Most Popular Stories
- Q&A: Disaster recovery when your business sits on the San Andreas Fault
- Content Marketing could be supplanting the traditional corporate blog
- Enterprise architecture at Chubb Insurance
- CFO has a role to play in ERP rollouts
- Content is the new gold
- Help desks get help at Peugeot, De Beers and University of Georgia
- A 'mobile help desk' in every pocket, from Salesforce.com
- Apple co-founder Wozniak sings Android's praises
- Four ways to better manage IT sales calls
- Section 508 web accessibility rule to change
- Survey finds many users blow by SharePoint security
- How hackers can eavesdrop on prevalent videoconferencing systems
Events
- MDSL Smart TEM US Roadshow
New York Feb 21 | Houston Feb 22 | Chicago Feb 23 - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - CIO Summit
March 18- 21 — Miami, FL
Sponsored Links
Free Newsletter
HOT TOPICS >> Tech world's top flops and fiascos of 2011 | Windows 8 slideshow | Cybersecurity | Caron's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
FierceCIO provides CIOs with IT best practices, business intelligence, and forward-looking IT strategies. Join 32,000+ industry insiders who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Ensuring Cultural Adoption
- Making Change Stick
- Penetration Testing with Metasploit Framework
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
Heartland CIO: "I don't think software will ever be secure again."
Heartland Payment Systems isn't necessarily synonymous with "great security," these days. The company's colossal data breach, in which as many as 130 million credit and debit card numbers were compromised, has cost it $139.4 million so far. Approximately 18 months ago, Steven Elefant took over as CIO, and, perhaps unsurprisingly, much of his job is focused on encryption technology.
One of the bigger security challenges at Heartland is developing hardware encryption technology because encryption provided solely through software is no longer adequate, Elefant said in an interview with Ed Sperling at Forbes. The personal data of individuals using credit cards must be protected from the time they swipe their cards until they complete their way through Heartland's processing system.
"I don't think software will ever be secure again. With hardware you can create what we call a tamper-resistant security module. If you try to crack it or drill it or open it you'll wipe out the keys and make it unusable. But unless you do it in hardware you don't have complete security," he said.
Data in motion is the most vulnerable, and hacking by organized crimes is a "huge threat," Elefant said. Hacking tools such as screen scrapers, CPU scrapers and memory scrapers make it imperative to integrate logical and physical security measures.
While security measures take a considerable investment, they can give a company a competitive advantage, he said. Merchants face not only a hit to their reputation, but also fines and fees, if their data is breached. Heartland is trying to set itself apart in the payment processing business with its attention to security now.
The cost of Heartland's huge data breach includes a settlement for almost $60 million with Visa, $42.8 million for other proposed settlements and about $26 million in legal fees, reports Jaikumar Vijayan at ComputerWorld.
For more:
- read Ed Sperling's article at Forbes
- read Jaikumar Vijayan article at ComputerWorld
Related Articles:
U.S. data breach = $204 per lost record
Heartland embraces encrypted payment system
Heartland settles with American Express
A plea in the massive Heartland breach case
Related Stories
- Data breach at SoSasta, Groupon's Indian subsidiary, reveals security negligence
- BP loses oil, now personal data
- Cops and your company's smartphones
- Heartland embraces encrypted payment system
- A plea in the massive Heartland breach case
- Heartland's CEO: Lessons from a bad data breach
- Teachable moments from the Zappos breach
- Cyber insurance decisions require IT's input
- The pros and cons of information sharing
- Intrusion protection: Best of breed or integrated solution?
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




