Showing posts with label data erasure. Show all posts
Showing posts with label data erasure. Show all posts

Tuesday, 21 April 2015

Apathy, Fear, Suspicion and the SME



Most people work hard and have busy days. Managers and business owners have a lot of things to think about, a lot of rules and regulations to consider, and it all takes time. That is why recycling and the idea of sustainable business is not as high on the agenda as we would like it to be.

EReco sits in a sector fraught with risks, regulations and rules, but the biggest feeling I get from the majority of SME’s I talk to is a strange mixture of apathy, fear and suspicion.

Let me take those three emotional responses in reverse order.

People are suspicious of someone taking away their old IT equipment purely because they suspect that they are missing out on something. It’s not so bad with old wires, keyboards and the like, because they did not cost a lot in the first place and they have been well used and abused, and possibly don't fit the replacement kit which in any case come with new wires etc, but when it comes to desktops, laptops, servers and stuff, the cost kicks in. Remember, this is the man who has just paid to replace this stuff. He knows what it cost him down to the last penny. And even if that pile in the corner is all now redundant, he has this nagging voice in his head that tells him he is giving away money. It makes him reluctant to let go.

Fear is there too. He is no fool. He knows about hard drives, or at least he thinks he does. He does not think there is anything bad on the old machines, he may even have checked, and he does not think any criminal mastermind would be that interested in his old files anyway, but there is a nagging doubt there. He is not really sure what he should do, so he does nothing much at all, except deleting everything he can see.

Which brings me to apathy. Because this is not one of life’s bigger decisions. Not in the great scheme of things. This is redundant kit. If you have bought replacements and you have put the old stuff in a dark corner somewhere whilst your mild fears and suspicions fester, you cannot really be bothered to chase the solution too far. There is no problem hanging on to IT rubbish. It is not decomposing. So unless you need the storage space back, keeping it is relatively risk-free. It is actually easier to do nothing at all.

I absolutely guarantee that if you root around in any business premises you will find a bit of redundant kit somewhere. Damn it, most family homes are the same. I have a Virgin Media box they just left with me when I upgraded to TiVo. It has been at the bottom of my wardrobe for two years for heaven’s sake. And I could just drop that down the dump, for free.

There are thousands of tons of WEEE we could be recycling right now sitting there doing nothing other than take up space. And that is quite important, don’t you think? The idea that our electrical goods can be broken down at worst and reused to make something else is an incredibly good one, but far too often the good message gets lost in the reality of the situation, and that causes fear, suspicion and apathy.

So if you are a slightly nervous, suspicious sort of person who hasn’t summoned the energy to do the right thing with that pile of rubbish in the storeroom, it’s time to buck up. Call me (there are other IT recycling businesses out there, if you really must, but hey, we’ve come this far together, give a guy a break!) and I will sort it for you. It doesn’t hurt, you might get a few quid ahead at the end of the process and you will be doing something good for once.

Come on, you know it makes sense.
http://www.ereco.co.uk

Thursday, 9 April 2015

Doing Porridge for your Data?



During an election campaign it is probably natural to ask ourselves what a government is for? And the answer is to govern...to conduct the policy, actions and affairs of a state, organisation or people with authority...to quote a dictionary definition. Obviously quite a complicated business but when it comes down to it I believe it amounts to setting boundaries.

That is what laws are. You can do this but you cannot do that, and if you do we will punish you. In an ideal world, any government’s legislation should leave its people in no doubt as to how they are expected to behave, everything should be black and white, and we should therefore understand the consequences of our actions.

Data security is regulated but the legal boundaries are anything but clear. Not to the vast majority of people. If you sat your average business manager in a room and asked him what he was supposed to do with the data within his control, he would not have a clue.

To a certain extent that is our own fault. Not many people have ‘check the data protection act and how it applies to my role’ on their to-do list. But they should of course. It would make things so much easier in the long run, especially if the information available was written so that anyone not related to Steven Hawking had a chance of understanding it.

Here’s a thing. An example of what I mean. When you dispose of an old Business PC, you are being governed (that word again) by two sets of legislation...WEEE and Data Protection. One classifies your old PC as waste and therefore it must be moved under a waste transfer note, by a licensed carrier and all that jazz. Not very exciting and we could have a debate about when it becomes waste, but essentially it is, so there, live with it and get a waste transfer note. It is better than a fine.

