Information Technology in Crisis - Three Priorities For IT in 2010 - Part 2

As we launch into 2010, the IT industry is faced withthey don't have the technical knowledge of where
three major challenges. What makes these soyour information is stored, or how to purge it. Most
significant is they are not on the radar of mosttechnicians believe the copier is purged when the
companies. In this report I will address the secondimages are no longer visible to the display. Don't fall
challenge we, as an industry, have ignored. Although Ifor their ignorance on this matter. Also, don't think
can't provide answers, my hope for these articles isyou can push the responsibility onto the leasing
to expose the issues and launch a dialogue within thecompany as I guarantee your lease agreement
IT community as we search for answers.doesn't require them to provide this service.
Your Digital Copy Machine can't keep secretsThis is one of corporate America's biggest risks, yet I
You'll never guess who's walking out your front doorhaven't found any company with security policies
with confidential data. Yes, it's the guy who leasesaddressing digital copiers. Most end of lease copiers
you your copy machine. When digital copy machinesare sold overseas where recipients of these copiers
are replaced or come off lease they are wheeled out(and your data) are not subject to US laws.
your front door with a disk-full of images that wereDo you know who has your old digital copy machine
printed, scanned, copied or faxed.and all your data that was on its hard drive?
Digital copiers can't erase their hard drive so at theHow many digital copy machines do you have that
end of their lease, gigabytes of images inside theare ready to go off lease? How will you ensure your
copier are wheeled out your front door. Newer copydata doesn't go off site with the copy machine? How
machines can make the data unreadable to thewill you ensure your competitors or hackers won't
copier itself but your data is still on the disk! If youget their hands on your data through your old copier?
happen to have a network connected digital copier,Are you at risk of lawsuits from employees or
additional information is retained on the copier such asvendors that use your copy machines? This is a
IP addresses, DNS server IP addresses, emailsecurity issue we cannot ignore, and it's an issue
addresses, etc.without an easy solution. The options available are
A company called Digital Copier Security Inc (DCSI) islimited and can be expensive for companies with
a pioneer in raising awareness to this security holemultiple copiers. DCSI provides a certified disk
which exists at most companies. DCSI claims theyscrubbing service. Another option is to purchase a
have obtained "off lease" copy machines where they"Security Kit" which is expensive and not user
scanned the hard drives with proprietary utilities andfriendly. The device is so troublesome that most
have recovered thousands of pages of documentscompanies disable them over the course of time.
fully intact. Here are some examples of what they'veIf your company is regulated by SOX, GLB, HIPAA,
recovered.FERPA or FTC Red Flags, a breach can be construed
- A complete home refinance application includingonce your digital copier leaves your possession and
applicant's full name, SSN, current employer, previouscontrol. Considering the costs of fines, penalties,
employers, bank account numbers, etc.sanctions, public notification, credit monitoring, and
- A Spreadsheet showing employee names anddamage to a corporate image. Careful purging of
company issued credit card numbers.these machines should be a top priority for every
- Full Tax Returnscompany.
- Confidential Medical recordsAs you can see from this series, IT has three
- Confidential Executive Business Reportspressing challenges; Old paradigms that cripple
- Over 20,000 documents were recovered from justbusinesses, digital copier security and our "part 3"
one hard drivetopic in the final article of this series. These challenges
You would never let a vendor walk out of your dataare easily ignored and have been to this day.
center with an un-scrubbed hard drive but yet it isHowever, ignoring these challenges only puts your
done every day with digital copiers.business at continued risk of pending crisis. In 2010
Don't even think about removing the hard drivewe must take steps to limit our exposure with
before releasing the copy machine, doing so wouldanswers to these challenges. As I mentioned earlier,
make the copier unusable and void your leasemy intent is to open the door to further dialogue. Let
agreement. You would become liable for theus consider the door now wide open. I encourage
complete cost of the copy machine. Don't expect theyou to propose your ideas and join me in a discussion
copy machine technician to purge the device either;on this topic.