'Insider' government data breaches soaring
By Emily Chung, CBC News
Posted: Nov 15, 2011 2:50 PM ET
Last Updated: Nov 15, 2011 3:57 PM ET
The study was presented Tuesday in Toronto by, left to right, Northgate CEO Michel Juneau-Katsuya, Rafael Etges of Telus Security Solutions and Walid Hejazi, professor of business economics at the University of Toronto's Rotman School of Management. (Emily Chung/CBC)
Related
Related Links
External Links
(Note:CBC does not endorse and is not responsible for the content of external links.)
The proportion of "insider" internet security breaches caused by employees are rising quickly within Canadian government departments and agencies, a new study shows.
Insider breaches in the government sector grew by 28 per cent between 2010 and 2011 and are up 68 per cent since 2008, the fourth annual Telus-Rotman joint study on Canadian IT security practices reported Tuesday. They now make up 42 per cent of breaches reported by government organizations, compared to 27 per cent of breaches at public corporations and 16 per cent at private businesses.
"This is quite alarming," said Rafael Etges, director for security and risk consulting services at Telus Security Solutions, who co-authored the report with Neil Begin, program director at Telus Security Labs and Walid Hejazi, professor of business economics at the University of Toronto's Rotman School of Management.
That alarm shouldn't be necessarily eased by the fact that the number of breaches per government organization have declined slightly in the past year, Etges said, because it points to weaknesses in the government's approach to IT security.
Insider breaches include both malicious and accidental incidents, such as laptop or mobile devices losses and unauthorized access to networks or data by employees.
In fact, the latter type are reported at a much higher rate by government organizations than public and private companies, the study found:
- Laptop or mobile device thefts were reported by 34 per cent of government organizations surveyed in the study compared to 19 per cent of private companies and 25 per cent of public companies.
- Unauthorized access of information by employees was reported by 24 per cent of government organizations, compared to 11 per cent of private companies and 19 per cent of publicly traded companies.
The study relied on a survey of more than 600 Canadian IT professionals at government organizations, private companies and publicly traded companies. It noted that in the private sector and overall, the percentage of breaches caused by insiders is declining – down to 22 per cent in 2011 from 25 per cent in 2010.
When asked why there is such a difference in trends between the business and government sectors, Etges proposed a number of reasons.
Laptop or mobile device thefts were reported by 34 per cent of government organizations surveyed in the study compared to 19 per cent of private companies and 25 per cent of public companies. iStockFor one thing, government organizations rely more heavily on technology for its IT security and less on education and awareness training than businesses do, he said.
The fact that governments often block employee access to certain services such as social networking sites may also play a role, he acknowledged.
Blocking Facebook results in breaches
The study found that blocking social networking sites leads to more security breaches as employees try to circumvent the company's security.
Etges also noted that the government is an "obvious target" for people seeking unauthorized access to data.
Michel Juneau Katsuya, a former CSIS agent and manager who now advises governments and businesses on IT security, said 85 to 90 per cent of current spy cases involve an employee who was granted access to certain information. In an interview following the release of the report, he added that while it may be possible to use technical means to gain unauthorized access to certain data, "the vast majority of the time, they will get access through a person."
The key to preventing that is education and awareness training, said Juneau-Katsuya, CEO of the Northgate Group, an Ottawa-based security intelligence and research firm.
"It's not difficult," he added, noting that most employees want to do the right thing — they simply need to know the risks and how to prevent them.
"Unfortunately, the government is doing a really, really poor job in raising the awareness," he said.
He blamed a culture of secrecy that he says has long been part of both the current and previous governments.
"This secrecy is not helping us at all. We need more transparency."
Share Tools
Top News Headlines
- Toronto mayor's brother says he never dealt drugs
- The brother of Toronto Mayor Rob Ford has vehemently denied allegations in Saturday's Globe and Mail that he was involved in the illicit drug trade in the 1980s. more »
- Hockey Canada votes to ban bodychecking in peewee hockey
- Hockey Canada's board of directors voted to eliminate bodychecking from peewee-level hockey on Saturday in Charlottetown. more »
- Neil Macdonald: How serious is Obama about curbing the drone surge?
- In a key speech this week, the U.S. president set out a host of supposed new safeguards for America's controversial practice of remote-controlled rough justice. But as Neil Macdonald writes, the underlying rationale for drone use has not fundamentally changed. more »
- Ontario man lost in Australian mountains has survival skills
- The sister of an Ontario man who disappeared in Australia's Snowy Mountains nearly two weeks ago says she remains hopeful he will be found, partly because of his training as a Canadian Forces reservist. more »
Must Watch
Latest Technology & Science News Headlines
- 1976 Apple computer sells for $668,000
- An auctioneer says one of Apple's first computers — a functioning 1976 model — has been sold for a record $668,000 US. more »
- 3D printers give rise to 'desktop manufacturing'
- Customizable objects from plastic dollhouse furniture to medical prosthetics can now be designed and printed out by almost anyone at the press of a button, and is going to lead to an 'explosion of new stuff,' predicts author Chris Anderson. more »
- Google Street View captures Galapagos Islands
- Few have explored the remote volcanic islands of the Galapagos archipelago, an otherworldly landscape inhabited by the world's largest tortoises and other fantastical creatures that inspired Charles Darwin's theory of evolution. more »
- King Richard III buried in 'untidy' grave
- New information has surfaced in the odd tale of the British king buried in a car park. King Richard III's remains, which were discovered August under a parking lot in Leicester, England, were laid to rest in a grave researchers are now saying was "badly prepared" and "untidy." more »
Bob McDonald's Blog
Chris Hadfield: The gravity of gravity May. 17, 2013 9:58 AM After five months of being Superman and a media superstar, Canadian astronaut Chris Hadfield is now beginning the challenging task of adapting his mortal body and brain to life back on Earth.
Latest Features
- Toronto mayor's brother says he never dealt drugs
- NYPD investigating Amanda Bynes sex assault allegations
- 3 more suspects arrested in slaying of U.K. soldier
- McDonald's CEO chastised by 9-year-old B.C. girl
- Dog snared on baited hooks near Vancouver's Grouse Grind trail
- Retired police officer killed in Mexico remembered as animal lover
- Ontario man lost in Australian mountains has survival skills
- Canadian mine giant Barrick fined a record $16.4M in Chile
- Black bear breaks into North Vancouver chicken coop

