Skip to main content

Two-thirds of used hard drives hold personally Data

New research from the Blancco Technology Group shows personal data remaining on old eBay hard drives long after they go out of use
Users are failing to completely delete files when recycling hard drives
Users are failing to completely delete files when recycling hard drives
Hard drives are not getting wiped of data at major firms, according to new research.  Moreover, those hard drives contain corporate information as well as data that could identify people.
Blancco Technology Group bought a random sample of 200 hard drives on eBay and Craigslist.  Investigating further, researchers found around 67 per cent of the used drives contained personally identifiable information and 11 per cent held sensitive corporate data, including company emails, CRM records and spreadsheets containing sales projections and product inventories.
The firm said its findings proved just how easy, common and dangerous it is when businesses buy back and/or resell used electronics without properly wiping all data from them. It added that firms failing to wipe drives clean before they are resold, repurposed or recycled can cause irreparable damage to customer loyalty, brand reputation and sales, both short and long-term.
Its digital forensics analysts found company emails on nine per cent of the drives, followed by spreadsheets containing sales projections and product inventories (five per cent) and CRM records (one per cent).
On 36 percent of the used HDDs/SSDs containing residual data, users previously attempted to wipe the drives clean by dragging files to the Recycle Bin or using the delete button. A quick format was performed on 40 percent of the used drives with residual data found on them.
Out of the 200 used HDDs and SSDs, only 10 percent had a secure data erasure method performed on them, according to the research.
“Even though the obvious identifiers had been removed, enough information was left to expose the site's users. The big lesson for Ashley Madison – and any other type of business – should be to test that your deletion methods are adequate and to not blindly trust that simply 'deleting' data will truly get rid of all of it for good. Remaining data can still be accessed and recovered unless the data is securely and permanently erased."
In an exclusive interview with SCMagazineUK.com, Henry added that the corporate data we found on the drives is far more telling of how little businesses really understand about data security – and how little they're doing to protect and completely remove data.
“Unfortunately, we found extremely sensitive intellectual property on the used drives we analysed, which included spreadsheets containing sales projections and product inventories, as well as direct customer data and CRM records. Remember, 80 percent of employees are BYO users in their workplaces, but only 20 percent actually have policies to deal with that behaviour and the security risks that come with it,” he said.
Javvad Malik, security advocate at AlienVault, told SC that in many cases, the breach comes down to poor asset inventory and management. It is not for lack of policy in place, but lack of enforcement.
“Often times third party suppliers who may be smaller companies and not used to disposing of such sensitive data may be involved. Other times, it is because of employees looking to repurpose an old machine for personal use or sale” he said.
Jamie Moles, principal security consultant at Lastline, told SC that first and foremost companies should be using encryption on their hard disks – Bitlocker comes with Windows as standard and is entirely sufficient for the majority of users.  
Computer Disposals should be carried in a safe and secure manner. Security has been become a bigger concern for many organisations across UK and Europe. The fines can incur upto £1 million, for breach of data.
“If a company cannot do this then they should have a data destruction policy in place that mandates the secure erasure of all hard disks before they are sold on or handed off for recycling – software to perform this task is freely available from the internet and is quite inexpensive.”

Comments

Popular posts from this blog

Future of e-waste Recycling

Electronic and electrical goods have become indispensable parts of our lives now. We cannot think of surviving without these products anymore. For instance, just think of your life without your laptop, computer, your tab, your cell phone, the flat screen television and so on. Another interesting fact in this regard is that the electronic companies manufacture higher versions of these devices and we replace the older ones with the latest models. Research reports say that almost 30-50 million tons of electrical and electronic goods are simply thrown away every year. And such stuffs are categorized under e-waste. Survey reports also say that the volume of such wastes is expected to increase by 3-5% per year as people don’t hesitate progressing towards ‘smarter’ products by dumping the older ones.
Where do the older and used electronic products head to?

This is a very important question that needs answers. You might find the old cell phone or tablet tucked in some corner of the drawer or…

7 Ways to Improve Your Recycling Practices

Everyone knows about recycling these days but many still don’t know how they can improve their recycling practices. This will not only improve their lifestyle but also contribute a few positives towards the environment.
But before going into details, let us just go back and tell you how actually recycling got started. Well, it got started almost 40 years ago when a US paper company wanted a symbol for its customers to tell them about the products’ recycled content.
A design competition was held and in the end, a young graphic designer named Gary Anderson won the competition. His design is now universally recognised as the symbol for recycling.
When it comes to recycling, blue plastic bins and bottle drives pops up in the mind. Part of the problem, though, is that major bottling companies of beer and soft drinks use recycling to get rid of the responsibility of dealing with their own manufactured packaging. But actually, if you see it, recycling is much more than this. It is a design prin…

Top 4 Myths about WEEE Recycling

Go into any office these days, and will undoubtedly observe electronic gadgets. From PCs and mobile phones to photocopying machines and network devices, being utilized for a wide range of everyday exercises. But the picture becomes blurry when we talk about Waste Electrical and Electronic Equipment recycling (WEEE recycling) . Once outdated, we should discard the hardware. It is amazing to discover where a considerable measure of those old gadgets wind up. As result of innovation and schedule obsolesces, old hardware is piling in storage space or distribution center. Or, more regrettable, in a landfill (ordinarily abroad). Directions are set up to keep the illicit dumping of utilized electronic hardware. As any organization’s representative knows, WEEE recycling at last boils down to assuming liability for your own association's activities. And ensuring that we legitimately discard all e-waste. Before, when WEEE recycling was as yet a novel idea, it may have been less demanding t…