<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Zecurion Company Blog</title>
	
	<link>http://www.zecurion.com/server-software-blog</link>
	<description>Data Storage Security, Data Loss Prevention</description>
	<lastBuildDate>Mon, 12 Jul 2010 21:40:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/zecurion/qwAh" /><feedburner:info uri="zecurion/qwah" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Zeus Compromises Student Data at University of Oklahoma</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/LapBaNANsLs/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/07/zeus-compromises-student-data-at-university-of-oklahoma/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 21:40:14 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[exposed]]></category>
		<category><![CDATA[OU]]></category>
		<category><![CDATA[Social Security numbers]]></category>
		<category><![CDATA[University of Oklahoma]]></category>
		<category><![CDATA[Zeus botnet]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=214</guid>
		<description><![CDATA[The University of Oklahoma has revealed that a laptop compromised by a variant of the Zeus botnet may have exposed or compromised sensitive information on OU students&#8211;including Social Security numbers. There are no further details yet available regarding the scope of the potential compromise. According to this blurb from KOCO.com, though, &#8220;OU officials said they [...]]]></description>
			<content:encoded><![CDATA[<p>The University of Oklahoma has revealed that a laptop compromised by a variant of the Zeus botnet may have exposed or compromised sensitive information on OU students&#8211;including Social Security numbers. There are no further details yet available regarding the scope of the potential compromise. According to this <a href="http://www.koco.com/mostpopular/24031441/detail.html" target="_blank">blurb from KOCO.com</a>, though, &#8220;OU officials said they are not aware of any instances of identity theft or similar problems as a result of the breach, but they said they can&#8217;t be certain that student information was not compromised.</p>
<p>One way that OU would be able to be certain that student information was not compromised is if the data stored on the laptop, or on servers the laptop has access to was encrypted. I am not sure why these incidents seem to occur almost exclusively at medical establishments and educational institutions, but simply <a href="http://www.zecurion.com/zserver.php" target="_blank">investing in the proper security controls</a> up front can save time, money, and embarrassment for the organization, as well as protecting the personal and sensitive information the organization has been entrusted with.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/LapBaNANsLs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/07/zeus-compromises-student-data-at-university-of-oklahoma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/07/zeus-compromises-student-data-at-university-of-oklahoma/</feedburner:origLink></item>
		<item>
		<title>Zserver Protects Data in the Cloud</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/F165dvHAIs4/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/zserver-protects-data-in-the-cloud/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 03:27:01 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Data Storage Security]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[ComputerWorld]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Flushing Bank]]></category>
		<category><![CDATA[Zecurion]]></category>
		<category><![CDATA[Zserver Storage]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=211</guid>
		<description><![CDATA[A ComputerWorld article title Cloud Security in the Real World: 4 Examples cites Zecurion&#8217;s Zserver as a cloud-based storage encryption solution. 
Examining the issue of data encryption in the cloud, the article states &#8220;Several providers of cloud-based backup storage install appliances at the customer site to accommodate encryption, but Flushing was not interested in that setup.&#8221;
It also explains &#8220;At [...]]]></description>
			<content:encoded><![CDATA[<p>A ComputerWorld article title <a href="http://news.idg.no/cw/art.cfm?id=3C6AFD79-1A64-67EA-E45767CFAC0C9C06" target="_blank">Cloud Security in the Real World: 4 Examples </a>cites Zecurion&#8217;s Zserver as a cloud-based storage encryption solution. </p>
<p>Examining the issue of data encryption in the cloud, the article states &#8220;Several providers of cloud-based backup storage install appliances at the customer site to accommodate encryption, but Flushing was not interested in that setup.&#8221;</p>
<p>It also explains &#8220;At Flushing Bank in New York, CIO Allen Brewer turned to the cloud for data backup after getting fed up with on-site tape backup. Using <a href="http://www.zecurion.com/zserver.php" target="_blank">Zserver</a> from Zecurion, Flushing is now sending files over the Internet to be stored for backup.&#8221;</p>
<p> Read the white paper <a href="http://www.zecurion.com/uploads/Protect%20Your%20Customer%20Data%20in%20the%20Cloud.pdf" target="_blank">Protecting Data in the Cloud</a> to learn more about encrypting and protecting data in the cloud with Zecurion&#8217;s Zserver.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/F165dvHAIs4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/zserver-protects-data-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/zserver-protects-data-in-the-cloud/</feedburner:origLink></item>
		<item>
		<title>Tufts University Alumni Data Exposed by Malware</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/i7JxJEAjh3I/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/tufts-university-alumni-data-exposed-by-malware/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 02:56:40 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Social Security numbers]]></category>
		<category><![CDATA[Tufts University]]></category>
		<category><![CDATA[Zserver Storage]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=209</guid>
		<description><![CDATA[What is it about networks and data at universities and medical establishments? It seems like almost every breach of sensitive or personal data is related to these two types of institutions. Are they targeted more often than other types of networks, or do they just have weaker security and poorer data protection mechanisms in place?
