Survey Finds Widespread Data Breaches
Dec 31st, 2007 • Posted in: Statline
Editor’s Note: Deloitte is a corporate sponsor of Ethics Newsline®
For more information, see this week’s Research Report.

Editor’s Note: Deloitte is a corporate sponsor of Ethics Newsline®
For more information, see this week’s Research Report.
by Rushworth M. Kidder
The other day a newspaper editor rang up. She was writing a preview of the coming year and wondered what ethical hotspots I saw emerging in 2008.
Great question. But as I thought about her request, I realized that ethics is less about places and events than about characters and ideas. The real question is, What overarching ethical trends are developing in 2008, and what moral qualities will be needed most as we move forward?
Glancing over the columns I’ve written this past year, I’m struck by four themes.
As these trends carry forward, what are the most important moral qualities we’ll need in the coming year? What New Year’s resolutions can we commit to for 2008? Here are my three:
Those are my three. What are yours?
©2008 Institute for Global Ethics

Questions or comments? Write to newsline@globalethics.org.
“To a spectator it would look like torture. And torture is wrong.”
– John Gannon, a former CIA. deputy director, talking to the New York Times about the content of terrorist interrogation videotapes destroyed by the CIA. In a Sunday piece, the Times chronicles the shift in political and legal considerations that prompted both the decision to tape the interrogations as well as the later decision to destroy them after waterboarding began.
Source: New York Times, Dec. 30.
Long-running graft saga in Pakistan ends in violence; leaders in Asia and Africa in court over corruption charges; aggressive anti-corruption official in Nigeria ousted
VARIOUS DATELINES
Corruption issues were the text and subtext of several major stories from the world press last week:
Sources: Washington Post, Dec. 30 — CTV, Dec. 28 — Bloomberg, Dec. 28 — Financial Times, Dec. 28 — VOA, Dec. 28 — Bangkok Post, Dec. 28.
For more information, see: Related Newsline story, Nov. 13 — Related Newsline story, Oct. 22 — Related Newsline story, Sep. 24 — Related Newsline story, Aug. 20 — Related Newsline story, Nov. 5.
Case centering on allegations of child kidnapping raises ethics questions on many levels, including whether the workers were duped and how their sentence of eight years of hard labor will be interpreted by a French Court
PARIS
A multi-layered ethics story involving French foreign aid workers has raised questions over international jurisdiction, the rights of children, and the fate of charity workers who may have been duped by members of communities they were assigned to help.
The case involves six charity workers who were convicted of child kidnapping in Chad.
Last week, they were transferred from Chad to Paris where a court will determine how the Chadian sentences of eight years of hard labor can be translated into French law, which has no such contingencies.
The Agence France-Presse reports that the transfer came after months of diplomatic wrangling, and raises the question, as posed by one of the defendant’s lawyers, of whether “French jurisdictions will … endorse a decision rendered by totalitarian justice.”
According to the Paris-based International Herald Tribune, the aid workers were part of a charity group formed in 2004 to help Sudanese orphans fleeing across the border into Chad.
The workers were arrested as they prepared to board a flight to France with 103 children, many of whom were neither orphans nor Sudanese, reports Radio Netherlands.
Workers claim they were duped by various local middlemen, and some families of the children claimed that they were deceived and told that their children were being taken to educational facilities in eastern Chad.
According to an analysis from the Scotsman, the case has embarrassed France and compromised aid efforts in other areas of Africa. The Republic of the Congo recently announced it is suspending international adoption programs after the incident in Chad.
Sources: Radio Netherlands, Dec. 28 — International Herald Tribune, Dec. 28 — AFP Dec. 28 — Scotsman, Dec. 28.
For more information, see: Related Newsline story, Oct. 23, 2006 — Related Newsline story, Oct. 24, 2005 — Related Newsline story, Oct. 24, 2005 — Related Newsline story, Jan. 12, 2004 — Related Newsline story, July 14, 2003.
China tackles plagiarism scandal with name-and-shame approach; Japanese educators compromise on dispute over how much candor should be employed in textbooks describing World War II; author says school districts must be more open about sex-abuse issues
VARIOUS DATELINES
Controversies over plagiarism, academic honesty, and administrative candor were featured in reports from the world press last week:
Sources: China Daily, Dec. 28 — Daily Yomiuri, Dec. 28 — AP, Dec. 28.
For more information, see: Related Newsline story, Sep. 10 — Related Newsline story, Aug. 6 — Related Newsline story, June 11 — Related Newsline story, Sep. 6, 2005.
Organizers, concerned over recent scandals rocking tennis, impose severe restrictions on access to players, ban laptop computers courtside, and promise hefty fines and jail time for perpetrators
SYDNEY
Stiff jail sentences and fines are promised for anyone found involved in match-fixing or illegal betting in the upcoming Australian Open tennis tournament.
The Australian Age reports that Open organizers have put in place a variety of anti-corruption measures including a hotline to report match fixing and a ban on laptop computers in certain parts of the stadium. Authorities fear that laptops could be used by bookies to monitor betting patterns and communicate commands for match-fixing when betting conditions are favorable.
Professional tennis has become one of the latest sports to be rocked by allegations of fixed matches and players claiming they were offered bribes to throw matches, reports the Australian Broadcasting Corporation.
According to a report in the Sydney-based Australian, a recently established anti-corruption commission will deal with allegations and hand out fines, but will refer what it considers to be criminal cases to the Victoria police.
The commission can ban any player or staff member and issue fines of up to a quarter-million dollars, or more if the player’s winnings exceed that amount. Criminal violations can result in up to 15 years in prison.
In addition to stringently restricting access to players, event organizers are bombarding players, coaches, and other support staff with warnings, including posters plastered in locker rooms and postings on websites, notes the Melbourne Herald-Sun.
Sources: Melbourne Herald-Sun, Dec. 29 — Australian Age, Dec. 28 — Australian Age, Dec. 25 — Australian, Dec. 22 — Australian Broadcasting Corp., Dec. 22.
For more information, see: Related Newsline story, Sep. 4 — Related Newsline story, Aug. 27 — Related Newsline story, Aug. 20 — Related Newsline story, July 23 — Related Newsline story, May 1, 2000.
They say ethical concerns over tracking systems are outweighed by benefits to patients, who will enjoy more freedom and exercise without threat of becoming lost
LONDON
A London-based Alzheimer’s charity has backed a controversial proposal by the British government to tag sufferers of dementia with electronic tracking devices if the subjects agree to the monitoring.
Reuters reports that many, previously including the Alzheimer’s Society charity, have expressed concern about the ethics of tagging dementia patients to keep them from wandering off.
But “we now take the view that there can indeed be some sort of use for these devices,” Alzheimer’s Society spokesman Andrew Ketteringham told Reuters.
Another spokesman for the Society, Neil Hunt, told the ITN network that there is a “careful balance to strike between empowering people and restricting their movement and this technology can certainly never be used as an alternative for high-quality dementia care.”
The Glasgow Daily Record reports that many dementia sufferers get strong urges to walk but about 40 percent get lost while doing so.
Advocates of the tracking plan say it not only will provide sufferers with more freedom but will allow them the benefits of exercise without the associated risks of getting lost, according to the Oxford Mail.
Sources: Reuters, Dec. 28 — ITN, Dec. 28 — Glasgow Daily Record, Dec. 28 — ITN, Dec. 27 — Oxford Mail, Dec. 27.
For more information, see: Related Newsline story, Nov. 19 — Related Newsline story, Sep. 10 — Related Newsline story, Aug. 29, 3005.
They will be subject to random checks of computer gear and lie-detector tests; critics say new law could backfire by restricting access to employment and education
TRENTON, N.J.
New Jersey last week enacted legislation that will prevent some convicted sex offenders from accessing the Internet.
