CIO Enterprise Newsletter
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Webcast: In the Google Apps Cloud: How to Achieve Your Business Objectives

Dec 3rd, '09, 1 - 2 pm US/Eastern (GMT-5)

Join Council member Brent Hoag, Director, Global IT, at JohnsonDiversey, as he discusses the adoption of Google Apps which has helped meet four corporate goals; sustainability, simplification, increased employee productivity and global collaboration.

Webcast: Collaboration Initiatives: Benchmarks & Best Practices

Dec 15th, '09, 4 - 5 pm US/Eastern (GMT-5)

Join Council members Ruth Thorpe, VP & CIO at the U.S. Pharmaceutical Operations of Sanofi-Aventis, and Gary Kuyper, CIO at Bethany Christian Services, as they speak about their collaboration initiatives and experiences in how and why they chose the social networking and collaboration tools they are using and their business goals for collaboration, and facing culture change challenges.

Data Overview: Collaboration Initiatives Field Guide: Benchmarks & Best Practices

This appendix to the Council Field Guide provides an analysis which discusses benchmarks for collaboration IT implementation costs, adoption rates and payoffs. The overview identifies top IT and business goals and satisfaction rates for collaboration initiatives as well as best practices and lessons learned for implementing collaboration IT.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 

Banks Fed Up With Retailers' Security Gaffes

What makes the TJX data breach different from the many that came before it?

 

March 22, 2007CIO

What makes the TJX data breach different from the many that came before it? This marks one of the first times banks or consumers have linked a specific incidence of credit card fraud to a security breach at a specific company, says Jim Lewis, a security expert at the Center for Strategic and International Studies.

Plus, bank executives are fed up and they aren't going to take it anymore.

That seemed to be the message delivered by the financial community in the wake of the security breach announced by TJX in January. TJX, the Framing­ham, Mass., parent company of discount stores including TJ Maxx and Marshalls, revealed that hackers had stolen an undisclosed number of customer credit card numbers (estimates are in the millions). The reaction to the break-in was swift: The Massa­chusetts Bankers Association said some of its member banks had been able to trace recent fraudulent purchases on credit cards to the TJX breach.

"We believe the financial responsibility for covering losses because of fraud is on the company where the breach occurred," says association spokesman Bruce Spitzer. "This is something we are pursuing."

As are others. So far, at least two class-action lawsuits have been filed against TJX (one by banks in Alabama and Ohio, and another by an individual in West Virginia). The Massachusetts Attorney General's office is investigating TJX's security practices. The suits and investigations have altered the security breach landscape. "You will see banks start to attempt to hold retailers and other merchants liable" for losses on credit cards, says Behnam Dayanim, a privacy attorney with Paul, Hastings, Janofsky & Walker in Washington, D.C.

As CIO, how do you protect your company from a similar mess? The first thing CIOs should do is discuss with business unit leaders whether personal information (such as addresses, driver's license data and Social Security numbers) needs to be stored at all. If there's no compelling business reason to keep it, then the company should discard it after processing any transaction, be it in a brick-and-mortar store or online. But if the storage of the information is viewed as key to increasing sales then the firm must secure the data.

Encryption is one answer. The Cali­fornia security breach notification law (the standard for such laws, which requires businesses to notify customers when personal data has been exposed) permits companies to forgo notification if the personal data was encrypted. But use strong encryption, because lawyers can argue that weak encryption is no protection at all, Dayanim warns.

 
 
Loading...
 
WHITE PAPERS

Expose Hidden Device-Account Relationships

A device fingerprinting solution such as iovation ReputationManager™ provides unique insight.
 

Exchange 2007 Risks and Mitigation Strategies

This whitepaper will review the strengths of Exchange 2007 and areas where CIOs should consider third party solutions.
 

Solving On-premise Email Challenges

This white paper presents ten on-premise challenges and their on-demand services solutions.
 

Adobe for Business Process Automation

Companies must be able to react to customer demands, competitive threats, and compliance requirements.
 

Increase Customer Satisfaction and Lower TCO

With Adobe® LiveCycle® Enterprise Suite (ES2) software, organizations can easily deploy intuitive user experiences.
 

Upgrading to VMware vSphere with vWire

Learn how vWire can help ensure the success of your upgrade from ESX 3.x to vSphere.
 

WEBCASTS

Email and Web Threats Require a Layered Defense

Can you trust the cloud to secure your enterprise from email and Web threats? This Webcast discusses how web threat...
 

Protecting PII: How to work with IT to manage risk

Understand the critical nature of the test data privacy problem and tips on how to work with IT to implement a test data privacy program.
 

Extending Client Refresh - 11 Steps to Maximize Savings

11 Steps to Maximize Savings
 

CIOs Weigh In On Virtualization

Date: November 19, 2009 Time: 2:00 PM EST

Jim Malone, Editorial Director of CXO Media's C...
 

Beyond Installing ITPM Software: How a global company reduced risk and successfully implemented ITPM

Hear directly from one of your peers who has reduced risk and successfully implemented ITPM in this Live Webcast. ...
 

IT Consolidation Made Easy

The Primary IT Initiative for Reducing Costs
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Keeping Your Members Safe from Online Scams and Predators

Return on Information: Google Enterprise Search pays you back

ROI of Application Delivery Controllers

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Webcast: Unleashing the Power of Customer Data

Disciplined Autonomy: Resolving the Tension Between Flexibility and Control

Enterprise Capture: Your Onramp to Business Process Automation

Cloud Computing--What is its Potential Value for Your Company?

Seven Design Requirements for Web 2.0 Threat Protection

How Consumerization of IT Will Make Your Business More Productive

How does a software company save big with Green IT?

Translate business strategy into IT strategy and obtain maximum benefits.

eBook: How Can You Make Your People Productive Anywhere?

Mind the Talent Gap: Global Survey on IT and HR trends and challenges

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

Increase UPS efficiency without sacrificing protection.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

Gartner Magic Quadrant, Application Delivery Controllers 2009

Authentication as a Service by Forrester Research

Learn How Web Site Performance Impacts Shopper Behavior

Build a Foundation for Unified Communications

Removing the Barriers to IT Governance: How On-Demand Software Changes the Game

Should Your Email Live In The Cloud? A Comparative Cost Analysis

Learn about the growing threat of insider data theft.

Adobe® LiveCycle® solutions for business process automation

10 Ways Excel Drives More Value from Your SAP Investment

The Key to Proving and Improving the Value of IT to the Company

Unleash the Power of Java with Oracle JRockit Real Time

Taking the Service Desk to the Next Level

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

See how AT&T can help protect your network.

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization