Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Tuesday, 21 April 2015

Apathy, Fear, Suspicion and the SME



Most people work hard and have busy days. Managers and business owners have a lot of things to think about, a lot of rules and regulations to consider, and it all takes time. That is why recycling and the idea of sustainable business is not as high on the agenda as we would like it to be.

EReco sits in a sector fraught with risks, regulations and rules, but the biggest feeling I get from the majority of SME’s I talk to is a strange mixture of apathy, fear and suspicion.

Let me take those three emotional responses in reverse order.

People are suspicious of someone taking away their old IT equipment purely because they suspect that they are missing out on something. It’s not so bad with old wires, keyboards and the like, because they did not cost a lot in the first place and they have been well used and abused, and possibly don't fit the replacement kit which in any case come with new wires etc, but when it comes to desktops, laptops, servers and stuff, the cost kicks in. Remember, this is the man who has just paid to replace this stuff. He knows what it cost him down to the last penny. And even if that pile in the corner is all now redundant, he has this nagging voice in his head that tells him he is giving away money. It makes him reluctant to let go.

Fear is there too. He is no fool. He knows about hard drives, or at least he thinks he does. He does not think there is anything bad on the old machines, he may even have checked, and he does not think any criminal mastermind would be that interested in his old files anyway, but there is a nagging doubt there. He is not really sure what he should do, so he does nothing much at all, except deleting everything he can see.

Which brings me to apathy. Because this is not one of life’s bigger decisions. Not in the great scheme of things. This is redundant kit. If you have bought replacements and you have put the old stuff in a dark corner somewhere whilst your mild fears and suspicions fester, you cannot really be bothered to chase the solution too far. There is no problem hanging on to IT rubbish. It is not decomposing. So unless you need the storage space back, keeping it is relatively risk-free. It is actually easier to do nothing at all.

I absolutely guarantee that if you root around in any business premises you will find a bit of redundant kit somewhere. Damn it, most family homes are the same. I have a Virgin Media box they just left with me when I upgraded to TiVo. It has been at the bottom of my wardrobe for two years for heaven’s sake. And I could just drop that down the dump, for free.

There are thousands of tons of WEEE we could be recycling right now sitting there doing nothing other than take up space. And that is quite important, don’t you think? The idea that our electrical goods can be broken down at worst and reused to make something else is an incredibly good one, but far too often the good message gets lost in the reality of the situation, and that causes fear, suspicion and apathy.

So if you are a slightly nervous, suspicious sort of person who hasn’t summoned the energy to do the right thing with that pile of rubbish in the storeroom, it’s time to buck up. Call me (there are other IT recycling businesses out there, if you really must, but hey, we’ve come this far together, give a guy a break!) and I will sort it for you. It doesn’t hurt, you might get a few quid ahead at the end of the process and you will be doing something good for once.

Come on, you know it makes sense.
http://www.ereco.co.uk

Thursday, 16 April 2015

Avoid the ‘I told you so’ lecture at all costs



You would never dream of putting your hard copy bank statement in the bin, would you? Not without at least tearing it up into little pieces. Maybe you bought one of those home-shredders? It is the same at work. If you print out something confidential, you are careful with it. You would not leave it out on your desk whilst you nipped to the loo, and you would shred it if you threw it away. It is second nature. You know something contains sensitive information and you are sensibly careful with it.

Which makes some people’s attitude towards IT data security unfathomable. The same person who bought one of those home-shredders to destroy their private correspondence, left their old PC at the local tip, in the dry WEEE store, without any real idea what would be done with it, and ignoring the fact that all that correspondence and more is still on the hard drive. Every word, every account number, every little detail of your life.

Mr Spock would call it illogical. We do not seem to connect the hardware to the printout. No one would bother to turn that old PC on and dig around for old personal files, would they? Well yes they would actually. Because data, information of almost any sort, is valuable. Cyber crime is on the rise and no one really knows what will happen next, because it is quite new. We have only really been using computers for twenty five years or so, and the internet is even younger. 

The basic bottom line is if it is valuable, someone will try to nick it.

So our apathy is getting more and more dangerous. We have to wise up here. However you do it and whoever you use, you need to sanitise your data before you dispose of any piece of kit. Be it a phone or a laptop, a tablet or a printer, think about the memory. It may only be a small percentage of people that get caught out this way but why would you want to be one of them?

When you get rid of anything with a memory you are taking a risk, a gamble. Every single time. As soon as you let that old PC out of your sight, you have given your data to someone else. Serious if you are a consumer, bloody scary if you are a business. Because as a consumer, you are only risking your own data, your own identity, your own bank balance. But as a business, you risk other people’s data, and as such you have a duty of care. You can be heavily fined and soon imprisoned if you do not fulfil that duty of care.

Lightning rarely strikes but when it does, it tends to hurt. I’ll give you another little example from my own life. In my private life, a pair of jeans is second skin to me. And for forty odd years I always put my wallet in my back pocket. Never gave it a second thought. My then wife used to nag me about it when we went out. She said it was easy to steal, in plain sight, but I doubted anyone could take my wallet out of my pocket without me noticing. And it had never happened...until one day at Crawley cinema. It was heaving and I was focussing on my son, then little more than a toddler, who was doing his best to get lost in the crowds. I caught him and took him back to his Mum, who was queuing for a drink. I went to pay...and no wallet.

An expensive lesson which got me the ‘I told you so’ lecture. Which no man ever wants to hear. So now I am a little more careful. In busy places, I move my wallet to a less obvious place. I manage the risk. Which is, as I may have said before, what data safe IT recycling is really about.

We do have to change our collective attitude to data security. There is no alternative. Cyber crime is not going to go away. You know I am right. Every person I sit down and talk this through with in any detail ends up agreeing with me. You cannot trust dumb luck to protect you, and you cannot do half a job and expect to stay safe. Sooner or later your luck always runs out. Do it, and if you are going to do it, do it properly.

Otherwise I am going to be right here saying I told you so!

Wednesday, 1 April 2015

Our (bad) attitude to data is all wrong



Data is something we all take for granted but when you think about it, what is data really? In terms of our old friend the data protection act it would be best described as information. The sort of stuff that if someone else gets hold of it they can do something with.

Information, as we are all taught, is power.

In the last week or so we have run the full gamut of emotions with data. We have had the dear old Daily Mail screaming from the rooftops about personal data being available for sale, allegedly without the permission of the people concerned. If you believe their rather wild claims millions of people will now be mercilessly stripped of their pensions by blaggards from the data industry who all have villas in Florida and drive expensive sports cars.

Undoubtedly there are some sharp operators out there. But that is true of almost any industry or sector. However the thing that struck me throughout the furore was that no one really cares about their data, so why are the Daily Mail getting so uptight?

Quite apart from the small rather inconvenient fact that quite a lot of the data they were whining about was probably obtained perfectly legally, the people they are trying to protect throw their personal information around with such gay abandon that it is a surprise anyone has a pension left.

Social media sites like Facebook and LinkedIn are rife with stupidity. People happily give access to their information to all and sundry and are then surprised when someone nicks it, or spam’s it. And people throw away old computers and phones without wiping the data. It’s like writing your bank details on a piece of paper and putting it in the bin, rather than shredding it.

Of course there is a problem here. Most people are not totally scammed. You hear about the odd identity theft or black credit rating caused by data theft, but most people get away with being really quite dim.

And here we are back at one of my pet themes...education. Technology has outstripped education to an extent. When I was a teenager we had some practical lessons...how to write a cheque, how to boil an egg, iron a shirt, sew on a button and make phone calls. And yes we got to look at pictures of the odd male reproductive organ in sex education classes too! Nowadays kids would not know what a cheque was, and have probably seen more naked bodies on social media than I have had hot dinners.

But we should be teaching them how to be safe on these things, and not just safe from sexual predators (although that is obviously important). Their data is precious because it is information. If they learn not to release it to strangers without cause, or without knowing what will be done with it, we can eradicate all these problems. And if they learn that the hardware holds a multitude of sins waiting to bite them in the bum too, they will learn to deal with that.

Businesses suck up information, largely for no apparent reason. They do not use most of it. Ever. If you are asked a personal question that has no relevance to what you are doing, refuse to answer. It will stop it ending up as a selection criteria on some database somewhere.

Data is mostly unintelligible. Most of the crazy predictive things analysts say they can do with data do not work very well. They work in general terms, and in that sense, from a marketing point of view help identify a category of targets with a theoretical propensity to do ‘X’. Then a tele-sales exec hits the number and asks you about PPI. That is the level of sophistication we are talking about here. It is nothing sinister. Data in itself, the sort we put down on forms and the sort that ends up on those evil databases, is not really going to do us much harm.

So, actually, if you are still with my train of thought, the disposal of your old equipment without dealing with the data is the most stupid thing of all. Because this is not just the data, this is the whole shebang...your account numbers, your passwords, your photo of that girl on holiday doing that physically almost impossible thing with the banana and the sun lounger. And the Daily Mail is not getting all excited about computer recycling are they?

So it’s just me then!

Tuesday, 31 March 2015

Dodgy Data Distraction



You have to love the Daily Mail. They do love a scare story. Yesterday it was your pension data being sold for 5p to unscrupulous cold-callers by allegedly dodgy data companies. Shock horror, we will never be safe in our beds again!

I caught up with the story on the Today programme and heard Chris Graham, the Information Commissioner himself, living up to my nickname for him of Genghis Khan. He was threatening immediate investigations into B2C Data, the company the Mail outed, with his usual £500k fine and a bit of decapitation if the guilty were found guilty.

But just hang on a cotton picking minute. The accusation here was that personal financial information was being passed on (sold) without the knowledge of the individuals concerned. Well the B2C website isn’t exactly hiding its activities under a bushel, Mr Daily Mail. Their website boasts of their 38m strong database and suggests that it has been compiled from a large number of syndicate partners.

So this is not necessarily dodgy and that is what the Daily Mail, the Today programme and the man in the street fail to realise. Every time we apply for something...a mortgage, a phone, a credit card or even a holiday...we freely give lots of information, and somewhere in the small print will be a box to either tick or untick talking about sharing that data.

It’s the junk mail box if you like. You are opting in if you tick it to agree and opting out if you tick it to disagree. And whether you opt in or fail to opt out matters.

All email data to consumers ought to be opt in, by law I believe. Genghis will know this. If you agree to receive emails, lo and behold you will receive emails. Your address will be sold to all and sundry for a few pence. Mine seems to be sold to Viagra salespeople and purveyors of gentlemen’s entertainment but that might just be spam. There is a difference between unsolicited marketing communications and spam you see. One you have agreed to, the other you haven’t.

So, just what are the Daily Mail objecting to here? If B2C are selling data without the required permissions/opt-ins from their syndicated partners, everyone will be in trouble. I am not saying it doesn’t happen, because it does, but the real charlatans are not trumpeting their wares on a web site in my limited experience.

I am afraid the much more likely scenario is that this is all essentially above board. Companies like B2C amalgamate data from a variety of sources and if you as an individual appear on their database it will be because you gave your information to one or more of those sources. If those sources are legitimate they will have asked you a question about selling your data on and you will, perhaps unwittingly, have given them permission to do so. It may have been asked sneakily, it may have been an auto-ticked box on a web form that you failed to notice, but it will have been done.

So what data are they likely to have? Well, basically anything you have ever filled out on a form applying for something. Name, address, phone number, spouse, number of kids, email, mobile and middle name for sure. Salary, job title and number of years in your job. Probably. Nothing startlingly private. Ok, I know it is not stuff that you want published in the Daily Mail, but it is not really doing you any harm appearing on a database, and remember, this information is really only going to be used to select you to receive a phone call or email.

A marketing database is a prospect list, and someone trying to get you to unwisely take your pension now in cash (the threat the Mail was highlighting) will have used your salary to bracket you. He/she earns above X so he/she will likely have a pension of X so is worth a call. Or he/she is this age and earns that, so he/she is a target. Every piece of information they have on you is a selector, and really nothing else. And companies like B2C charge by selection.

The 5p the Mail quoted probably won’t get you a lot more than email, name and postcode. If you want the detailed information, you would pay more. And this information has been on the market for years, both legally and illegally. No doubt, as the Mail says, some of this information ends up in the hands of criminals, but I am not sure you can necessarily blame B2C for that.

This needs investigating of course, but if the accused company have been aggregating data from multiple sources legally, making sure that the opt-ins and outs were all done properly by their syndicate partners and then cleansing and managing their database correctly, I hope they sue the backside off the Mail.

Data is a very misunderstood commodity. We all create it and give it to people without really thinking about what we are doing. As a marketer, I want your email address and your permission to use it. In B2B, my field of expertise, there is much less regulation on this sort of thing but I still want your permission, tacit or proactive, because the communication is more rewarding that way.

The aggregation of business data is every bit as sly as the consumer stuff. For instance, Companies House happily sells its data on every business registered with it for a nice fat fee. Then the data companies start adding to this basic registered address and directors info by overlaying directory data to get trading addresses and phone numbers. Maybe some research will be done at some stage to pick up some contact names and bingo, you have a list.

You may not realise that you gave your data away. You may have been slightly tricked into not noticing the box which would have stopped it all. But you have done it dozens of times. We are all on hundreds of different lists. Just one example you probably do not realise, the Bounty rep who called on you or your partner whilst you were recovering from the birth of your baby. They gave you some nice freebies and took some information off you, and that information is one of the most valuable data sets in the country. New parents are an easy touch you see, like prospective pensioners. I wonder if the Mail will investigate that?