But the data stuff is trickier. According to the law you are not throwing out an old PC, you are giving away your data. From the moment it leaves your possession, your risk is running around outside of your control and protection and legally you need to show a duty of care towards its security. If you have not and it all goes a bit Pete Tong you are in the firing line of a £500k fine. Very soon you would be opening up the doors of the Scrubs and heading for a six month stretch standing nervously with your back to the wall!

Make no mistake about it; the penalties are serious and getting worse. The misuse of data is taken very seriously in Brussels and Westminster. Mess up through negligence or criminal intent and you can expect to feel the full force of the law and the Daily Mail, not necessarily in that order.

The law is often an ass but in this case it is not. It may not be educating us in how to stay on the right side of it enough for my liking but this idea that you are transporting data is good sense. People disposing of an old piece of kit do not see the data, they see the hardware. They are well used to passwords and network security and they don’t really think about what is on the hard drive. So the law is trying to say ‘hey stupid, remember what’s on there.’

The law is trying to protect everyone. Any data a business holds will involve someone else. It may just be name, address and phone number but in many if not most cases it will include sensitive stuff like bank details, medical records, financial information or even criminal records. So the law reminds you to take care.

Hence the existence of some 800 recycling businesses in this country who will deal with IT or data-bearing equipment. Or at least say they will deal with it. And this is where I get worried about the laws. The fact is they make suggestions without defining what they mean. They say use a specialist partner to make sure but they do not help with that choice. There are no British standards, no Kitemark for data erasure or destruction.

That in itself is not unusual. There are many sectors that have no government standards and quite often the sector gets together to try and set its own. The Press Complaints Commission would be a recognisable example of an industry regulating itself. In our case ADISA or the Asset Disposition and Information Security Alliance, which is an independent body certifying members and setting standards, in conjunction with the government, who do work around the edges.

However of those 800 business less than 40 are certified by ADISA. And only 3 are approved by DIPCOG to work in the MoD/Government space. Now this does not make the other 760 or the other 797 bad of course. It just suggests that in the absence of a national standard they do not see the value of playing the game.

That is a shame. The waters are muddy enough and we could do with some clarity. Because without it, who your data walks out of the door with is rather left to chance. And it is you who will pay the fine, not them. In a few months, when the new European laws get ratified, it could be you, or one of your directors, who gets to do the porridge.

Wednesday, 1 April 2015

Our (bad) attitude to data is all wrong



Data is something we all take for granted but when you think about it, what is data really? In terms of our old friend the data protection act it would be best described as information. The sort of stuff that if someone else gets hold of it they can do something with.

Information, as we are all taught, is power.

In the last week or so we have run the full gamut of emotions with data. We have had the dear old Daily Mail screaming from the rooftops about personal data being available for sale, allegedly without the permission of the people concerned. If you believe their rather wild claims millions of people will now be mercilessly stripped of their pensions by blaggards from the data industry who all have villas in Florida and drive expensive sports cars.

Undoubtedly there are some sharp operators out there. But that is true of almost any industry or sector. However the thing that struck me throughout the furore was that no one really cares about their data, so why are the Daily Mail getting so uptight?

Quite apart from the small rather inconvenient fact that quite a lot of the data they were whining about was probably obtained perfectly legally, the people they are trying to protect throw their personal information around with such gay abandon that it is a surprise anyone has a pension left.

Social media sites like Facebook and LinkedIn are rife with stupidity. People happily give access to their information to all and sundry and are then surprised when someone nicks it, or spam’s it. And people throw away old computers and phones without wiping the data. It’s like writing your bank details on a piece of paper and putting it in the bin, rather than shredding it.

Of course there is a problem here. Most people are not totally scammed. You hear about the odd identity theft or black credit rating caused by data theft, but most people get away with being really quite dim.

And here we are back at one of my pet themes...education. Technology has outstripped education to an extent. When I was a teenager we had some practical lessons...how to write a cheque, how to boil an egg, iron a shirt, sew on a button and make phone calls. And yes we got to look at pictures of the odd male reproductive organ in sex education classes too! Nowadays kids would not know what a cheque was, and have probably seen more naked bodies on social media than I have had hot dinners.

