<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: nsk]]></title>
    <link>http://securityratty.com/tag/nsk</link>
    <description></description>
    <pubDate>Mon, 11 Feb 2008 08:11:51 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Insecure folder on NSK Americas' internal network]]></title>
      <link>http://securityratty.com/article/722bff3a91e4e0118c01d2b709b53c89</link>
      <guid>http://securityratty.com/article/722bff3a91e4e0118c01d2b709b53c89</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/25/08

Organization
NSK Ltd

Contractor/Consultant/Branch
NSK Americas, Inc

Victims
NSK employees, past employees, and retirees

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/nsk.jpg" align="right" height="64" width="142"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/25/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.nsk.com/index.html" target="_blank"> NSK Ltd.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.am.nsk.com/public/enu/index.asp?rg=am&amp;lg=enu" target="_blank"> NSK Americas, Inc.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>NSK employees, past employees, and retirees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~2,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, Social Security numbers, and salaries<br><br><span style="font-weight: bold;">Breach Description:</span><br>NSK Americas has reported a breach to the New Hampshire State Attorney General in which a folder containing sensitive personal information was found to be inadequately secured on their internal network.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/NSK.pdf" target="_blank"> The New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>NSK Americas, Inc. recently became aware that a computer folder containing employee<br>data on our internal corporate server was not properly secured<br><br>The affected folder included the names, Social Security numbers and salaries of approximately 2,000 current, former and retired employees<br><br>The affected folder was on an internal NSK server which was not accessible by non-NSK employees<br><br>We immediately secured the affected folder and launched an investigation to detennine the facts.<br><br>We promptly retained Kroll On-Track, an industry-leading security consulting firm, to help us. As a part of this investigation and with the assistance of Kroll, we conducted a detailed review of all network logs to determine if the information was inappropriately accessed or downloaded to personal computers.<br><br>Based on our investigation, security for this particular folder was likely compromised due to an IT administrative error when information was migrated to a new server in June 2006.<br><br>Based on our corporate IT infrastructure, only 360 people out our employee population of 1,600 would have been able to access this document<br><br>As of now, we have confirmed that only a few employees gained access to the data file without authorization.<br><br>In addition, we are working with Kroll to determine if any other corrective or improved security measures are necessary.<br><br>we have also contracted with Kroll ID TheftSmart firm to provide credit monitoring and other related services at no cost to our employees<br><span style="font-style: italic;">[Evan] Sounds like Kroll got some good business out of this breach.&nbsp; I have never worked with Kroll, so I don't know enough to comment.</span><br><br>NSK is committed to never compromising your personal information. We have a zero tolerance privacy policy and do everything we can to make sure your data is protected.<br><br><span style="font-weight: bold;">Commentary:</span><br>NSK deserves credit for doing the right thing security-wise.&nbsp; Did they do the right thing business-wise?&nbsp; How many companies encounter similar circumstances during their day-to-day operations that simply overlook it as a non-incident worthy or reporting?<br><br>Based on this response and the retention of outside help, NSK has demonstrated that they are willing to do what it takes to secure personal information. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/11/nsk.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 11 Feb 2008 08:11:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nsk americas">nsk americas</category>
      <category domain="http://securityratty.com/tag/nsk">nsk</category>
      <category domain="http://securityratty.com/tag/nsk employees">nsk employees</category>
      <category domain="http://securityratty.com/tag/non-nsk employees">non-nsk employees</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/secure personal information">secure personal information</category>
      <source url="http://breachblog.com/2008/02/11/nsk.aspx">Insecure folder on NSK Americas' internal network</source>
    </item>
  </channel>
</rss>
