• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register | Login to Member's Area

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • NDL Seminar: Take the office with you - easily
    8th February
    London, United Kingdom
  • NDL Seminar: Take the office with you - easily
    9th February
    Greater Manchester, United Kingdom
POPULAR PAPERS
  • Best practices for cloud security by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Raw Wit - "I live so far out of town the mailman mails me my letters." - Henny Youngman

PAGE TOOLS
  • Request Reprints
  • Tell A Friend
  • Contact Author
RECENT POSTS
  • Secure disposal of old IT equipment
  • A critical software problem for banks
  • Auditors want to know about individuals, not groups
  • IT security vendors can't all be right, but they can all be wrong
  • Don't forget the network
  • Consumers say no [to data leaks]
ADVERTISEMENT
fotoSENSE - Click here!
BLOG ARCHIVE
  • December, 2011
  • November, 2011
  • October, 2011
  • September, 2011
  • August, 2011
  • July, 2011
  • April, 2011
  • February, 2011
  • January, 2011
  • November, 2010
  • October, 2010
  • September, 2010
Voipfone VoIP 30 Day FREE Trial Click To Sign Up Now
Blogs > Quocirca

CRU email row highlights importance of data loss prevention

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 21st December 2009
Copyright Quocirca © 2009
Logo for Quocirca

The recent theft of emails from the University of East Anglia Climate Research Unit (UEA CRU) has proved embarrassing, but the incident does not change any of the facts regarding global warming. New Scientist (9th Dec 2009) summaries it well:

"The emails suggest some of the scientists may have tried to shut out critics, which, if true, goes against advancing knowledge through open debate. On the other hand, the aim of peer review is to prevent substandard research from being published, so you could argue that the scientists were just doing their job because they felt the papers in question were not scientifically rigorous."

The full article is viewable here.

As a research company, albeit looking into matters not quite so prescient for the future of life on Earth, Quocirca can sympathise with New Scientist's view. Should our own email server be hacked, you would find discussions along the lines of "how can we present this in the best light", "this research seems to contradict previous research, how do we explain that?" and so on. This does not represent any attempt to falsify the findings, but just ensuring a reasoned interpretation provides an understanding of how, in the complex markets Quocirca covers, contradictions occur and what they mean. Once work is published findings have to be explained, justified and defended.

However, one thing most people will agree on is that emails that were meant to be private are best kept that way. The Norfolk Police are investigating the crime that led to all this, but it seems that the UEA CRU was targeted by persons unknown with the specific aim of undermining the Dec 2009 Copenhagen Climate conference. For an outsider with malicious intent to gain access to private email servers suggest poor security somewhere along the line, perhaps finding a privileged back door, which can be all too easy (see Quocirca free report, Privileged User Management, Nov 2009). However the theft was perpetrated, it should have been preventable.

Of course, it may be that someone chose to leak the email. The volume involved (thousands of emails and other documents) would have shown up as anomalous behaviour had data loss prevention (DLP) software been in place (see Quocirca free report, Content security for the next decade, Nov 2008). Only about 25 per cent of organisations have such tools in place, as a new Quocirca report on DLP, to be published in early 2010, will show, and public sector organisations like the UEA CRU lag other industries in deploying it.

Government sponsored research units have an important job to do and, in some cases where their work may get in the way of others, they may become targets of criminal activity. While it is understandable that scientists are focused on their day-to-day work it's unacceptable when they are let down by poor IT security that, in this case, has been exploited to try and undermine the efforts of thousands of politicians trying to grapple with global society's most pressing problem. In this case, it looks like the attempt has failed, on another day it might not.

Reader Comments

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

Voipfone VoIP 30 Day FREE Trial Click To Sign Up Now


  • Feedback
  • | Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd. | Tel: 01908 880760