Data Security

Hard Drive Lost with Data on 583,000 Canadian Students

Hard Drive Lost with Data on 583,000 Canadian Students
January 16, 2013 10:54AM

Bookmark and Share
Commenting on the hard drive that has gone missing with Canadian Student Loan data, analyst Lawrence Reusing advised, "Companies and government offices need to provide secure USB devices with strong encryption. Solutions exist today that allow for that encryption to be applied without interfering with use of those devices."

You have the experience and skills, let an ISACA® certification demonstrate your value. Our certifications announce that you have the expertise and insight to speak with authority. ISACA certification is more than a credential; it's a platform that can elevate your career. Register for an Exam Today.

The Canadian government says a portable hard drive containing personal information on 583,000 Canada Student Loan borrowers was lost from an office in Gatineau, Quebec. The electronic storage device held data on clients of the Canada Student Loans Program from 2000 to 2006.

Student names, Social Insurance Numbers, dates of birth, contact information and the loan balances of Canada Student Loan borrowers were stored in the lost device, along with personal contact information of 250 government employees. No banking or medical information was included on the portable hard drive.

"While there is no evidence at this time that any of the information has been accessed or used for fraudulent purposes, this incident is being taken very seriously and the Office of the Minister has engaged the Royal Canadian Mounted Police," the Canadian government said in a statement. "Extensive and thorough search efforts have been undertaken and continue."

Solution: Secure USB Devices

Lawrence Reusing, general manager for Imation's Global Mobile Security business, told us large-scale data losses such as this are disastrous but avoidable.

"In this case, for example, had the data on the USB device been properly encrypted, the data contained thereupon would have been completely undecipherable and useless to anyone finding it. USB devices are more and more vital today, given the mobile nature of the workforce," Reusing said.

"Companies and government offices need to provide secure USB devices with strong encryption, and solutions exist today that allow for that encryption to be applied without interfering with use of those devices. Beyond providing peace of mind and protecting sensitive information, this helps address related regulation since many regulations and laws regarding close control of data do not apply to encrypted information."

Who's to Blame?

Diane Finly, minister of Human Resources and Skills Development (HRSD), the agency responsible for safeguarding the data, said she has requested that HRSD employees across Canada receive comprehensive communications on the seriousness of these recent incidents and that they participate in mandatory training on a new security policy to ensure that similar situations do not occur again.

"Further, I have instructed that the new policy contain disciplinary measures that will be implemented for staff, up to and including termination, should the strict codes of privacy and security not be followed," she said.

Sophos security analyst Paul Ducklin said he could not help but notice a touch of "beatings will continue until morale improves" in this comment. Although he admitted Finley might not mean it that way, it sounded to him like employees would be in the firing line if a hard disk was stolen from their desks.

"I'm all in favor of employees living up to their responsibilities, but what if your own organization makes that difficult by not providing an environment in which computer security is easy to do properly?" Ducklin asked in a blog post. "For example, should it even be possible for you, or any of your colleagues, to make a backup copy of that much data onto a removable drive without encryption?"

Tell Us What You Think
Comment:

Name:

Eugene:

Posted: 2013-07-19 @ 3:11am PT
I cannot imagine such a thing would happen to me. I am totally alright with unexpected problems, but someone letting my personal data be breached would be too much. As far as I understand, lots of wrong people got bills for education. I assume they were pretty much astonished. So I guess someone was not really careful with the entire security system, right?! You know, I have taken our loans many times and got positive feedback for Manitoba online loan company. Not a single time data was stolen or leaked.

Joeseph:

Posted: 2013-01-18 @ 7:27am PT
This situation could have been avoided, I am just thankful that my information is not included in this mistake (I started taking loans in 2007). There are multiple ways to avoid a situation like this, and dodge the severe repercussions a mistake like this brings. There are multiple companies that specialize in data retention, security and storage that can provide a solution for avoiding situations like this. Educate yourselves on different options please. This brings up concerns for me as well, because I am now questioning the safety of my data and information that I entrusted with the University and the National Student Loans Service. I plan on doing my masters this coming year, and I am now seriously questioning taking another student loan, and postponing my studies until I can make the money myself....

So disappointed...

Herry69:

Posted: 2013-01-18 @ 7:16am PT
Harper and the corruption are STILL screwing everything up as usual. I hope Harper gets sued big time. This pig MUST go to jail for a million years!



 Data Security
1. Juniper DDoS for High-IQ Networks
2. Google Hacker Team to Hunt Bugs
3. Cloud Firms Offer Azure Starter Kit
4. FBI Cyber-Expert's Humble Start
5. Chinese Hackers Hit U.S. Officials




 Most Popular Articles
1. Experts Say Four Threats Put Internet Freedom at Risk
2. Gartner Rates Security Solutions in Annual Magic Quadrant Report
3. Google I/O Conference Brings a Lot for Businesses
4. IBM Earmarks $3B for Next-Gen Cloud Computing Chips
5. Focus on Security in New Dell Products, Upgrades

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Juniper DDoS for High-IQ Networks
  Seagate Unveils Networked Drives
  Google Hacker Team to Hunt Bugs
  Cloud Firms Offer Azure Starter Kit
  FBI Cyber-Expert's Humble Start

 Technology Marketplace
Big Data
Unlock your enterprise data's potential. Learn how in the research report.
Are you getting everything you can out of your business data?
 
Business Intelligence
Get real-time, cloud-based information services with Neustar.
 
CIO Issues
Secure and retain skilled technology professionals. Learn how.
 
Cloud Computing
Are you getting everything you can out of your business data?
 
Data Storage
Unlock your enterprise data's potential. Learn how in the research report.
 
Enterprise Hardware
Protect your network with APC Smart-UPS battery backup
Cisco UCS Invicta Series flash memory systems
 
Enterprise I.T.
Register for an upcoming ISACA® certification exam today
Secure and retain skilled technology professionals. Learn how.
 
Enterprise Software
Unlock your enterprise data's potential. Learn how in the research report.
 
Hardware
Protect your network with APC Smart-UPS battery backup
Ferocious productivity. A fearless team of pros. Find Out More
Cisco UCS Invicta Series flash memory systems
 
Network Security
Protect your network with APC Smart-UPS battery backup
 
Small Business
Ferocious productivity. A fearless team of pros. Find Out More