But we should be teaching them how to be safe on these things, and not just safe from sexual predators (although that is obviously important). Their data is precious because it is information. If they learn not to release it to strangers without cause, or without knowing what will be done with it, we can eradicate all these problems. And if they learn that the hardware holds a multitude of sins waiting to bite them in the bum too, they will learn to deal with that.

Businesses suck up information, largely for no apparent reason. They do not use most of it. Ever. If you are asked a personal question that has no relevance to what you are doing, refuse to answer. It will stop it ending up as a selection criteria on some database somewhere.

Data is mostly unintelligible. Most of the crazy predictive things analysts say they can do with data do not work very well. They work in general terms, and in that sense, from a marketing point of view help identify a category of targets with a theoretical propensity to do ‘X’. Then a tele-sales exec hits the number and asks you about PPI. That is the level of sophistication we are talking about here. It is nothing sinister. Data in itself, the sort we put down on forms and the sort that ends up on those evil databases, is not really going to do us much harm.

So, actually, if you are still with my train of thought, the disposal of your old equipment without dealing with the data is the most stupid thing of all. Because this is not just the data, this is the whole shebang...your account numbers, your passwords, your photo of that girl on holiday doing that physically almost impossible thing with the banana and the sun lounger. And the Daily Mail is not getting all excited about computer recycling are they?

So it’s just me then!

Friday, 27 March 2015

Spock says it is not logical



Hoarding is easier. I think every man knows that deep down, but most of us live with women who do seem to get an extra chromosome...the tidy gene. At home that means the remote control does not live on the sofa and that newspaper from last Wednesday is not going to turn into a fixture...if you want to live. But at work, we have rather more power and I have never known a store cupboard or room yet that is not a male preserve.

I am not being sexist here. I am all for equality and have personally never craved storeroom control but it is just a fact of life. Where there is a growing pile of junk a man is involved. He naturally sees the effort and potential problems involved in getting rid and has never yet derived any real pleasure in seeing any space clutter free. It only a member of the fairer sex who can spend countless hours cleaning a room and then declare that it was all worthwhile because it looks so clean and tidy. A man would much prefer to close the door and watch the footie.

So the storeroom tends to fill up over time. There are the stores of course...the paper, maybe some toner for the printers, a bit of stationary...but the most interesting stuff is the waste. You know what I mean. The stuff we all know we are finished with but getting rid of it completely would take some real positive action. The broken chair, those old filing cabinets, that fax machine no one was using anymore, the accounts printer that only prints when it feels like it and that old desktop that crashed last month.

This is the stuff you cannot put in the bins round the back of the office. It’s easy to get rid of waste paper and discarded coffee cups and milk cartons. You have bins for that and the collection is all arranged on a bi-weekly basis with that nice man in the hi-viz jacket, but he does not take broken chairs and he does not take old computers. And the old computers are tricky. Dimly in the back of your mind, you remember that it has a hard drive. You cannot just throw that away. So putting it in the boot of the car and slipping it down the local tip is not really an option. You know you are not supposed to do that with business waste anyway but the hard drive worries you, a little. Not enough to do anything else but stack it in the storeroom though. Because it is safe there. Out of sight and out of mind.

Except that is not the answer. Not forever. Eventually the storeroom gets full. Eventually someone with influence suggests that it looks like a tip in there. Sooner or later you are forced to face up to the fact that this stuff has to go.

Ideally at this point you realise that your first priority should be data security, closely followed by the demands of sustainability. In other words, get it data clean then recycle it. And herein lies the problem of course, because it is at this point where some people get the impression that someone will clear their storeroom for free, whilst meeting their various priorities.

Let’s recap. This is waste. You know it and I know it. Not only has it been in that storeroom since Clive Sinclair last had a glint in his eye but it was put there because it is BROKEN. Your list of stuff includes a few bits of IT equipment, a few bit of general WEEE and some broken down old office furniture. And yet you expect someone to come and get it, give you all the right paperwork, erase your data and recycle the kit for...nothing.

Sorry Jim, this is not logical. And the problems are all caused by people not understanding what we are doing here. This is about the data and the planet. We all have a legal responsibility to protect the data we hold that concerns other people. That sounds reasonable to me. I do not want any business or organisation that has my personal details risking any sort of breach thank you very much. And the government and the European Union take it seriously enough to pass laws making it illegal, with very large fines. Quite soon directors will be held responsible, and could end up going to jail if they are found guilty of some seriously nefarious data related disaster.

