
BLIND FAITH: INFORMATION LEAKS OUT OF CONTROL, ORGANIZATION LIABILITIES AND CONSUMER PRIVACY AT RISK
Workshare-sponsored Study Exposes Organizations Running on Faith; No Automated Standard of Care for Educating Users and Enforcing Information Security Policies
San Francisco — July 24, 2006 - The majority of corporations and government agencies in North America have no idea how much sensitive data is leaking out of their organizations. Worse yet, they have no automated standard of care for detecting and preventing leaks or educating personnel on information security polices, according to a new study released today. This lack of awareness and action exists despite an understanding of how such leaks put brand reputation and customer privacy and loyalty at risk.
The industry-wide study was conducted by The Insight Advantage, a Silicon Valley research firm with expertise in in-depth customer insight and information analysis. The data, collected from 359 executives responsible for security, compliance, risk management and legal at large organizations in North America, paints a distressing picture. Even though respondents consider privacy and confidential data leaks a top concern, the study reveals a significant lack of knowledge and awareness about the level of risk in these organizations. Findings include:
- 94 percent of respondents reported having no visibility into how many email messages containing confidential or private information were leaving their organization each month or believed that some leaks were occurring. Only 6 percent reported no information leaks.
- 80 percent of participants reported having information leaks—through email or other electronic channels such as Blackberrys or HTTP postings—or admitted to no visibility to leaks that occurred within their organization last year. Of those, 17 percent were afraid to know how many leaks they had.
- More than 70 percent now believe PDF does not secure information, a growing trend from a recent rash of publicized information leaks in PDF documents. Alarmingly, 46 percent are still relying on PDF file conversion to enforce their information security policies.
- 68 percent stated personally identifiable customer data poses the greatest information risk and 56 percent said a leak of this type would result in their company losing customers.
- 57 percent do not have a specific method for enforcing data privacy and document security policies.
- While 100 percent of respondents consider it important to protect information within their organizations, 80 percent consider it “extremely important.”
“Over 40 million privacy violations occurred in the last year alone, yet fewer than two percent of organizations were caught. The fact that 94 percent of organizations are running on faith or have no automated way of educating users and enforcing data protection policies explains escalating consumer concerns about identity theft,” said Joe Fantuzzi, chief executive officer and president of Workshare. “Workshare built its Protect product line to help organizations gain control over information leaks. Today more than 1,000 organizations have peace of mind using Protect--securing information from their desktops to their gateways, both offline and online, with user-involvement and full auditability.”
The Insight Advantage uses a rigorous, advanced methodology leveraging participant confidentiality to gain unprecedented customer insight and objectivity. This research was conducted using both quantitative and qualitative interview methods with leaders in corporate and government agencies. The Insight Advantage has done similar work for notable companies such as Cisco, Yahoo! and Handspring to name a few. The complete study is available at www.workshare.com/surveyresults.
About Workshare Protect Enterprise Suite
The Workshare Protect Enterprise Suite is an endpoint and network solution that delivers the ABCs of content security: Alerts users and IT management to potential information leaks, Blocks content in violation of policies and Cures content of risky information automatically. Workshare’s user-centric approach minimizes business disruption while dramatically lowering compliance enforcement costs. The suite includes Workshare’s award-winning Protect client, already installed at more than 1,000 organizations worldwide, Workshare Policy Manager and Workshare Network Protect. Details are at www.workshare.com/products/wsprotect/protect_enterprise.aspx.
About Workshare
Workshare, an Information Security company, delivers Secure Content Compliance solutions to over 5,500 organizations worldwide. Workshare solutions uniquely combine policy enforcement, management control and user education to ensure safe information exchange without business disruption. Its products include Workshare Protect Enterprise Suite, Workshare Professional, DeltaView and TRACE! Workshare’s customer base spans small to large organizations in every industry segment with more than 58 percent of the Fortune 1000 and 85 percent of the ProServices 250. Over 900,000 professionals in 65 countries use Workshare software. The company has offices in San Francisco, New York, Chicago, Atlanta, Dallas, Washington DC, London, Frankfurt, Paris and Sydney. Workshare is the sponsor of www.metadatarisk.org, the definitive source for content security. For more information, visit www.workshare.com.