The branch that you searched for does not have a page in your preferred language. Would you like to visit the branch page on the #CODE# site?
As the world leader in paper shredding, we ensure your documents are securely destroyed.
Hard drives could cost you millions in a data breach. Physically destroy your electronic data.
Stay ahead of legal or regulatory risks with our easy, online compliance training.
Get a Quote
Back To Information Security Resources
Welcome to the fourth edition of Securing the Future, a periodic e-newsletter from Shred-it. In this issue, we will talk about the importance of education and awareness when it comes to information security – and pinpoint some common concerns and best practice solutions that will help you create a high-security culture in your organization
“There is a growing need for secure document management and destruction as a preventative measure against information security breaches,” says Michael Skidmore, Chief Security Officer at Shred-it. “Effective protection comes hand in hand with an organizational culture of total security, which requires a shift in the attitudes of employees. Employees should not only know and understand their organization’s security policies and procedures, but truly commit to them and implement them correctly. With regard to document destruction, one aspect of this cultural shift is moving away from the paradigm of ‘document disposal’ to ‘document destruction’ and, even more importantly, ‘destruction at the source’.”
Download PDF Version
The eminent threat from fraud artists who benefit by stealing vital business and personal information makes your organization’s confidential data vulnerable to security breaches – potentially exposing your customers, clients or employees to identity theft and fraud. As the recovery from the economic recession is just starting, organizations may still be reluctant to increase or even sustain their security budgets. In fact, according to a 2009 survey by TELUS and the Rotman School of Management, Canadian organizations have reported an average security budget decrease of 10 per cent. The question arises: are the scaled down security measures enough to deal with the growing threats of security breaches?
“The high-security culture does not necessarily mean an increase in budgets or more efforts,” says Michael Skidmore of Shred-it. “In many cases, it simply means changing your processes and thinking differently. The first step towards a culture of high security, so critical to the integrity of any organization’s confidential data, is to understand the big picture of the organization’s typical security risks and then assess the best way to address them.”
While each and every organization has unique security challenges, the top five security concerns among Canadian organizations, according to the 2009 TELUS and Rotman survey on security breaches, are related to:
Disclosure or loss of confidential data
Compliance with Canadian regulations and legislation
Business continuity and disaster recovery
Loss of strategic corporate information
Employee understanding and compliance with security policy
A lack of a strategic security planning, combined with weak or inconsistent implementation of an organization’s security policies and procedures, creates an organizational environment that is more susceptible to security breaches. The culture shift towards total security, therefore, should start at the very top with the adoption of high-security strategic thinking amongst the senior management team, who can then push it down the organization in the form of effective security policies, processes and values.
It may come as a surprise to many that insider access to sensitive data, including customer and employee records, is a key organizational security concern, potentially leading to identity theft and fraud. According to the TELUS-Rotman survey, 17 per cent of Canadian organizations reported so-called “insider breaches” in 2008, and that figure doubled to 36 per cent in 2009. Similarly, unauthorized access to information by employees has increased in 2009 by an alarming 112 per cent, and is the fastest-rising breach category.
These figures point to the conclusion that organizations need to turn inward when dealing with security threats. Consider who has access to sensitive information in your organization. Given that employees with “access” are most closely related to potential risks for leaked or lost data, stringent access policies should be in place and followed rigorously. While there are no sure-fire methods for preventing security breaches from within, there are ways to reduce the threat – and creating a total security culture is one of the key components of any successful strategy.
Any solutions to the risks of security breaches should be based on a holistic, integrated perspective on document security throughout the document lifecycle across an organization. In other words, documents should be protected from the moment they are created until the time they are no longer needed. The TELUS and Rotman survey reported that the focus in Canada has predominantly been towards after-the-fact security activities, dealing with breaches as they happen or testing the effectiveness of security features that are already in place. Instead, organizations should look to the future as an opportunity to develop approaches and concepts that are strategic, integrated and long-term, such as eliminating security risks at the source and permanently securing the entire document lifecycle across all organizational units.
One of the most effective ways to prevent security breaches from either inside or outside an organization is by implementing “shred all” policies. A “shred all” policy will make sure that all documents are fully and securely destroyed on a regular basis.
The cultural shift should change from reducing to eliminating security loopholes throughout the lifecycle of the document. Rather than “disposing” or “discarding” of confidential data that is no longer needed, employees should be trained in the values of “destruction at the source”.
A culture of security is about educating employees about the importance of secure document management and destruction. The attitudes and values reflected in your organization’s security strategies, policies, procedures and overall security thinking are the foundation of this security culture.
The tips from Shred-it below will help you build the culture of total security in your organization:
Stay informed with the latest in information security news and promotions.
Fill out the form or call 888.750.6450 to start protecting your business today!