Tel: (416) 498-1550
info@osborne-group.com
FOLLOW US ON
Executive Leadership Toronto

Our Principals

Osborne Group Principals are flexible, experienced executives who fill senior-level positions in any functional area on an interim or contract basis.

Details

Functional Expertise

Osborne Insights Blog

Osborne Insights Blog

Elections Ontario and Security



The Osborne Group - Thursday, July 19, 2012

This week the news emerged that Elections Ontario has improperly managed the data of 2 million or so Ontario voters and has “lost” our personal data. Apparently back in April, a couple of USB drives went missing from an Elections Ontario office, and they contained information collected about voters provided during the election last fall.

First, we’re going to set aside the issue of timing – that this breach occurred back in April and the news is only coming out now. This feels to me like a pretty big gap in accountability, but that’s a topic for another day

Second, we’re also going to ignore the notion that the likelihood of the data being misused is low – apparently due to the specialized software used to manage this data. While this possibly is true, I would never underestimate the capabilities of a determined hacker to be able to decode the data.  Further, what data was lost and how much damage can be done with it is not really the point, particularly if you happen to be one of the people whose data was on the drives.

But more practically, what happened here?

It seems that a number of “paper procedures” had been established but were not followed by employees.  And no audits appear to have been done to ensure the procedures were being followed. And finally, it seems that the significance of securing this data was not sufficiently impressed on at least a couple of Elections Ontario employees.

What does this mean for your organization?

First, have some security procedures – including but by no means limited to:

Personal data about customer or clients or citizens should not be put on a USB drive as a matter of policy, and if there are some exceptional circumstances, they should be depersonalized or encrypted at minimum.

Strong passwords should be required to get into any system containing personal data, and users should be forced to change them regularly.

Encryption software for laptops should be installed and activated.

Materials should be secured when users are not there – screen locks, laptops and USB devices stored in locked drawers, and so on.

Secondly, test the procedures and audit users behavior.  If that means something as silly sounding as walking around the office and checking, just do it.  If phones or blackberries are supposed to be password protected, check them to make sure.

Finally, ensure staff know the procedures, understand why they are there and the implications of them not being followed (both to the organization and to them personally) as it is at the personal level that security is most effectively implemented.

Christy DeMont


Recent Posts


Tags

golf connections "business growth" "Canadian Army" Electricity "frankenstorm" "non-profits" "Chris Hadfield" "fresh perspective" "Globe and Mail" Canada negoation experimental "Osborne Announcement" "osborne group names new president" "Canadian Government" beethoven "New Year's Resolution" 'interim management" "Hydro One" "Occupy Wall Street" "Ray Kong" energy taxpayer "paper procedures" "business partners" "Tim Cooke" "business opportunity" "total cost of ownership" value "Janet Carnegie" "financial goals" "Ken Goodwin" IT "Osborne Group" leader networking "Sheila Hamilton" "need for volunteers" audit "business plan" "John Annett" Psychology "Bob Cooke" "development program" Strategies "The Osborne Group" Greece "news" "Ian Glen" "communication plan" "Captial Conference" hawkesbury "David Rankin" "Human Resources" NHL entrepreneur "Remembrance Day" "sustainable energy sources" contractors "Board of Directors" "policy manual" "innovative communication" "business acquisition" "CEO" "2012 Olympics" weather "fossil fuel" Superbowl "career change" communication "bad news" politics "sally fazal" "identifying solutions" "financial services" "business exit" "Canadian Armed Forces" "John Gundy" marketing english "business goals" "province of ontario" "pareto principle" Zipcar "business processes" "jane rounthwaite" "executive director" "GM Oshawa" anniversary "Fighter Jet" "National Retail Council" Linkedin "energy management" "best employers" policy sports "News Years resolution" "ontario energy" customers "solar energy" "board member" BOD "US Open" "Bob Fisher" quality "smart phone" executive toronto 'interim executive" "stewarding energy" "HR manager" "Not-for-Profit" "nuclear power" "Ontario Health care" mentorship "janet carnegie" "Direct Energy" "non-profit" "Part time CFO" governance Shelburne vacation "Don Weaver" Volunteering "Leonard Cohen" "family doctor" "Sir Fredrick Hoyle" "Interim executive" "Canadian flag" "Dalton McGuinty" "Canadian utilities" "government policy" "board of directors" "Jet plane" Olympics "Canadian Diabetes Association" "Change Management" ontario CMO "Premier of Ontario" "risk elements" "Jane Rounthwaite" RRSP "contract executive" "community support" "Mike Dick" HR "Teri Brown" "Canadian poetry" "successful organization" "Lile Jia" "bob fisher" "Risk Management" "Tiger Woods" leadership "executive management" "change initiatives" RFP acquisition "clear writing" balsillie "Winston Churchill" risk "problem solving" "standard for quality" "Shulich School of Business" "bidding process" "interim management" "contract negoation" "Canadian Business" volunteer "Information technology" spring consultant "leadership skills" experiences The Masters "procter and gamble" retirement "electrical utilities" "Christy DeMont" Government "Wired Magazine" NRC "conserve energy" "Queens Park" Incentives "Donna Brazelton" "Osborne group" "corporate philosophy" "job search" "new principal" CIO "Silverthorn collegiate" Banker vote "customer experience" stakeholder Masters "Health care" CFO SMEs "Roy Thompson Hall" "Organizational communication" "The value of time" "Jenkins report" "West Jet" "Electrical heat" "information technology" stakeholders leaders "voter security" history "Central Vermont" Apple negotiation "Christy Demont" conservation "The Osborne group" "senior executive" thorsten "bob cooke" "interim CEO" "Richard Taylor" Summer utilities "f-35 jets" "hydro one" scientific "earth rising" budget "Interim management" TFSA "newpapers" "Giuseppe Quintarelli" President "john bielby" "ontario highschool students" "opportunity cost" enterprises "International Camping Fellowship" "Steve Jobs" CEO "Community members" "British Open" "password protection" football Technology Denmark RIM "athletic movement" "business valuation" "Ontario Premier" "Ipsos Reid" "energy assessment" "new technology" Wikipedia "Big Wind" "2012" "young entrepreneur" "interim executive" "leadership" "energy conservation" "Elections Ontario" Universities lender entrepreneurs iPad "American Heritage dictionary" science "Louboutin" cbc "private business" announcement "Arthur D. Little" "shareholder value" "retirement homes" "customer service" "Ontario power authority" ""small business" "Melodie Zarzeczny" "Communications Audit" "John Bielby" "ontario jobs" "Rotman School of Commerce" Canadian "Request for Proposal" "interim ceo" "susan bihun" resources fuel "Succession planning" "Eric preston" "Linda Hall" strategy "Super Bowl XLVII" hockey

Archive