Following [...]]]></description>
			<content:encoded><![CDATA[<p>What is it about networks and data at universities and medical establishments? It seems like almost every breach of sensitive or personal data is related to these two types of institutions. Are they targeted more often than other types of networks, or do they just have weaker security and poorer data protection mechanisms in place?</p>
<p>Following on the heels of the recent <a href="http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/" target="_blank">botnet compromise</a> at Penn State University, <a href="http://www.boston.com/news/education/higher/articles/2010/06/09/letters_to_tufts_alumni_warn_of_security_breach/" target="_blank">Tufts University has discovered</a> that &#8220;several computers were recently exposed to an unknown virus or malicious software program.&#8221; As a result, roughly 7000 alumnus may have had their student ID numbers exposed&#8211;and like Penn State University the breached data is legacy data from a time when the university used the student&#8217;s Social Security number as their student ID number.</p>
<p>Universities, including both Penn State University and Tufts University, have abandoned that practice, but apparently have not found the time to go back through archive data and old databases to purge legacy information from the servers. While that is still a good idea, and a project that these universities should be pursuing, having <a href="http://www.zecurion.com/zserver.php" target="_blank">sufficient data protection controls</a> in place, such as encrypting the stored data, would ensure that it would not be exposed even in the event of a malware compromise or breach of the server itself.</p>
<p>A small investment in proactive security measures goes a long way and saves the organization from the lost reputation, time, and money involved in responding to a data breach incident.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/i7JxJEAjh3I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/tufts-university-alumni-data-exposed-by-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/tufts-university-alumni-data-exposed-by-malware/</feedburner:origLink></item>
		<item>
		<title>Penn State Server Compromised by Botnet</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/XL_goowSpmA/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/#comments</comments>
		<pubDate>Thu, 10 Jun 2010 03:28:32 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Penn State]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=206</guid>
		<description><![CDATA[Penn State University has sent out data breach notification letters to nearly 16,000 individuals to let them know that a computer in its Outreach Market Research and Data office was found to be actively communicating with a malicious botnet and that personal information including Social Security numbers may have been compromised.
