Skip to main content

Two-thirds of used hard drives hold personally Data

New research from the Blancco Technology Group shows personal data remaining on old eBay hard drives long after they go out of use
Users are failing to completely delete files when recycling hard drives
Users are failing to completely delete files when recycling hard drives
Hard drives are not getting wiped of data at major firms, according to new research.  Moreover, those hard drives contain corporate information as well as data that could identify people.
Blancco Technology Group bought a random sample of 200 hard drives on eBay and Craigslist.  Investigating further, researchers found around 67 per cent of the used drives contained personally identifiable information and 11 per cent held sensitive corporate data, including company emails, CRM records and spreadsheets containing sales projections and product inventories.
The firm said its findings proved just how easy, common and dangerous it is when businesses buy back and/or resell used electronics without properly wiping all data from them. It added that firms failing to wipe drives clean before they are resold, repurposed or recycled can cause irreparable damage to customer loyalty, brand reputation and sales, both short and long-term.
Its digital forensics analysts found company emails on nine per cent of the drives, followed by spreadsheets containing sales projections and product inventories (five per cent) and CRM records (one per cent).
On 36 percent of the used HDDs/SSDs containing residual data, users previously attempted to wipe the drives clean by dragging files to the Recycle Bin or using the delete button. A quick format was performed on 40 percent of the used drives with residual data found on them.
Out of the 200 used HDDs and SSDs, only 10 percent had a secure data erasure method performed on them, according to the research.
“Even though the obvious identifiers had been removed, enough information was left to expose the site's users. The big lesson for Ashley Madison – and any other type of business – should be to test that your deletion methods are adequate and to not blindly trust that simply 'deleting' data will truly get rid of all of it for good. Remaining data can still be accessed and recovered unless the data is securely and permanently erased."
In an exclusive interview with SCMagazineUK.com, Henry added that the corporate data we found on the drives is far more telling of how little businesses really understand about data security – and how little they're doing to protect and completely remove data.
“Unfortunately, we found extremely sensitive intellectual property on the used drives we analysed, which included spreadsheets containing sales projections and product inventories, as well as direct customer data and CRM records. Remember, 80 percent of employees are BYO users in their workplaces, but only 20 percent actually have policies to deal with that behaviour and the security risks that come with it,” he said.
Javvad Malik, security advocate at AlienVault, told SC that in many cases, the breach comes down to poor asset inventory and management. It is not for lack of policy in place, but lack of enforcement.
“Often times third party suppliers who may be smaller companies and not used to disposing of such sensitive data may be involved. Other times, it is because of employees looking to repurpose an old machine for personal use or sale” he said.
Jamie Moles, principal security consultant at Lastline, told SC that first and foremost companies should be using encryption on their hard disks – Bitlocker comes with Windows as standard and is entirely sufficient for the majority of users.  
Computer Disposals should be carried in a safe and secure manner. Security has been become a bigger concern for many organisations across UK and Europe. The fines can incur upto £1 million, for breach of data.
“If a company cannot do this then they should have a data destruction policy in place that mandates the secure erasure of all hard disks before they are sold on or handed off for recycling – software to perform this task is freely available from the internet and is quite inexpensive.”

Comments

Popular posts from this blog

4 Types of Recycling Materials

Recycling is inevitable for the environment. Anyone can take part in recycling in order to save the environment. In case you are wondering what things can be recycled, this is what you need to know. Eco Green IT London Tells About 4 Recycling Materials There are several types of recycling. We can categorize recycling into 4 main categories. Paper & Cardboard Recycling Any type of paper or cardboard can be recycled. The process of recycling paper includes collecting the paper from various ways, sorting the paper with respect to the grade of the paper and soaking the paper in a mix of water and chemicals to make a pulp. The pulp is cleaned up by tossing in machine, injecting air and soap-like chemicals to remove any type of ink or other residues and then drying the pulp in a screen. The fibres bind with each other as the water drains off. The rollers are then used to smooth the paper and squeeze remaining water. Plastic Recycling Plastic is the wond

8 Eco-conscious Ways to Dispose Hazardous Waste

Hazardous waste can be found everywhere – from commercial offices to factories to heavy manufacturing plants in the form of chemicals, cleaning fluids, pesticides, batteries, nuclear power, and more. Even if you are not producing hazardous waste, you are indirectly contributing in some or the other way. Here are 8 steps you can take to ensure safe and Eco-friendly disposal of waste: 1. Incineration Incineration is a safe way to dispose toxic waste and destroy hazardous waste. A big advantage of this method is the ability to transform flammable waste into energy sources. Advanced incinerators have greatly reduced the release of toxic gases in the environment. Incineration needs minimal amount of land, brings down the amount of trash to half and the residue produced is odorless. 2. Recycling Certain treated hazardous waste can also be recycled instead of being directly dumped into a landfill. Companies are now also compacting recyclable waste to reach their green goals

Secure Data Destruction: How to Wipe a Computer Before Recycling

  Introduction: In our digital age, recycling old computers responsibly is crucial for both data security and environmental conservation. Properly wiping your computer before recycling ensures that your sensitive information remains confidential and prevents electronic waste from polluting our planet. In this comprehensive guide, we'll walk you through the step-by-step process of securely wiping your computer before recycling, protecting your privacy and contributing to a greener future . Back Up Your Data: Before initiating the computer wiping process, it's essential to back up all your important files and data. This precaution ensures you don't lose valuable information during the recycling process. You can back up your data using an external hard drive, cloud storage, or a network storage solution. Sign Out of Accounts: To prevent unauthorized access to your accounts and personal information, make sure to sign out of all your accounts on the computer. This incl