Over 60 percent of all data leakage takes place due to employees, either
carelessly or intentionally. Indian companies are still very complacent about
this state of affairs and the risk it poses to their business health. So if they
are your customers then wake them up before it's too late
Scenario 1: A company hires a senior management employee for what it thinks
is a steal package and the latter is given access to some key information about
its growth and investment plans. Six months later the person quits the company,
and takes away valuable information about the company, which is when the
promoters of the company realize that he was an industrial spy used by their
competitors to get inside information about their operations.
Scenario 2: A leading pharmaceutical company rolls out marketing plans to
launch a new medicine six months down the line and has already started
production. Just a month before the launch date a competitor launches the same
medicine sans the fanfare and gains crucial marketshare and first mover
advantage. On checking its IT assets the first company realizes that a lot of
information about its product plans had been accessed by some employees who had
either inadvertently or knowingly left it lying around making it convenient for
the information to be picked up by hackers.
Before you dismiss these above two cases as something that happens in a Tom
Cruise-starring Hollywood potboiler here is the catch-this has happened closer
home. It took place in India and the two companies mentioned above are actual
customers of Mumbai-based Orient Technologies.
/dqc/media/post_attachments/c83bf987828ad426296a664fd929a8d8a286784942dc068e248005e22debe74f.jpg)
In fact, so shaken was the MD of one of the companies after the incident that
he has agreed to sanction a budget of Rs 10 crore to ensure that information is
safeguarded and can't be leaked. And this when his entire IT infrastructure is
also worth that amount!
Welcome to the world of data leakage. Industrial espionage is now here to
stay and has information technology to piggyback to get results. And it is not
just the paranoid who are investing in it globally; the technology has become an
accepted security protocol for most enterprises in the US and Europe.
Why the sudden interest?
Data leakage by itself is a very vast field encompassing many aspects of
information protection. Gartner calls it content monitoring and filtering, while
others call it simple data loss prevention. According to an IDG report
commissioned by Trend Micro in February 2008 with a random sample of 100
mid-sized companies, 86 percent of the respondents stated that data leakage is a
physical or virtual breach of confidential or proprietary content occurring
either as a result of malicious intent or mistake; while 76 percent maintained
that data leakage is when content meant only for need-to-know individuals falls
into the hands of someone who is not classified as need to know.
While the definitions are converging what data leakage essentially signifies
is prevention of information being leaked from a network of connected users from
any domain, either knowingly or inadvertently. As the threats started emerging
more from external sources to the internal ones, the concept of data leakage
gained ground.
The survey stated, “Although there is always the potential threat of
malicious outsiders hacking into company systems and gaining access to
proprietary or confidential information, businesses generally feel well
protected against these intruders with traditional firewalls and anti-virus
software. Companies are finding that the most challenging sources of data
leakage are internal, most often as a result of employee mistakes or
carelessness. Without the proper security measures in place, employees can
unknowingly put extremely important data at a very high risk of accidental
exposure.”
According to a report by the Aberdeen Group, the risk of data loss comes from
all types of data, from innumerable 'channels' for potential leakage, and from
end-user behavior ranging from inadvertent, to well-intentioned, to malicious.
Said Niraj Kaushik, Country Manager-India and SAARC, Trend Micro, “When data
leakage began as a concept it focused more on the periphery of an organization's
boundaries. It is only now that data leakage is happening at individual employee
levels and its focus has shifted to end point products like CD-Roms, desktops,
laptops, USB drives and mobility devices.”
How does it take place?
With a world, which is slowly going digital a lot of information is stored
electronically making it susceptible to be lost, stolen or misplace. Most of the
time this information is a happy resident on network systems as data bits and
bytes and is also traveling on the very networks, in the form of e-mails, or are
saved on network extension devices like thumb drives, CDs, laptops, mobiles etc.
Any network that has an USB port and or CD writer on user machines or provides
access through VPN for mobile products stands the risk of having its data
leaked.