Penn State has not used SSNs [...]]]></description>
			<content:encoded><![CDATA[<p>Penn State University has <a href="http://www.infosecurity-us.com/view/9976/penn-state-data-may-have-been-exposed/" target="_blank">sent out data breach notification letters</a> to nearly 16,000 individuals to let them know that a computer in its Outreach Market Research and Data office was found to be actively communicating with a malicious botnet and that personal information including Social Security numbers may have been compromised.</p>
<p>Penn State has not used SSNs as a student identifier for 5 years, however an archived copy of a legacy database apparently still existed on the compromised server.</p>
<p>A Penn State spokesperson explained that “We have, of course, standard defenses: site-licensed antivirus, unit firewalls, patching, vulnerability scanning, web application scanning, intrusion detection and blocking of confirmed hostile sites or frequently probed ports. When a machine is compromised, it must be re-installed from known ‘good’ media before it&#8217;s allowed back on the network, since it&#8217;s not possible to truly clean a machine that&#8217;s been fully compromised.&#8221;</p>
<p>All of those are excellent security controls and fit nicely with established security best practices. However, the data itself <a href="http://www.zecurion.com/zserver.php" target="_blank">should be encrypted</a> so that if and when an attacker figures out how to circumvent those defenses the data itself will still be impervious to unauthorized access.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/XL_goowSpmA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/</feedburner:origLink></item>
		<item>
		<title>An Unenforced Policy is the Same as No Policy at All</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/rRTUVssjZrk/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/an-unenforced-policy-is-the-same-as-no-policy-at-all/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 04:53:29 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[sensitive data]]></category>
		<category><![CDATA[USB memory stick]]></category>
		<category><![CDATA[Zlock]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=204</guid>
		<description><![CDATA[The West Berkshire Council has just learned this lesson the hard way. According to a recent report of lost data &#8220;West Berkshire introduced encrypted memory sticks in 2006. But following an investigation by the Information Commissioner&#8217;s Office (ICO), it was also discovered that council employees were still using unencrypted memory sticks.&#8221;
In a perfect world, simply [...]]]></description>
			<content:encoded><![CDATA[<p>The West Berkshire Council has just learned this lesson the hard way. According to a <a href="http://www.publicservice.co.uk/news_story.asp?id=13126" target="_blank">recent report of lost data</a> &#8220;West Berkshire introduced encrypted memory sticks in 2006. But following an investigation by the Information Commissioner&#8217;s Office (ICO), it was also discovered that council employees were still using unencrypted memory sticks.&#8221;</p>
<p>In a perfect world, simply stating that data should only be stored on approved USB devices, and that all data on portable storage media must be encrypted would be good enough. In the real world, though, simply stating it is not good enough. Stating a policy&#8211;without any means of monitoring or enforcing compliance with it&#8211;is simply paying lip service to data protection and gambling that a data breach incident will never occur.</p>
<p>West Berkshire Council lost that gamble when an unencrypted USB memory stick containing sensitive information relating to the ethnicity, and mental and physical health of children was lost. The report also contains this quote &#8220;It is essential that organisations ensure the correct safeguards are in place when storing and transferring personal information, especially when it concerns sensitive information relating to children.&#8221;</p>
<p>The best option to ensure correct safeguards are in place is <a href="http://www.zecurion.com/zlock.php" target="_blank">Zlock</a>. Zlock allows IT administrators to restrict users from writing to data to unapproved portable storage media. Access can be locked down to devices from a particular manufacturer, or of a particular type. A specific USB memory stick can be associated with each individual user, and all other memory sticks can be blocked.</p>
<p>In the case of West Berkshire Council, Zlock would have been instrumental in ensuring  that users relied on the encrypted USB memory sticks they were issued four years ago, rather than storing data on the now lost unencrypted USB memory stick.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/rRTUVssjZrk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/an-unenforced-policy-is-the-same-as-no-policy-at-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/an-unenforced-policy-is-the-same-as-no-policy-at-all/</feedburner:origLink></item>
		<item>
		<title>Sometimes You Wish You Could “Unsend” that Email</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/kQyX4Sjs_zQ/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/sometimes-you-wish-you-could-unsend-that-email/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 04:36:03 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[bank account]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[email]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=200</guid>
		<description><![CDATA[Have you ever hit &#8220;Send&#8221; on an email, and in that fraction of an instant had an epiphany that you accidentally hit &#8220;Reply to All&#8221; or addressed the email to the wrong party? Oops.
