Past News - CIOInsight
Home arrow Past News arrow LexisNexis in the Security Hot Seat
  Past News


LexisNexis in the Security Hot Seat
By CIOinsight


Rate This Article:
Add This Article To:
Learn how LexisNexis chief information security officer Leo Cronin shored up defenses after the company was raided by data thieves.

In April 2005, Leo Cronin, chief information security officer of data provider LexisNexis Group, got the kind of news that every manager in his position dreads: Personal records for 310,000 individuals had been stolen from the company's databases in 59 separate incidents. Even bigger data thefts have hit the headlines since then, including the loss of data on 26 million U.S. veterans last month.

Nevertheless, for LexisNexis, a $2.7 billion subsidiary of publishing company Reed Elsevier that provides specialized legal and business data to customers, the compromise was a potentially serious blow. Cronin, 47, says the company has taken specific steps to minimize the risk of the company's data being pilfered again.

And like other security professionals, Cronin says that what's needed is a "defense-in-depth" strategy, an industry term that refers to applying security measures ubiquitously across the computing infrastructure.

Resource Library:
One key layer for Lexis-Nexis: Its $2 million project to deploy intrusion prevention system (IPS) appliances, which not only detect network attacks but are designed to automatically neutralize them.

What lessons did you learn from having data on 310,000 individuals stolen?

The big message we took away is that we absolutely have to be concerned about our customers' environments when it comes to accessing our services. Providing a fortress around LexisNexis and making sure nobody can spearhead an attack against our data center—that's one thing. But the fact that someone could go in and manipulate a customer's environment to steal [a password and user ID] ... to get access to our service is an issue we need to absolutely worry about.

And we are doing a lot of things within Lexis to lock that down, for example, by restricting where certain customer user IDs can be used from on the Internet. We are looking very hard at two-factor authentication systems [which require both a password and a specialized hardware device to log on to a network], very much like what banks are doing.

What's a typical misconception businesspeople have about data security?

The assumption that it's there—that when I go out and hook my computer up to the Internet, somehow someone was thinking about safety. When in reality, where we've come from, is that nobody was thinking of safety. Microsoft was thinking about selling more Windows operating systems. The [telecommunications] carriers were interested in getting people on the Internet. And at the end of the day, I don't think anyone was really thinking about the safety aspect of it.

Read the full story on eWEEK.com: LexisNexis in the Security Hot Seat



Discuss LexisNexis in the Security Hot Seat
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Past News Articles          >>> More By CIOinsight
 


 
 
FEATURED SPONSORED MESSAGE

FEATURED SPONSORED MESSAGE

BIZTECH 3.0
By Brian P. Watson
IT Salaries Rise. Kinda.

Some IT workers will get a pay bump this year, but the good times aren't back just yet.
CIO STRATEGY
Data Center Power Play

Parkinson expresses his serious concerns over power density, cost.   

Google CIO on IT's Role in Corporate Culture

RECENT NEWS

KNOW IT ALL
By Tony Kontzer
Doubting the iPad

Our resident skeptic turns his attention to Apple's latest offering. 


EDITORS' PICKS
 
 
LATEST STORIES

FEEDBACK


Ziff Davis Enterprise RSS Feeds

Sponsored Links
  • up.time Easily Monitors Virtual/Physical/Cloud. Free Trial.
  • Register for WES 2010 by February 19 and save $400.
  • Learn more about EnterpriseDB @ the Postgres Center
  • One number. One voicemail. Sprint Mobile Integration.
  • 10 Reasons to Upgrade to Windows Server 2008 R2.
  • CDW Healthcare offers the IT solutions you need.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • eWEEK Quick LInks