laptops include laptop locks and alarms. Employers might also encourage physical security by imposing rules that:
Require employees to lock laptops when not in use.
Prohibit employees from leaving media containing sensitive files unattended or unsecured.
Require employees to place their laptops in a secure state when left unattended.
Password Protect Laptops
Management should require that all laptops be protected by strong passwords, requiring users to input a password when a system is started, unlocked or woken from the sleep state. This type of protection, however, is limited. It does not secure unencrypted data stored on operating system drives; it only prevents individuals from logging into systems’ user accounts. In fact, such passwords can be reset or bypassed on every operating system.
Encrypt Laptop Data
Management should require the use of data encryption to protect sensitive data being stored on laptops. Encryption is the process whereby electronic information is transformed using an algorithm (called a cipher) to make it unreadable to anyone without the encryption key, and it is one of the most effective methods of protecting sensitive information on portable devices.
Encryption solutions generally encompass two types: full-disk encryption, and folder and file encryption.
Full disk encryption technology encrypts all the information stored on a system’s hard drive automatically. By using full disk encryption, users can ensure that sensitive information is not exposed if a work laptop is lost or stolen.
There are numerous third-party tools that offer full device encryption technologies, and some operating systems come with this technology built in. For example, Microsoft's full-disk encryption tool, Bitlocker, is available natively for machines running the Ultimate and Enterprise editions of Windows 7 and Vista and the Pro and Enterprise editions of Windows 8 and Windows 8.1. Likewise, Apple offers FileVault and FileVault 2, full disk encryption technologies that come installed with systems running Mac OS X 10.3 or higher.
Full disk encryption, however, differs from folder and file encryption. Folder and file encryption is the process of encrypting individual files and folders on a storage medium. Folder and file encryption, unlike full disk encryption, does not encrypt all the information on a hard drive, but allows users to decide which data needs encrypting.
Back Up Laptop Data
To reduce the risk of data loss, management must ensure that laptop data is backed up on a regular basis and that backups are stored in secure areas. To accomplish this, management should establish a backup policy that dictates the data that should be backed up and the storage requirements for backups.
Install Tracking Software
Management should consider installing tracking software on work laptops. Tracking software allows users to identify the location of missing devices, and it can be a valuable investment, especially for organizations with mobile employees.
Additionally, some tracking software allows users to remotely lock and erase data from laptops; this functionality is valuable for users with devices containing sensitive information.
Tracking software, however, is not perfect. All tracking software requires power, and most tracking software requires an Internet connection to work. Therefore, if a missing laptop with tracking software is powered down or not connected to Wi-Fi, it will not be able to provide any tracking information.
Engage in Proper Disposal
Organizations must engage in proper disposal procedures for electronic storage devices no longer used to process or store sensitive information.
Provide Awareness Training
Educating employees is a key part of data security because a large amount of data breaches are the result of human error. According to the 2014 Cost of Data Breach Study, human error was the root cause of 30 percent of data breaches in 2013.
Management should provide periodic awareness training to educate employees about their information security obligations. Such training should motivate employees to fulfill their information security obligations, and it should give them a basic level of understanding about a broad range of information security matters, such as:
General obligations under the organization’s information security policies and practices
The importance of data security
The risks of data breaches
What information is sensitive and needs protection
Employees’ roles in, and responsibilities for, furthering data security
Appropriate measures for handling and protecting sensitive data
Advice on strong password construction
Guidance on data encryption
Procedures for reporting suspected breaches
The risks of lost and stolen laptops (and other portable devices)
Information-security requirements for preventing data breaches from lost or stolen laptops (and other portable devices)
Information-security requirements for safeguarding laptops might include the following demands for employees:
Use laptop security locks whenever possible.
Back up laptop data on regular basis.
Do not leave laptops unattended in public places.
Do not leave laptops in vehicles.
Do not leave laptops in public areas (conference rooms, coffee shops, libraries, etc.).
Keep attention on laptops when going through airport security.
Do not leave laptops in hotel rooms without proper security.
Conclusion
Access to information is essential for today's mobile workforce, but as the Coca-Cola laptop breach illustrates, allowing employees to use laptops for work-related purposes increases organizations’ vulnerability to data breaches from theft and loss. Accordingly, management in organizations today must take necessary measures to ensure that sensitive work data does not fall into the wrong hands.