While some email programs have a feature that allows for a message to be recalled, that functionality usually relies on two things- [...]]]></description>
			<content:encoded><![CDATA[<p>Have you ever hit &#8220;Send&#8221; on an email, and in that fraction of an instant had an epiphany that you accidentally hit &#8220;Reply to All&#8221; or addressed the email to the wrong party? Oops.</p>
<p>While some email programs have a feature that allows for a message to be recalled, that functionality usually relies on two things- 1) the recipient must be on the same mail server&#8211;in other words someone in your same organization, and 2) the recipient must not have already received and opened the errant email message. Typically, what happens is that someone tries to recall a message and the errant recipient receives a notification that the sender would like to recall the email message, which just piques the recipient&#8217;s curiosity and draws attention to the fact that there is some reason the sender does not want you to see the message. Its not a very good system.</p>
<p>All of that is a long way of getting around to a recent data breach incident that <a href="http://www.irishexaminer.com/ireland/probe-after-bank-details-of-firms-sent-by-email-to-rivals-121183.html" target="_blank">occurred in Ireland</a>. An error occurred in merging account data into emails which resulted in the wrong account information being sent to various parties and compromising the data. Since the account data merging was an automated process, it seems fair to assume that the sender did not actually have an opportunity to review and approve each email prior to transmission. It seems that the Tralee Town Council was not aware of the problem until it was too late.</p>
<p>One way to ensure that sensitive or confidential data isn&#8217;t accidentally emailed out&#8211;and maybe prevent that &#8220;oops&#8221; feeling one gets when realizing sensitive information was emailed to the wrong party&#8211;is with <a href="http://www.zecurion.com/zgate.php" target="_blank">Zgate</a>. Zgate <span style="font-family: Calibri; font-size: small;"><span style="font-family: Calibri; font-size: small;">analyzes the contents of all fields in the email, including the body and file attachments, ensuring that sensitive information remains secure.</span></span></p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/kQyX4Sjs_zQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/sometimes-you-wish-you-could-unsend-that-email/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/sometimes-you-wish-you-could-unsend-that-email/</feedburner:origLink></item>
		<item>
		<title>How Many Stolen Laptops Does It Take?</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/o_-bMxjf8vk/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/05/how-many-stolen-laptops-does-it-take/#comments</comments>
		<pubDate>Thu, 27 May 2010 19:56:02 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[notebook]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=198</guid>
		<description><![CDATA[You may or may not realize this, but one of the primary advantages of notebook and netbook computers is their portability. Being able to computer from hotel lobbies, corner coffee shops, and the random McDonald&#8217;s certainly has its advantages, but I&#8217;ll let you in on a little secret&#8211;thieves like the small size, light weight, and [...]]]></description>
			<content:encoded><![CDATA[<p>You may or may not realize this, but one of the primary advantages of notebook and netbook computers is their portability. Being able to computer from hotel lobbies, corner coffee shops, and the random McDonald&#8217;s certainly has its advantages, but I&#8217;ll let you in on a little secret&#8211;thieves like the small size, light weight, and portability of laptops too.</p>
<p>Just in the past couple weeks there have been two incidents of laptops from medical centers being lost or stolen. One from the <a href="http://www.greenvilleonline.com/article/20100518/NEWS/305180014/1004/NEWS01/Loss-may-compromise-Oconee-Heart-Center-patients-data" target="_blank">Oconee Physician Practices</a> contained name, date of birth, gender, height and weight, blood pressure and some other medical data connected with the EKG from more than 600 patients. Another laptop from <a href="http://www.pe.com/localnews/stories/PE_News_Local_D_nb26_information.3353e01.html" target="_blank">Loma Linda University Medical Center</a> had patient&#8217;s name, medical record number, diagnosis, surgery date, and the type of procedure for more than 500 patients.</p>
<p>How many laptops have to be lost or stolen before IT administrators and executive management realize that data has to be proactively encrypted and protected? The investment in the right tools to do the job&#8211;like <a href="http://www.zecurion.com/zserver.php" target="_blank">Zecurion Zserver Suite</a>&#8211;is <a href="http://www.zecurion.com/server-software-blog/2010/05/6-5-million-is-a-lot-to-gamble/" target="_blank">significantly less than the cost</a>&#8211;financially and to the company&#8217;s reputation&#8211;from being responsible for compromising the sensitive and confidential data of customers or employees.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/o_-bMxjf8vk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/05/how-many-stolen-laptops-does-it-take/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/05/how-many-stolen-laptops-does-it-take/</feedburner:origLink></item>
		<item>
		<title>$6.5 Million is a Lot to Gamble</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/89k1DynFuAo/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/05/6-5-million-is-a-lot-to-gamble/#comments</comments>
		<pubDate>Wed, 12 May 2010 14:09:56 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Data Storage Security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[personal information]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=195</guid>
		<description><![CDATA[Section 13402(e)(4) of the HITECH Act, requires that the Secretary of Health and Human Services post a list of breaches of unsecured protected health information affecting 500 or more individuals.  
