<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com &#187; breach</title>
	<atom:link href="http://paulmudgett.com/tag/breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Thu, 05 Jan 2012 17:32:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Self-inflicted&#8230; the ongoing saga</title>
		<link>http://paulmudgett.com/2011/03/28/self-inflicted-the-ongoing-saga/</link>
		<comments>http://paulmudgett.com/2011/03/28/self-inflicted-the-ongoing-saga/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 19:00:15 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=351</guid>
		<description><![CDATA[I could have sworn I was in a Dilbert cartoon when I got a phone call over the weekend from a small business owner who claimed a system on our network was attacking him.   The conversation went something like this: Him:  &#8220;Your system has been attacking me on port 3389&#8243; Me:  &#8220;Port 3389?  Did [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/03/28/self-inflicted-the-ongoing-saga/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t Rely on Others to Protect Your Assets</title>
		<link>http://paulmudgett.com/2010/12/29/dont-rely-on-others-to-protect-your-assets/</link>
		<comments>http://paulmudgett.com/2010/12/29/dont-rely-on-others-to-protect-your-assets/#comments</comments>
		<pubDate>Wed, 29 Dec 2010 17:29:47 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Workstation Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=309</guid>
		<description><![CDATA[A company has a PC infected with malware that steals the User ID and password for their bank account.  The bad guys proceed to steal a large sum of money from the company bank account.  The bank won&#8217;t refund the money and the FDIC doesn&#8217;t insure commercial accounts.   This sums up a recent case described [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/12/29/dont-rely-on-others-to-protect-your-assets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lawsuit, breaches and bashing&#8230; oh my!</title>
		<link>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/</link>
		<comments>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 17:39:38 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=129</guid>
		<description><![CDATA[Though it seems obvious that corporations have an obligation to protect the sensitive information they use for business it still amazes me that corporate behavior in this regard is still quite dismissive.  Lawsuits and public embarrassment seem to be the only catalyst for action for many organizations.  That is kind of sad.  Not only is [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons in Due Diligence</title>
		<link>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/</link>
		<comments>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 19:24:41 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=106</guid>
		<description><![CDATA[An article by Kim Zetter on Wired.com caught my attention:  &#8220;Restaurants Sue Vendor for Unsecured Card Processor&#8221;. The gist is that several restaurants purchased Point-of-Sale (POS) systems from a particular vendor.  These POS systems that were sold were apparently not Payment Card Industry &#8211; Data Security Standard (PCI-DSS) compliant and that resulted in a breach [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Failures in Leadership, Ethics, and Security</title>
		<link>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/</link>
		<comments>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 18:25:19 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=103</guid>
		<description><![CDATA[A breach of patient personal information at University Medical Center has all the makings of a made for TV movie or at least provides an opportunity to examine issues in security, leadership, ethics, and even the knee-jerk reaction of ignorant politicians trying to use the opportunity to score some free publicity.  The story &#8220;FBI looking [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>It&#8217;s Just One Little E-mail&#8230;</title>
		<link>http://paulmudgett.com/2009/08/06/its-just-one-little-e-mail/</link>
		<comments>http://paulmudgett.com/2009/08/06/its-just-one-little-e-mail/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 20:55:38 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=31</guid>
		<description><![CDATA[How often is e-mail used to send documents and information that contains sensitive information?  I&#8217;ve seen consultants share sensitive information about clients this way as well as staff members just &#8220;trying to be helpful&#8221;.  I&#8217;m sure this happens all the time and it can be mitigated through training and providing staff the tools necessary to [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/08/06/its-just-one-little-e-mail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Ethics May Actually Still Exist</title>
		<link>http://paulmudgett.com/2009/06/09/business-ethics-may-actually-still-exist/</link>
		<comments>http://paulmudgett.com/2009/06/09/business-ethics-may-actually-still-exist/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 20:23:32 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Ethics]]></category>
		<category><![CDATA[breach]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=14</guid>
		<description><![CDATA[T-Mobile is investigating a claim that customer data was stolen and attempts made to sell the information to their competitors.  While data breaches unfortunately seem common, the good news from this story is that T-Mobile&#8217;s competitors apparently denied the offer of the theives.  This whole story may be hogwash but even the idea that ethics [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/06/09/business-ethics-may-actually-still-exist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