The moral of all this is that it is never good to give your data away. Find the box if you are filling out a form and find a responsible data security and recycling professional if you disposing of any old computers! Simples.

Friday, 27 March 2015

Spock says it is not logical



Hoarding is easier. I think every man knows that deep down, but most of us live with women who do seem to get an extra chromosome...the tidy gene. At home that means the remote control does not live on the sofa and that newspaper from last Wednesday is not going to turn into a fixture...if you want to live. But at work, we have rather more power and I have never known a store cupboard or room yet that is not a male preserve.

I am not being sexist here. I am all for equality and have personally never craved storeroom control but it is just a fact of life. Where there is a growing pile of junk a man is involved. He naturally sees the effort and potential problems involved in getting rid and has never yet derived any real pleasure in seeing any space clutter free. It only a member of the fairer sex who can spend countless hours cleaning a room and then declare that it was all worthwhile because it looks so clean and tidy. A man would much prefer to close the door and watch the footie.

So the storeroom tends to fill up over time. There are the stores of course...the paper, maybe some toner for the printers, a bit of stationary...but the most interesting stuff is the waste. You know what I mean. The stuff we all know we are finished with but getting rid of it completely would take some real positive action. The broken chair, those old filing cabinets, that fax machine no one was using anymore, the accounts printer that only prints when it feels like it and that old desktop that crashed last month.

This is the stuff you cannot put in the bins round the back of the office. It’s easy to get rid of waste paper and discarded coffee cups and milk cartons. You have bins for that and the collection is all arranged on a bi-weekly basis with that nice man in the hi-viz jacket, but he does not take broken chairs and he does not take old computers. And the old computers are tricky. Dimly in the back of your mind, you remember that it has a hard drive. You cannot just throw that away. So putting it in the boot of the car and slipping it down the local tip is not really an option. You know you are not supposed to do that with business waste anyway but the hard drive worries you, a little. Not enough to do anything else but stack it in the storeroom though. Because it is safe there. Out of sight and out of mind.

Except that is not the answer. Not forever. Eventually the storeroom gets full. Eventually someone with influence suggests that it looks like a tip in there. Sooner or later you are forced to face up to the fact that this stuff has to go.

Ideally at this point you realise that your first priority should be data security, closely followed by the demands of sustainability. In other words, get it data clean then recycle it. And herein lies the problem of course, because it is at this point where some people get the impression that someone will clear their storeroom for free, whilst meeting their various priorities.

Let’s recap. This is waste. You know it and I know it. Not only has it been in that storeroom since Clive Sinclair last had a glint in his eye but it was put there because it is BROKEN. Your list of stuff includes a few bits of IT equipment, a few bit of general WEEE and some broken down old office furniture. And yet you expect someone to come and get it, give you all the right paperwork, erase your data and recycle the kit for...nothing.

Sorry Jim, this is not logical. And the problems are all caused by people not understanding what we are doing here. This is about the data and the planet. We all have a legal responsibility to protect the data we hold that concerns other people. That sounds reasonable to me. I do not want any business or organisation that has my personal details risking any sort of breach thank you very much. And the government and the European Union take it seriously enough to pass laws making it illegal, with very large fines. Quite soon directors will be held responsible, and could end up going to jail if they are found guilty of some seriously nefarious data related disaster.

So before you hand your entire database over to some free collection service, be bloody sure that they are going to do things properly....for nothing remember. Of course sir, your data will be rubbed out using a J-cloth and some white spirit, when old Joe gets around to it. Well if old Joe gets around to it. Nothing really to worry about, because we will be sending it to Africa anyway...

Which brings us back to the planet. Tossing your data away might cost you £500k, which turns a free collection into a very expensive mistake. But not ensuring that your equipment is properly recycled is quite literally a crime against nature. I am relatively new to this industry but I have come to hate landfill, and the idea that we can countenance so many people cheating the regulations to make a profit, or in our example’s case save a few quid.

I am beginning to resent losing orders to these free services. Part of that is my natural inclination to compete. I like winning you see, and therefore hate losing. I am not and never have been a good loser. I make Arsene Wenger, Jose Mourinho and Alex Red-Nose Ferguson look positively cheery by comparison with me. But that is because they usually play on a level playing field.

£100 to get rid of a pile of junk legally, morally and responsibly is not a bad deal. Nothing to get your database on eBay and your old equipment into landfill in Ghana is a terrible deal.