<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>In Defense of Data</title>
	<atom:link href="http://www.indefenseofdata.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.indefenseofdata.com</link>
	<description>Exposing Data Security Leaks and Breaches</description>
	<lastBuildDate>Fri, 23 Apr 2010 21:45:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Welcome to the GuardianEdge blog</title>
		<link>http://www.indefenseofdata.com/2010/04/welcome-to-the-guardianedge-blog-2/</link>
		<comments>http://www.indefenseofdata.com/2010/04/welcome-to-the-guardianedge-blog-2/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 23:44:10 +0000</pubDate>
		<dc:creator>Robert Hamilton</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.indefenseofdata.com/?p=93</guid>
		<description><![CDATA[Thank you for stopping by our blog.  We hope that you’ll consider this an ongoing resource for endpoint data protection industry news and trends.  We also want to provide you with a first-hand look at our activities at GuardianEdge.  So far 2010 has been an exciting year for the company with a strong first quarter [...]]]></description>
			<content:encoded><![CDATA[<p>Thank you for stopping by our blog.  We hope that you’ll consider this an ongoing resource for endpoint data protection industry news and trends.  We also want to provide you with a first-hand look at our activities at <a href="http://www.guardianedge.com" target="_blank">GuardianEdge</a>.  So far 2010 has been an exciting year for the company with a strong first quarter and a recent move of our corporate headquarters to Silicon Valley.</p>
<p>The IT security industry is constantly changing, and we want our blog to evolve with it.  A variety of GuardianEdge voices will be sharing their expertise here, keeping you up to date with industry changes. My posts will include thoughts about the current state and future of enterprise security.  Ram Krishnan, senior vice president of products and marketing, will provide his take on market trends, enterprise security, and customer and product news.  Joe Gow, senior director of product management, will discuss trends in data protection technology, and Balaji Venkateswaran, vice president of engineering, will bring technical information and details on the nitty-gritty of IT security to the blog.  In addition, you may also hear from other GuardianEdge <a href="http://www.guardianedge.com/company/executive-management-team.php" target="_blank">thought leaders</a>.</p>
<p>We hope you will appreciate the fact that we will take a stand on controversial issues from time to time.  Part of our desire is to engage the broader data security industry in a dialogue, so please feel free to join the conversation.  We look forward to hearing from you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.indefenseofdata.com/2010/04/welcome-to-the-guardianedge-blog-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Seattle Children’s Hospital: The Road to HITECH Act Compliance</title>
		<link>http://www.indefenseofdata.com/2010/04/seattle-children%e2%80%99s-hospital-the-road-to-hitech-act-compliance/</link>
		<comments>http://www.indefenseofdata.com/2010/04/seattle-children%e2%80%99s-hospital-the-road-to-hitech-act-compliance/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 17:36:17 +0000</pubDate>
		<dc:creator>Sandler Rubin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.indefenseofdata.com/?p=85</guid>
		<description><![CDATA[On April 13 I co-presented an eSeminar with Wes Wright, the vice president and CTO of Seattle Children’s Hospital.  We talked about the questions and challenges that IT departments at healthcare organizations face as they move towards complying with the HITECH Act.
We agreed that Electronic Personal Health Information (ePHI) is a necessary byproduct of this [...]]]></description>
			<content:encoded><![CDATA[<p>On April 13 I co-presented an <a href="http://www.guardianedge.com/eseminar/20100413/recording.php">eSeminar</a> with Wes Wright, the vice president and CTO of <a href="http://www.seattlechildrens.org/">Seattle Children’s Hospital</a>.  We talked about the questions and challenges that IT departments at healthcare organizations face as they move towards complying with the <a href="http://www.hipaasurvivalguide.com/hipaa-survival-guide-21.php">HITECH Act</a>.</p>
<p>We agreed that Electronic Personal Health Information (ePHI) is a necessary byproduct of this digital age.  Healthcare data needs to be mobile.  But, with the transition to more digital records, each being touched by the complete spectrum of healthcare organizations (providers, insurers, etc.), how does this impact the complexity of security?</p>
<p>When you look at the healthcare industry from a 30,000 foot view, some staggering statistics emerge.  According to the <a href="http://www.himss.org/ASP/index.asp">Health Information and Management Systems Society</a> (HIMSS), the association that guides healthcare IT, 69 percent of healthcare data breaches are a result of a lost or stolen endpoint.  This usually comes in the form of laptops, but does include other devices like Smartphones and USB thumb drives.</p>
<p>A terrifying 34 percent of healthcare organizations have had a known data breach, and fewer than 50 percent currently encrypt data where it is stored.</p>
<p>Most surprising to me? Only 39 percent encrypt their mobile devices.</p>
<p>Because ePHI is highly mobile, often stored in multiple locations, and overwhelmingly shared with third parties, it is important that IT administrators consider the complete lifecycle of each record.</p>
<p>When it comes to HITECH compliance, it is absolutely necessary that healthcare organizations demonstrate beyond a reasonable doubt that systems are in place to secure ePHI, and that they can audit and report against those systems.  If a device is ever in question, the organization falls victim to stringent disclosure and audit requirements.</p>
<p>So the question is: How mobile is your healthcare organization’s data and how ready are you for the HITECH Act?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.indefenseofdata.com/2010/04/seattle-children%e2%80%99s-hospital-the-road-to-hitech-act-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Superheroes</title>
		<link>http://www.indefenseofdata.com/2010/03/security-superheroes/</link>
		<comments>http://www.indefenseofdata.com/2010/03/security-superheroes/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 23:42:33 +0000</pubDate>
		<dc:creator>Sandler Rubin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.indefenseofdata.com/?p=91</guid>
		<description><![CDATA[My favorite quote of the week: “The truth is, we now fear the auditor more than the attacker.”