Since HHS began tracking and posting these breaches in late September of 2009, there have been 77 such incidents, impacting a total of 2.4 million individuals. That [...]]]></description>
			<content:encoded><![CDATA[<p>Section 13402(e)(4) of the HITECH Act, requires that the Secretary of Health and Human Services post a list of breaches of unsecured protected health information affecting 500 or more individuals.  </p>
<p>Since HHS began <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/postedbreaches.html" target="_blank">tracking and posting these breaches </a>in late September of 2009, there have been 77 such incidents, impacting a total of 2.4 million individuals. That is an average of more than 30,000 breached records containing personal information for each incident. A 2009 study by the Ponemon Institute found that the average cost of a data breach in the United States is $208 per compromised record, making the average cost of these 77 data breaches over $6.5 million.</p>
<p>Some of the data breaches were the result of physical data&#8211;forms and paperwork&#8211;being thrown into a dumpster. But, nearly 75 percent of the incidents involved unencrypted data stored on servers, backup tapes, or portable storage media.</p>
<p>Applying the averages&#8211;here is the bottom line: 56 out of 77 incidents could have been prevented if those organizations used <a href="http://www.zecurion.com/zserver.php" target="_blank">Zecurion Zserver Suite</a> to encrypt and protect data. That means that nearly 1.8 million of the 2.4 million affected individuals would not have had their personal data compromised, and that thesr organizations could have avoided a combined $364 million in costs to clean up after the breach.</p>
<p>The investment in proactively protecting data is significantly less than the cost of reacting to a data breach incident, and it doesn&#8217;t have the long-term negative impact to the organization&#8217;s credibility and reputation.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/89k1DynFuAo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/05/6-5-million-is-a-lot-to-gamble/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/05/6-5-million-is-a-lot-to-gamble/</feedburner:origLink></item>
		<item>
		<title>Cyber Advisors Joins Zecurion Advantage Partner Program</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/WuFABxlCWAQ/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/05/cyber-advisors-joins-zecurion-advantage-partner-program/#comments</comments>
		<pubDate>Tue, 11 May 2010 16:11:30 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Cyber Advisors]]></category>
		<category><![CDATA[partner]]></category>
		<category><![CDATA[Secure360]]></category>
		<category><![CDATA[ZAPP]]></category>
		<category><![CDATA[Zecurion]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=193</guid>
		<description><![CDATA[Cyber Advisors is the latest addition to ZAPP&#8211;the Zecurion Advantage Partner Program.
Since 1997, Minnesota-based Cyber Advisors (CA) has been providing information technology, e-business services, and solutions that work and grow with their clients. Consistently ranked one of the fastest growing companies by CRN and Inc., CA takes a true 360-degree view of technology and business, [...]]]></description>
			<content:encoded><![CDATA[<p>Cyber Advisors is the <a href="http://www.zecurion.com/press-release/15/CYBER-ADVISORS-AND-ZECURION-PARTNER-TO-DELIVER-WORLD-CLASS-INTERNAL-SECURITY-PROTECTION-TO-THE-MID-SIZED-MARKET" target="_blank">latest addition to ZAPP</a>&#8211;the Zecurion Advantage Partner Program.</p>
<p><span style="FONT-SIZE: 11pt">Since 1997, Minnesota-based Cyber Advisors (CA) has been providing information technology, e-business services, and solutions that work and grow with their clients. Consistently ranked one of the fastest growing companies by CRN and Inc., CA takes a true 360-degree view of technology and business, applying their knowledge and expertise to build, support, and use technology that enriches their clients and enhances performance. Key practice areas include security, storage, virtualization, DR/backup, Microsoft consulting, and outsourced managed services.</span></p>
<p><span style="FONT-SIZE: 11pt"></p>
<p style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 11pt">“Auditing and compliance used to be issues specific to the financial and healthcare sectors, but lately they have been spilling over into other industries,” says Cyber Advisors president and CEO Shane Vinup. “There are many security products on the market, but they don’t give companies the control they need. Zecurion is the only single-bullet security solution that fits in terms of price, and allows users to work when and where they want while maintaining corporate control over the data.”</span></p>
