BreachExchange mailing list archives

Re: Oops: Auditor Loses McAfee Employee Data (fwd)


From: Chris Walsh <cwalsh () cwalsh org>
Date: Thu, 23 Feb 2006 14:20:37 -0600

It took Deloitte practically 3 weeks to figure out what was on the CD?
I don't want to see that consultant's dry-cleaning bill.  :^)

Here's an idea.  If you are a publicly-traded firm, TELL your external
auditors that they have to keep your data on encrypted media.  If they
give you a line of BS about it, have the head of your audit committee
call the managing partner at your external auditor.  The problem will
magically go away, and it will take one phone call.  Why firms allow 
themselves to be bullied by those they engage for professional
services mystifies me.  (yes, I know switching costs are huge...)

Chris


On Thu, Feb 23, 2006 at 02:56:48PM -0500, lyger wrote:

---------- Forwarded message ----------
Date: Thu, 23 Feb 2006 19:49:42 GMT
Subject: Oops:  Auditor Loses McAfee Employee Data

Via C|Net News.

[snip]

An external auditor lost a CD with information on thousands of current and 
former McAfee employees, putting them at risk of identity fraud.

The disc was lost on Dec. 15 by Deloitte & Touche USA, McAfee spokeswoman 
Siobhan MacDermott said Thursday. The Santa Clara, Calif.-based security 
software company was first notified on Jan. 11, and on Jan. 30, it received 
particulars of the data that may have been on the CD, MacDermott said.

The disc contained personal details on all current U.S. and Canadian McAfee 
workers hired prior to April 2005 and on about 6,000 former employees in the 
same region, MacDermott said. (The security company currently has approximately 
3,290 employees worldwide.) The information wasn't encrypted and potentially 
includes names, social security numbers and stock holdings in McAfee.

[snip]

More:
http://news.com.com/2100-1029_3-6042544.html

_______________________________________________
Dataloss mailing list
Dataloss () attrition org
https://attrition.org/mailman/listinfo/dataloss

_______________________________________________
Dataloss mailing list
Dataloss () attrition org
https://attrition.org/mailman/listinfo/dataloss


Current thread: