590 likes | 702 Vues
Explore the aftermath of a data breach at the University of Victoria in 2012. Discover the importance of transparency, effective communication, and the implementation of good policies in safeguarding sensitive information. Gain insights into handling breaches and mitigating risks.
E N D
Lessons Learned from a Breach Eric van Wiltenburg University of Victoria @e_vanwiltenburg
“Transparency is an asset.” Eric van Wiltenburg, January 31, 2012
employee names • employee numbers • Social Insurance Numbers • bank account • employee classification code • amount of last deposit
January 2012 January 2010
Lesson • Having good policies in place is very important, even if nobody reads them
University Secretary • Vice President Finance and Operations • Manager Privacy, Access and Policy • University Legal Counsel • Information Security Manager • Director, Communications • Associate Vice-President Human Resources • Associate Vice-President Faculty Relations • Assistant Director, Campus Security • Executive Director, Government Relations • Vice-President External Relations • Assistant Treasurer • Risk Analyst
FIPPA OIPC
Lesson • Effective external communication to {organization, staff, community} is important for {salvaging reputation, reassuring affected individuals, ensuring resolution}, even if the internal politics, communications and logistics cause friction.
250-472-4333 privacyinfo@uvic.ca
Regular bulletin updates • Information sent to current and former UVic employees, Jan. 9, 2012 • Letter from Vice-president Finance and Operations Gayle Gorrill, Jan. 10, 2012 • A message from President David Turpin, Jan. 11, 2012 • Jan. 12, 2012 update • Jan. 13, 2012 update • Jan. 19, 2012 update • Jan. 20, 2012 update - Launch of review • Jan. 23, 2012 update - Phishing attacks & fraud investigation • Jan. 25, 2012 update - Preliminary report to board • Jan. 27, 2012 update - Agreement reached on Credit Monitoring Service • Jan. 26, 2012 update - Saanich police release info • Feb. 3, 2012 update - Credit monitoring service available Monday • Feb. 6, 2012 update - Credit monitoring instructions
Lesson • Bad guys and gals know how to read the news
Lesson • Understand what “reasonable security arrangements” are