![]() | ![]() |
| We educate our customers about the need to be sensitized about the vulnerabilities of the data that resides on their machines and how it can be leaked Nityanand Shetty | Companies have to realize that just because they have an anti-virus solution or a firewall or a UTM, that will not take care of the problem of data theft or leakage Sunil Sapra |
According to the IDG report 63 percent of the survey respondents said that
internal employee mistakes or carelessness is by far the most frequently cited
reason for data leakage. This is distantly followed by mishandled or mislabeled
proprietary information, which can be pegged at 12 percent, external malicious
intent at 10 percent and internal malicious intent at five percent.
Most CIOs today are working out ways and means to make their networks
accessible for various mobility devices like USB drives, mobile handsets and
laptops. Since they offer the benefit of convenience most users too prefer just
copying data on the fly using these devices and then work remotely.
So how does the CIO ensure that this data is secure and not misused by
employees or some other people with malicious intents? With the increasing
number of laptop thefts, how can the CIO ensure that the data residing on the
laptop does not fall into the wrong hands?
It is not possible for a CIO to shut out an employee from the network because
that will impact productivity. So how do you deal with the 30 percent of
security threats which are usually due to internal sources, who might be
accessing the wrong website, downloading content with Trojans in the background
or sharing files over unsecured networks?
A US study found that companies estimate nearly one in five outgoing e-mails
(19 percent) contained content that poses a legal, financial or regulatory risk.
“The most common form of non-
compliant content is e-mail that contains confidential or proÂprietary business
information (30 percent) followed by adult, obscene, or potentially offensive
content (25 percent) and personal healthcare, financial or identity data which
may violate privacy and data protection regulations (20 percent),” the study
said.
In 78 percent of the incidents, the insiders were authorized users with
active computer accounts at the time of the incident; in 43 percent of the
cases, the insider used his or her own username and password. Only 23 percent of
the insiders were employed in technical positions, with 17 percent of the
insiders possessing system adminisÂtrator/root access within the organization.
“Most insiders were motiÂvated by financial gain, rather than a desire to
harm the company or information system; other motives included revenge,
dissatisfaction with company management, culture or policies, and a desire for
respect,” the report specified.
| How good data leakage policies helped some global companies |
Source: Aberdeen Group |
A pain area?
According to the IDG-Trend Micro report, while one in five respondents
(which comes to 19 percent) reported that their companies experienced data
leakage in 2007-08, 32 percent were unsure. Among those who have experienced
data leaks, almost 60 percent report that these breaches were from internal
sources.
Sadly, there are no official figures available on the number of data leakage
cases that have taken place in India over the past few years. This does not mean
that data leakage is not happening on a large scale. It simply means that very
few of these are reported.
There are several reasons for this. One of them is that any organization
accepting to a data leakage will find it credibility questioned, especially if
it is from the BFSI segment.
“The second is that there are no disclosure regulation policies in India,
unlike the stringent ones that exist in the West,” said Vishal Gupta, Director,
Seclore, which offers IPR protection solutions. In India, if an organization
loses customer data then they do not have any legal obligation to declare the
same to the customers, which is why such cases never come to light.
Of course there is a need for stricter laws, because the depth and amount of
the data theft that happens is not known. Gupta maintained for all apparent
reasons the volume of data leakage taking place in India would be far more than
the West, but is never known because the cases are not reported. It is a classic
case of sweeping more and more of the cases under the carpet till some day the
carpet itself is shredded to pieces.
Preventing data leakage
The most effective strategies for preventing data loss include a combination
of enabling technoÂlogies, including data discovery and classification; data
monitoÂring and filtering; and endpoint data protection. Another step is
extrusion prevention, which stops unauthorized transfer of files or information
based on a set of rules or policies.
According to an Aberdeen Group study, over the last year “Best-in-class
organizations experienced 27 percent fewer data loss incidents than the industry
average from trusted internal users, and 92 percent fewer data loss incidents
attributed to malicious outÂsiders,” once they had deployed data leakage
policies and solutions.
