Tel: (416) 498-1550
info@osborne-group.com
FOLLOW US ON
Executive Leadership Toronto

Our Principals

Osborne Group Principals are flexible, experienced executives who fill senior-level positions in any functional area on an interim or contract basis.

Details

Functional Expertise

Osborne Insights Blog

Osborne Insights Blog

Elections Ontario and Security



The Osborne Group - Thursday, July 19, 2012

This week the news emerged that Elections Ontario has improperly managed the data of 2 million or so Ontario voters and has “lost” our personal data. Apparently back in April, a couple of USB drives went missing from an Elections Ontario office, and they contained information collected about voters provided during the election last fall.

First, we’re going to set aside the issue of timing – that this breach occurred back in April and the news is only coming out now. This feels to me like a pretty big gap in accountability, but that’s a topic for another day

Second, we’re also going to ignore the notion that the likelihood of the data being misused is low – apparently due to the specialized software used to manage this data. While this possibly is true, I would never underestimate the capabilities of a determined hacker to be able to decode the data.  Further, what data was lost and how much damage can be done with it is not really the point, particularly if you happen to be one of the people whose data was on the drives.

But more practically, what happened here?

It seems that a number of “paper procedures” had been established but were not followed by employees.  And no audits appear to have been done to ensure the procedures were being followed. And finally, it seems that the significance of securing this data was not sufficiently impressed on at least a couple of Elections Ontario employees.

What does this mean for your organization?

First, have some security procedures – including but by no means limited to:

Personal data about customer or clients or citizens should not be put on a USB drive as a matter of policy, and if there are some exceptional circumstances, they should be depersonalized or encrypted at minimum.

Strong passwords should be required to get into any system containing personal data, and users should be forced to change them regularly.

Encryption software for laptops should be installed and activated.

Materials should be secured when users are not there – screen locks, laptops and USB devices stored in locked drawers, and so on.

Secondly, test the procedures and audit users behavior.  If that means something as silly sounding as walking around the office and checking, just do it.  If phones or blackberries are supposed to be password protected, check them to make sure.

Finally, ensure staff know the procedures, understand why they are there and the implications of them not being followed (both to the organization and to them personally) as it is at the personal level that security is most effectively implemented.

Christy DeMont


Recent Posts


Tags

"need for volunteers" BOD "Electrical heat" "retirement homes" golf Technology Canada "new principal" Universities "Jenkins report" "job search" Psychology "Ian Glen" "john bielby" stakeholders Banker "West Jet" "bob cooke" "Not-for-Profit" Strategies value vacation "Bob Cooke" "ontario energy" "osborne group names new president" lender "Canadian Diabetes Association" Apple "David Rankin" taxpayer sustainability "Tiger Woods" sports "contract negoation" "Christy DeMont" budget "interim ceo" strategy "community support" "stewarding energy" "private business" "Risk Management" "Don Weaver" politics "Colin Powell" "bad news" "financial services" cbc experimental "interim management" "province of ontario" energy "American Heritage dictionary" ""small business" "Wired Magazine" "government policy" "GM Oshawa" "Dalton McGuinty" "Steve Jobs" "Bob Fisher" leader Government "fresh perspective" "Information technology" "Interim management" "Giuseppe Quintarelli" risk "Request for Proposal" weather Summer "nuclear power" negoation "communication plan" anniversary "Louboutin" "development program" SMEs hawkesbury Incentives "jane rounthwaite" "Canadian poetry" "frankenstorm" "Communications Audit" announcement "Organizational communication" "customer experience" entrepreneurs "earth rising" "business partners" Zipcar "John Bielby" CMO "paper procedures" "Stephen Covey" "Canadian flag" "shareholder value" thorsten "policy manual" "2012" history "new technology" "Janet Carnegie" marketing football "hydro one" "contract executive" "HR manager" "opportunity cost" "f-35 jets" negotiation "pareto principle" "Richard Taylor" "The value of time" "Ontario Health care" ontario utilities "athletic movement" "Ken Goodwin" "A leadership primer" mentorship "bidding process" RFP "Central Vermont" scientific vote "sally fazal" "Canadian Government" governance "Leonard Cohen" "conserve energy" Superbowl CIO "Rotman School of Commerce" customers "energy management" TFSA "Arthur D. Little" 'interim management" "Jane Rounthwaite" entrepreneur "Ray Kong" enterprises audit "password protection" "Teri Brown" "Super Bowl XLVII" "fossil fuel" "Fighter Jet" "news" "standard for quality" "Captial Conference" "risk elements" "Part time CFO" retirement executive volunteer communication "total cost of ownership" "Canadian utilities" "Direct Energy" english "family doctor" iPad "Ontario power authority" "energy conservation" "successful organization" "2012 Olympics" "Scott Percival" leadership "New Year's Resolution" leaders "Health care" "identifying solutions" Denmark "Donna Brazelton" "change initiatives" "business growth" "US Open" "National Retail Council" NHL "Queens Park" contractors "CEO" experiences "John Gundy" "non-profits" "career change" "senior executive" "Big Wind" "business goals" "Linda Hall" "business acquisition" Electricity "best employers" "Change Management" "Premier of Ontario" "Sir Fredrick Hoyle" science "voter security" The Masters "John Annett" Linkedin "smart phone" "Tim Cooke" "business plan" "Osborne group" "sustainable energy sources" "business valuation" "International Camping Fellowship" "Canadian Army" IT "Osborne Group" "board of directors" "Melodie Zarzeczny" Greece Olympics "Human Resources" "Occupy Wall Street" "Osborne Announcement" RIM "Community members" "Roy Thompson Hall" "electrical utilities" quality "energy assessment" beethoven HR policy "Shulich School of Business" "janet carnegie" "News Years resolution" "executive management" "interim executive" "customer service" "The Osborne group" "clear writing" "Canadian Business" "Winston Churchill" stakeholder "Elections Ontario" "British Open" "Eric preston" resources "business processes" hockey "Remembrance Day" balsillie Shelburne Volunteering Wikipedia "Globe and Mail" "leadership" "Board of Directors" "Ipsos Reid" fuel "Canadian Armed Forces" "interim CEO" "leadership skills" "ontario jobs" "business exit" "young entrepreneur" "Organizational health assessment" "business opportunity" "problem solving" networking 'interim executive" "financial goals" RRSP conservation President consultant "Mike Dick" "executive director" "corporate philosophy" "Chris Hadfield" Canadian "non-profit" "Sheila Hamilton" "The Osborne Group" "bob fisher" NRC acquisition CEO "procter and gamble" "Jet plane" "Ontario Premier" "Hydro One" "solar energy" spring CFO "ontario highschool students" "Christy Demont" "newpapers" "susan bihun" "Succession planning" "information technology" "board member" toronto "innovative communication" "Interim executive" Masters "Lile Jia" connections "Silverthorn collegiate"

Archive