Even before her state of California put a stake in the ground regarding public disclosure of data breaches, Christy Quinlan could see the wisdom in encrypting client data on mobile devices. Shortly after Quinlan became CIO of California's Department of Health Care Services in 2005, one of the agency's partners lost a computer. The contractor had to notify everyone who might have been affected, at a cost of several hundred thousand dollars: And while Quinlan's staff had not lost the laptop, they still spent much of the week before a holiday coordinating with the contractor to determine the possible scope of the security breach and then ensuring swift and proper notification. "Once information is on the loose, you can never get it back," Quinlan says.
California eventually created a state law that required the public disclosure of data breaches (quickly followed by most other states). But ironically, at the time of Quinlan's contractor incident, the state was still trying to figure out the right internal policies to protect data across its many agencies.
Issues include deciding what should be encrypted, how to recover the passwords that unlock encrypted data when users lose them or leave the company, and how to make passwords available to backup and client management software
As it turns out, the encryption effort proved less difficult than she'd feared, thanks to systems and infrastructure already in place. The agency had recently updated its laptops to support Windows XP, providing sufficient computing and storage capabilities as well as an operating system to support enterprise-class encryption software. And the agency had a client management system in place to update users' laptops with new software and enforce encryption and other security policies automatically.
CIOs should take Quinlan's experience to heart, says Paul Kocher, president and chief scientist of consulting firm Cryptography Research. "Anyone not doing it has no excuses anymore," Kocher says: Encryption technology is now widely available and proven.