![]() | ![]() |
| If a CEO sees the value in data leakage solutions he can decide if the organization should invest in it or not, cutting the sales cycle shorter for the solution provider Ajay Sawant | Right now, there is no access control protocol or any profiling done about the nature of data that can be accessed by any source within the network, which is dangerous Sam Ghebranious |
But these technologies can work only if the end-users take the trouble to
apply it and use it properly and it is made a way of life in the organization
and is strictly enforced. Effective prevention of data leaks needs to start with
good security awareÂness, which does not mean that everything is put under lock
and key, but there people using the information realize the associated risks of
sharing information.
There are several knee-jerk reactions that enterprises implement when they
suffer from data leakages. These could include blocking all USB ports or
encrypting the hard disk drives. In the latter case, even if a laptop gets
stolen the CIO is assured that the data residing on it can't be hacked.
Some organizations even disallow mobiles to get connected to the wireless
network. “There are even cases where only an approved model of handset like a
Nokia N73 is permitted to be connected to the network and all other handsets do
not get the permission,” a partner stated. These kind of standardizing policies
might have a negative impact on productivity because an employee might lose his
mobile and have to work with another model as its replaceÂment. If he is off the
limits of the network, his work would suffer.
Additionally these are low-budget security measures that some SMB customers,
who just want to protect their data, might undertake. But it does not constitute
a planned data management plan.
Need of the day
What is needed to avoid data theft is ensuring that the data is mapped to
find out its criticality and then design policies accordingly. According to
Vishal Gupta of Seclore, it is pertinent to audit the existing data on the
network for vulnerabilities, so that these can be plugged.
There is also a need for specialized security solution providers (SPs) who
are trained on this technology. These partners should have certain amount of
intensive training and consulting expertise in data classification. This is to
underÂstand what is important data and what isn't. For instance, a company's
pricelist is an important document, but is it confidential? No. Similarly, the
company's customer database might not be confidential, but is it critical? Yes.
But Niraj Kaushik of Trend Micro is quick to point out that this does not
mean that information leakage is rocket science and needs lot of intensive
training. “Most data leakage solutions currently available in the market can be
plugged into the existing security blanket that partners offer to their
customers,” he said, adding, “What is more critical is knowing how to sell this
technology to customers.”
This is why while working with companies for creating security policies, SPs
should not work with the CIOs alone; they should involve the CEOs as well. This
is because data leakage is not merely an IT problem, it is an organization flaw
that needs to be corrected and the value for safeguarding this data has to be
shown to the promoter of the business.
“Often a CIO might decide that the solution is relevant, but the finance or
accounts head might feel that investing in it is frivolous and therefore the
proposal might get shot down. So if a CEO sees the value he can decide if the
organization should invest in data leakage solutions or not, cutting the sales
cycle shorter for solution providers,” added Ajay Sawant of Orient Technologies.
Kaushik too agreed with this viewpoint.
Sam Ghebranious, Senior Sales Director, Lumension Security felt that it is
important for enterprises to wake up to the idea of white listing their network.
“Right now, there is no access control protocol or any profiling done about the
nature of data that can be accessed by any source within the network, which is
dangerous. Enterprises might shrug off the risk of not having a white listing
protocol today, but they will wake up to its disastrous results tomorrow,” he
added.
| What was the primary source for the data leaks? |
![]() |
| Source: IDG-Trend Micro, February 2008 |
Like Sunil Sapra, Country Manager-India ad SAARC, Watchguard Technologies
stated, “Just because I have more knowledge about technology or work in a
technology domain, does not mean that it makes me impervious to any data
attacks.” Similarly companies have to realize that just because they have an
anti-virus solution or a firewall or a UTM, that will not take care of the
problem of data theft or leakage.
Good news for SPs?
Content monitoring has taken over the spotlight from firewalls and intrusion
prevention because CIOs are very concerÂned about data loss prevention. This is
good news for solution providers (SP) who are looking at upscaling themselves to
offer the next level of services to their customers. They can work on
organizations to enable them to take an information-centric approach to
protecting sensitive data, using a combination of network-based and
endpoint-based solutions to prevent data loss.
One SP gave an example of how an MNC bank came into India through a joint
venture it was reluctant to hand over its infrastructure manageÂment business to
a third party in India. This was because it had some global IT practices, which
it felt that Indian partners could be flippant about the data on the systems.