<p style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt"> </p>
<p style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 11pt">“We’ve been aggressive in terms of creating a security solution that blocks, controls, and encrypts sensitive information, and we’ve been equally aggressive at creating a partner program that will attract high caliber partners like Cyber Advisors,” says Zecurion CEO Alexey Raevsky. “We’re pleased that Cyber Advisors selected Zecurion to be their security partner.”</span></p>
<p style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 11pt"> </span></p>
<p style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 11pt">You can learn more about Zecurion and Cyber Advisors at the <a href="http://www.secure360.org/" target="_blank">Secure360 conference today and tomorrow</a> in St. Paul, MN.</span></p>
<p></span></p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/WuFABxlCWAQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/05/cyber-advisors-joins-zecurion-advantage-partner-program/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/05/cyber-advisors-joins-zecurion-advantage-partner-program/</feedburner:origLink></item>
		<item>
		<title>Zlock Rewrites the Rules</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/HSlB-Ccx30A/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/05/zlock-rewrites-the-rules/#comments</comments>
		<pubDate>Tue, 11 May 2010 03:08:49 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Data Storage Security]]></category>
		<category><![CDATA[ChannelWeb]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[Zlock]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=190</guid>
		<description><![CDATA[ChannelWeb&#8217;s Edward Moltzen took a detailed look at Zecurion&#8217;s Zlock and praised the product in his article titled Zecurion&#8217;s Zlock Rewrites the Rules.
Moltzen begins by explaining the issue faced by organizations &#8220;Even well-meaning and well-trained employees can put data at risk on a network, and even heightened network firewalls can&#8217;t keep all data from walking [...]]]></description>
			<content:encoded><![CDATA[<p>ChannelWeb&#8217;s Edward Moltzen took a detailed look at Zecurion&#8217;s Zlock and praised the product in his article titled <a href="http://www.crn.com/security/224701408" target="_blank">Zecurion&#8217;s Zlock Rewrites the Rules</a>.</p>
<p>Moltzen begins by explaining the issue faced by organizations &#8220;Even well-meaning and well-trained employees can put data at risk on a network, and even heightened network firewalls can&#8217;t keep all data from walking out the door. Having data on a network means it could become available for <a href="http://www.crn.com/encyclopedia/defineterm.jhtml?term=download&amp;x=&amp;y=">download</a> onto DVDs, <a href="http://www.crn.com/encyclopedia/defineterm.jhtml?term=floppy&amp;x=&amp;y=">floppy</a> drives or thumb drives. Sensitive data could even be errantly left on a printer&#8217;s <a href="http://www.crn.com/encyclopedia/defineterm.jhtml?term=hard drive&amp;x=&amp;y=">hard drive</a> or cache&#8211;allowing anyone with the know-how to steal it.&#8221;</p>
<p>The conclusion Moltzen arrives at after seeing Zlock in action: &#8220;That&#8217;s why we think the approach taken by emerging security vendor Zecurion makes so much sense. Zecurion&#8217;s Zlock application provides a straightforward approach to securing and managing a network&#8217;s potential open doors and breaches, and it&#8217;s an approach that it makes too much sense to ignore.&#8221;</p>
<p>Moltzen adds &#8220;We think Zecurion could be on the way to becoming one of the stronger players in the data security space, and the company is a strong alternative for VARs to consider when looking at solutions for small or midsize businesses or workgroups.&#8221;</p>
<p>Read the complete article for more from ChannelWeb. To learn more about Zlock, <a href="http://www.zecurion.com/zlock.php" target="_blank">click here</a>.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/HSlB-Ccx30A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/05/zlock-rewrites-the-rules/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/05/zlock-rewrites-the-rules/</feedburner:origLink></item>
	</channel>
</rss>
