Join the community!

Login, register or Connect to comment.

Our View

Maine needs to analyze breach data, not just store it

Published on Friday, Feb 12, 2010 at 12:12 am | Last updated on Friday, Feb 12, 2010 at 12:12 am 2 Comments

Since April 2008, more than 24,000 Mainers have had their personal e-information compromised in more than 200 corporate security breaches, according to information gathered from five state agencies by the Sun Journal for a story about e-security that appeared Jan. 24.

Many of the breaches resulted from criminal hacking, but many others happened because laptops containing sensitive information were stolen or lost, or e-mails containing personal information were sent with attachments that should not have been shared. The public never heard about most of the breaches.

There are five separate agencies in Maine that collect information about identity breaches, instances in which someone's personal computerized information — payroll records, credit card purchases, bank account balances and numbers, Social Security numbers, addresses, birth dates — are lost or "compromised."

These agencies do a good job of collecting the data, but not such a good job of cataloging, collating and comparing that data. Breach notifications are received by these agencies and individual consumers alerted by the companies, but there is no requirement to analyze patterns or report worrisome developments to the Legislature or to the public.

The Sun Journal asked these five stage agencies for information about recent security breaches, and each of the agencies willingly provided the data, all stored in different formats.

The Office of Securities, which collects data of breaches at stock brokerages; the Bureau of Insurance; the Bureau of Consumer Credit Protection, monitoring breaches of mortgage companies and loan brokers; and the Bureau of Financial Institutions, which monitors banks and credits unions, provided data on internal spreadsheets. The Attorney General's Office, where 76 percent of all security breaches in Maine are reported, keeps the reports on paper filed in file folders.

Storing these reports on paper without any real means to alert the general public seems an ineffective way to protect consumers. It's no defense against e-thieves.

The Sun Journal created its own spreadsheet of data at the AG's Office during a two-day inspection of the paper files, and compared it to data collected at the state's four other reporting agencies.

We were struck by how inaccessible this information is in the digital age. Consumers who are the subject of an e-breach are alerted, but there is no general public alarm about how widespread or creative these breaches can be, which makes it difficult for others to respond to protect their own personal information.

We can try to protect our e-selves by creating passwords, being careful about logging on to unsecure sites and not putting personal information on computers at work, but we can't prevent widespread breaches of databases that happen because someone in the corporate world makes a mistake, leaving a laptop with our credit card history on a plane or e-mailing other personal information where it doesn't belong.

As a group, Mainers are less likely to be the victims of identity theft than others across the country, but as digital access increases here, that's not likely to remain the case.

Maine doesn't need a new agency to monitor security breaches, but it does need some means of combining breach reports intra-agency and some means of analyzing the data in real time, in time for consumers, when they can, to defend themselves.

Information is not only power. It's protection.

editorialboard@sunjournal.com

In order to make comments, you must verify your account.

In order to comment on SunJournal.com, you must use your real name and include the town in which you live in your profile. A member of our staff will call you to verify this information. To join in, fill out your user profile completely and check the box "please verify my status." We'll get back to you within one business day to verify your account.

Login or create an account here.

Our policy prohibits comments that are:

  • Defamatory, abusive, obscene, racist, or otherwise hateful
  • Excessively foul and/or vulgar
  • Inappropriately sexual
  • Baseless personal attacks or otherwise threatening
  • Contain illegal material, or material that infringes on the rights of others
  • Commercial postings attempting to sell a product/item
If you violate this policy, your comment will be removed and your account may be banned.

Advertisement

Displaying comments, from newest to oldest

veritas's picture
verified

Interesting that the

Interesting that the Sun-Journal is now suddenly concerned about 'Data Breaches' and the misuse of information, yet only two days ago the Editorial Board saw absolutely nothing of concern with Law Enforcement Agencies storing vast amounts of data indicating where the vehicles of every-day citizens' - suspected of no criminal activity, were located -  at what time, and in relative proximity to what other vehicles and places, and information concerning the owner's of those other vehicles.

Nope - no problem at all.

Just the type of data mining, and information old J. Edgar Hoover would have swooned to have had available to him.  The possibilities are mind-boggling to anyone familiar with intelligence gathering.

Let's not be asleep at the switch, Sun-Journal.

tron's picture
verified

What you forget is that the

What you forget is that the people who would misuse the license plate information would be the police, which the SJ has no problem with.   It is the type of double standard that all republican rags possess.

Advertisement

Stay informed — Get the news delivered for free in your inbox.

I'm interested in ...