They would often manage the infrastructure remotely. It was only when there were
onsite services that the MNC bank's CTO decided to give some level of authority
to the Indian SP for managing the network locally.
This instance indicates that sometimes when companies get into alliances with
global MNCs either through mergers, acquisiÂtions or joint ventures, they have
to align their network practices to those of the global entity. Since most
global organizations have an established data protection policy, they would
expect the same from their Indian business partners.
So any Indian organization which has plans for global tie-ups will have to
scale up their network to have data protection and privacy policies, which in
turn is a good sales pitch for (SP) solution providers to make to their
customers.
At the end of the day, selling the concept of data leakage practices is like
selling health insurance. Nityanand Shetty of EssenVision Software noted that
just because a person has paid his health insurance premiums it does not mean
that he will go bungee jumping without a harness.
“The same logic applies to data leakage solutions. Just because a company has
some protocols set for preventing data theft or loss, it does not mean they have
to become complacent about it. We make it a point to educate the users of our
enterprise customers about the need to be sensitized about the vulnerabilities
of the data that resides on their machines and how it can be leaked,” he added.
The likely challenges
Most of the adopters of data leakage solutions are the larger enterprises,
especially in the BFSI segment, who are known as technovators. Seclore currently
has three leading banks in India, which have implemented these solutions.
But most other companies are not as quick on the uptake for these solutions.
This is often because most companies have a lot of unstructured data pracÂtices,
especially in developing nations like India.
Most SMB customers, when informed about data leakage solutions, are sold on
the concept and the technology. But few of them actually deploy it on their
network.
“One reason for this could be that most SMB customers seek a solution which
give them a tangible RoI, which data leakage can't offer because it is something
that safeguards your data but does not make you invincible to any future loss,”
he explained.
He also blames the reactive nature of Indian customers who rush to buy a
solution only when they have encountered a problem. Sapra too agreed to this
viewpoint and mentioned that he had once come across a company which had gone
for encryption of hard disk on the laptops of the key management after the
laptop of the company's MD was stolen. Gupta called it the “incident-based
reactive reflex in panic mode.”
The other challenge is matching the expectations of customers. Additionally,
since there are also no actual numbers of the number of data leakage instances
in India, most customers live in the belief that these incidents either happen
rarely or happen to only the larger enterprises, which makes it even more
difficult to convince them to adopt it.
But in a 2007 study conÂducted by Datamonitor, more than 60 percent of
enterprises globally surveyed have experiÂenced data leakage within the year,
and 33 percent believe it could put them out of business.
In the background of non-existing disclosure norms it is difficult to find
similar data for India. Though data leakage has the potential to impact business
adversely, it often goes unchecked in the country. “Unless it is not driven by
business needs, no organization goes for data leakage solutions because there
are no penal, fiscal, RoI or liability concerns,” noted Kaushik.
But this does not mean that it will not become a mainstay in the future.
Kaushik believes that in another two years this technology will become an
accepted practice in the industry. He added that in the case of Trend Micro,
some trials have started happening with SMB customers as the cost of doing
pilots there is very small. Companies will start opting for data leakage
solutions, but in a gradual stage-by-stage fashion.
VINITA BHATIA
vinitavs@cybermedia.co.in
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us/dqc/media/post_attachments/416e8611697c7c3c745b557378916182d9cee3d685dcc4325d3ad2a73ad0b20d.jpg)
/dqc/media/post_attachments/60c936430cdedd7640c04c384794ef9e76190aef8d265e102c51bc18bee8b061.jpg)
/dqc/media/post_attachments/cfb96f373c847d0dea4a78c20c283871f6ae6fda56f2b4a3049618c1f7c3a29c.jpg)
/dqc/media/post_attachments/5148f9b7a66c40ffddd0d48526eed2e168da929947179350239cd6165f09f78c.jpg)
/dqc/media/post_attachments/813485ecb37d2467375d23a1229331acc0bb2c0fdedf5cbee741fe487fde114d.jpg)