The 451 Group Research Director of Enterprise Security, Josh Corman, joined me in a recent GuardianEdge eSeminar and explained the new challenges facing the “good guys” of IT security.  While obvious threats include malware and data breaches, many [...]]]></description>
			<content:encoded><![CDATA[<p>My favorite quote of the week: “The truth is, we now fear the auditor more than the attacker.”</p>
<p><a href="http://www.451group.com/about/bio_detail.php?eid=407">The 451 Group Research Director of Enterprise Security, Josh Corman</a>, joined me in a recent GuardianEdge <a href="http://www.guardianedge.com/exclusive/20100325_MassMutual_eSeminar_Slides.pdf">eSeminar</a> and explained the new challenges facing the “good guys” of IT security.  While obvious threats include malware and data breaches, many administrators are also finding themselves fending off auditors armed with regulations and strict compliance standards.</p>
<p>“Compliance is now eclipsing threat as the number-one driver in security spending,” Corman noted.  “Nearly every penny spent last year on security was under a compliance mandate.”</p>
<p>Corman added that when he asked administrators why they were focused more on dealing with the auditors then on fending off the latest threat or what their risk management research noted as key issues, the response was very clear: “I might get hacked, but I WILL be fined.”</p>
<p>“That’s a troubling development for me,” Corman responded.</p>
<p>So in today’s world of emerging threats, what is scarier: having a portable device stolen or having a device that does not meet your industry’s compliance standards?  Being non-compliant but secure; or being compliant but exposed to real risks?  Take a listen <a href="http://www.guardianedge.com/eseminar/20100325/recording.php">to Corman</a>, or download his recent report, titled, “<a href="http://www.guardianedge.com/exclusive/WP_the451group_Security.pdf">Security Derivatives: The Downward Spiral Caused by Information Asymmetry</a>.”   <a href="mailto:rkrishnan@guardianedge.com">Let me know what you think</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.indefenseofdata.com/2010/03/security-superheroes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MassMutual CISO and 451 Group Talk About “Proactive” Protection</title>
		<link>http://www.indefenseofdata.com/2010/03/massmutual-ciso-and-451-group-talk-about-%e2%80%9cproactive%e2%80%9d-protection/</link>
		<comments>http://www.indefenseofdata.com/2010/03/massmutual-ciso-and-451-group-talk-about-%e2%80%9cproactive%e2%80%9d-protection/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 23:41:59 +0000</pubDate>
		<dc:creator>Sandler Rubin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.indefenseofdata.com/?p=89</guid>
		<description><![CDATA[Next Thursday, March 25, GuardianEdge is hosting an eSeminar on Practical and Proactive Data Encryption.  Bruce Bonsall, the award-winning CISO of MassMutual, and Josh Corman from the 451 Group are joining me on the panel.
How does a company protect its sensitive data when much of it resides on the endpoints of third-party agents who are [...]]]></description>
			<content:encoded><![CDATA[<p>Next Thursday, March 25, GuardianEdge is hosting an eSeminar on <a href="http://www.guardianedge.com/eseminar/20100325/?z=pr">Practical and Proactive Data Encryption</a>.  Bruce Bonsall, the award-winning CISO of <a href="http://www.massmutual.com/">MassMutual</a>, and Josh Corman from <a href="http://www.the451.com/">the 451 Group</a> are joining me on the panel.</p>
<p>How does a company protect its sensitive data when much of it resides on the endpoints of third-party agents who are not employees?  This is the challenge Bruce and his team faced at MassMutual, when tasked with rolling out encryption to their internal workforce as well as a large network of insurance brokers and agents in the field.  It’s an interesting dilemma, and as part of this discussion Bruce will draw on his many years as a leader amongst his CISO peers and highlight the importance of being proactive in outlining an overall protection strategy.</p>
<p>Recently <em>NetworkWorld</em> magazine recognized Josh Corman as a top Influencer of IT for 2009, and he is going to bring some interesting insight on wider security issues to the discussion. Josh is an original thinker with strong opinions, and will talk about the choices that organizations make between addressing a real security risk with a focused solution, versus satisfying an auditor’s checkbox with a consolidated suite.  I’m excited to hear him share his perspective on the tradeoffs between these approaches.</p>
<p>I’m looking forward to a good discussion with both Bruce and Josh about how companies can stay ahead of today’s security threats.</p>
<p>If you’d like to listen in, please sign up at <a href="http://www.guardianedge.com/eseminar/20100325/recording.php">http://www.guardianedge.com/eseminar/20100325/recording.php</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.indefenseofdata.com/2010/03/massmutual-ciso-and-451-group-talk-about-%e2%80%9cproactive%e2%80%9d-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
