• Skip Navigation |
  • Accessibility 
IT-Director.com Logo
  • Conficker grounds police checks
  • What's wrong with \
  • What is Total Cost of Ownership, and Why Should You Care?
 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • TIBCO is pleased to announce the availability of TIBCO Spotfire version 3.1.
    11th March
    Webinar (online)
  • Enterprise Social Media
    15th March
    London, United Kingdom
POPULAR PAPERS
  • Mobile Application Momentum by Quocirca
  • Telecoms reinvention - optimising the online customer experience by Quocirca
  • Enterprise Performance Management - Cycle II by Quocirca
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
INTERACT
  • Advertising
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "I regard you with an indifference bordering on aversion." - Robert Louis Stevenson

ADVERTISEMENT
Blogs > Quocirca

CRU email row highlights importance of data loss prevention

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 21st December 2009
Copyright Quocirca © 2009
Logo for Quocirca
Page Tools

Request Reprints
Tell A Friend
Contact Author

Recent Blog Posts
  • Can Novell thrive by being a jack of all trades?
  • Enterprise performance management - the story continues...
  • Keeping mobile data flowing
  • Making a pain go away
  • Mobile machine to machine (M2M) - is it worth having less to talk about?
  • Lotusphere 2010 - consolidation, and setting the future scene
Blog Archive
  • March, 2010
  • February, 2010
  • January, 2010
  • December, 2009
  • November, 2009
  • October, 2009
  • September, 2009
  • August, 2009
  • July, 2009
  • June, 2009
  • May, 2009
  • April, 2009
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

The recent theft of emails from the University of East Anglia Climate Research Unit (UEA CRU) has proved embarrassing, but the incident does not change any of the facts regarding global warming. New Scientist (9th Dec 2009) summaries it well:

"The emails suggest some of the scientists may have tried to shut out critics, which, if true, goes against advancing knowledge through open debate. On the other hand, the aim of peer review is to prevent substandard research from being published, so you could argue that the scientists were just doing their job because they felt the papers in question were not scientifically rigorous."

The full article is viewable here.

As a research company, albeit looking into matters not quite so prescient for the future of life on Earth, Quocirca can sympathise with New Scientist's view. Should our own email server be hacked, you would find discussions along the lines of "how can we present this in the best light", "this research seems to contradict previous research, how do we explain that?" and so on. This does not represent any attempt to falsify the findings, but just ensuring a reasoned interpretation provides an understanding of how, in the complex markets Quocirca covers, contradictions occur and what they mean. Once work is published findings have to be explained, justified and defended.

However, one thing most people will agree on is that emails that were meant to be private are best kept that way. The Norfolk Police are investigating the crime that led to all this, but it seems that the UEA CRU was targeted by persons unknown with the specific aim of undermining the Dec 2009 Copenhagen Climate conference. For an outsider with malicious intent to gain access to private email servers suggest poor security somewhere along the line, perhaps finding a privileged back door, which can be all too easy (see Quocirca free report, Privileged User Management, Nov 2009). However the theft was perpetrated, it should have been preventable.

Of course, it may be that someone chose to leak the email. The volume involved (thousands of emails and other documents) would have shown up as anomalous behaviour had data loss prevention (DLP) software been in place (see Quocirca free report, Content security for the next decade, Nov 2008). Only about 25 per cent of organisations have such tools in place, as a new Quocirca report on DLP, to be published in early 2010, will show, and public sector organisations like the UEA CRU lag other industries in deploying it.

Government sponsored research units have an important job to do and, in some cases where their work may get in the way of others, they may become targets of criminal activity. While it is understandable that scientists are focused on their day-to-day work it's unacceptable when they are let down by poor IT security that, in this case, has been exploited to try and undermine the efforts of thousands of politicians trying to grapple with global society's most pressing problem. In this case, it looks like the attempt has failed, on another day it might not.

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)1908 880760 | F: +44 (0)1908 880761