So before you hand your entire database over to some free collection service, be bloody sure that they are going to do things properly....for nothing remember. Of course sir, your data will be rubbed out using a J-cloth and some white spirit, when old Joe gets around to it. Well if old Joe gets around to it. Nothing really to worry about, because we will be sending it to Africa anyway...

Which brings us back to the planet. Tossing your data away might cost you £500k, which turns a free collection into a very expensive mistake. But not ensuring that your equipment is properly recycled is quite literally a crime against nature. I am relatively new to this industry but I have come to hate landfill, and the idea that we can countenance so many people cheating the regulations to make a profit, or in our example’s case save a few quid.

I am beginning to resent losing orders to these free services. Part of that is my natural inclination to compete. I like winning you see, and therefore hate losing. I am not and never have been a good loser. I make Arsene Wenger, Jose Mourinho and Alex Red-Nose Ferguson look positively cheery by comparison with me. But that is because they usually play on a level playing field.

£100 to get rid of a pile of junk legally, morally and responsibly is not a bad deal. Nothing to get your database on eBay and your old equipment into landfill in Ghana is a terrible deal.

Tuesday, 17 March 2015

One Direction for Data Security



Data security is an ever expanding nightmare. You are liable. Yes you. For everything. Or rather you are if you are the nominated data controller for your company. Soon there will also be a defined board responsibility too. We are months away from someone getting thrown in the clink because Mavis in accounts thought she was checking her Twitter account and ended up posting the database to North Korea by mistake.

Do you remember the good, old fashioned western? The sort of film where the sheriff, in an effort to clean up his town, made all the cowboys leave their guns at the jailhouse. Our offices will be like that one day...mobile phones left in lockers until the end of the day...rather like school. Because a Smartphone is a data breach waiting to happen, and companies will only want their staff using company owned (and regulated/controlled) kit on the wifi.

Which will drive their employees mad, and cause them to break the rules and sneak their beloved phones in anyway. It is all a recipe for disaster, not to mention dissatisfaction and angst.

However, we need to remember why this is all such a concern, and then apply it to all areas of the IT minefield, including asset disposal at end of life. It’s all about the data, and the harm that can be done if that data falls into the wrong hands. It could be data about you and me as consumers, as patients or pupils. It could be bank details, and therefore access to our worldly goods, or it could be medical records, criminal records, confidential information we would not like anyone else to see. In law, this data is enshrined and protected, so the person who loses it, or negligently lets it get lost, is liable to do twenty years in Pentonville.

But oh how blasé we all are about data! Come on, admit it, you know it’s true. I am a salesman and have been for over thirty years. I have been adding information to database’s throughout that time I suppose, starting with a pen and a rolodex and ending up with salesforce.com and all manner of other CRM systems. So I know what it is like, and although I no doubt tried to enter the right information at the time, we all know there is a lot of garbage in there. And of course if it isn’t all used on a regular basis, even good information turns to garbage. B2B data decays at the rate of about 30% a year, as companies close, move or merge, and people leave. And yet, lose that pile of old misspelt names and bounce back email addresses and you will feel the long arm of the law on your shoulder in next to no time.

I suspect that the latest plans to make a director of any company or organisation directly responsible for data security will wake a few people up. I have been a director of a limited company, and signed all the forms for Companies House, and I remember reading through the responsibilities. It was hard not to take them seriously. I sincerely hope that will be the case.

Because the current situation really is a bit of a worry. The penalties are there and the regulations are there but there is a lack of understanding and appreciation not only of the risks but of the solutions. We start with subject knowledge at ground zero, so there really is only one direction to go and that is up!

We need to educate. I know it is a fairly dry subject but just think about it. Do you search your staff when they leave the building for a USB memory stick? Do you make sure every printer has it’s memory dealt with when you get rid of it? What do you do with the company mobile phone handsets when you upgrade? It’s not just all about computers and hard drives anymore.

We are going to have to change. Data has got bigger but you can now steal it on a stick which you can hide in the smallest of orifice’s. You can attach a file to an email and post it out. Or you can let that nice man take those 5 broken desk tops and find your database on eBay the next day.