The New York Times reports that no federal law restricts sex offenders’ use of the Internet, and only two other states, Florida and Nevada, have laws curbing access.
Parolees will be subject to random searches of their computers and other electronic equipment and must submit to lie detector tests during which they will be asked if they have accessed the Internet.
According to the Courier-Post of Cherry Hill, New Jersey, the new law bars sex offenders from the Internet even if their original crimes did not involve a computer.
Tom Rosenthal, a spokesman for the state Public Defender’s Office, which represents many of the convicted offenders, told the Newark Star-Ledger that prohibiting Internet access to violators whose underlying crimes did not involve computers could backfire. Rosenthal said sex offenders who live stable lives are less likely to commit future crimes, and that prohibiting Internet use could restrict opportunities for employment and education.
“We’re concerned that it does not destabilize them and we’ll be watching it closely,” Rosenthal said. “If it prevents repeat offenses, great. However, we question whether it’s going to work and we would like someone to study it to make sure it does…. If anyone is harmed by the legislation we may have to resort to the courts.”
Certain offenders deemed especially dangerous will wear physical tracking devices to ensure they do not access computers in libraries or cafes, reports the trade journal InformationWeek.
Sources: New York Times, Dec. 28 — Cherry Hill Courier-Post, Dec. 28 — Newark Star-Ledger, Dec. 28 — InformationWeek, Dec. 28.
For more information, see: Related Newsline story, Nov. 19 — Related Newsline story, May 21 — Related Newsline story, Apr. 16 — Related Newsline story, Apr. 9 — Related Newsline story, July 31, 2006.
While some welcome discussion of religion, others view it as pandering
BOSTON
Unprecedented candor about religion among U.S. presidential candidates is raising moral questions about the appropriate role of faith in politics, according to a report from the Christian Science Monitor.
Monitor reporter Ariel Sabar notes that a recent campaign commercial featuring Republican candidate Mike Huckabee, seated near a Christmas tree with “Silent Night” playing in the background, has drawn fire from both sides of the political aisle.
Sabar writes, “To some, the spot was no more offensive or profound than a Hallmark card. But the former Arkansas governor found himself defending it against criticism that its mix of faith and politics went too far.”
The Monitor report notes that “the liberal blog wonkette.com mocked the ad as a ’subliminal floating Christmas cheer,’ a reference to the Cross-like image formed by the brightly lit edges of a bookshelf behind Huckabee. Kathryn Jean Lopez, writing in the conservative National Review, accused Huckabee of ‘using Christ and Christmas to change the subject away from policy and [his] record.’ ”
Pollsters quoted in the Monitor report noted that in general, Americans want their presidential candidates to be religious — but not too religious. After a point, one pollster concluded, more secular voters react negatively to what they view as religious display calculated for political gain.
Source: Christian Science Monitor, Dec. 28.
For more information, see: Related Newsline Commentary, Nov. 6, 2006 — Related Newsline Commentary, Apr. 3, 2006 — Related Newsline story, Mar. 21, 2005 — Related Newsline story, Aug. 30, 2004 — Related Newsline story, July 28, 2003.
Survey finds 85 percent of privacy and security professionals ‘acknowledge a reportable data breach occurred within their organizations in the last year’
From Deloitte & Touche and the Ponemon Institute:
“Personally identifiable information (PII) of customers and employees is being exposed — frequently and repeatedly — potentially putting hundreds of thousands of individuals at risk and exposing organizations to increased liability, according to a new survey by Deloitte & Touche LLP (’Deloitte’) and the Ponemon Institute LLC.
“A shocking 85 percent of privacy and security professionals in North America surveyed acknowledged having at least one reportable data breach of PII within their organizations during the last 12 months, according to the ‘Enterprise@Risk: 2007 Privacy & Data Protection Survey.’ More alarming is the fact that 63 percent acknowledged multiple reportable data breaches occurred within their organizations during the same period. As a result, privacy and security professionals continue spending most of their privacy-focused time on incident response and relatively little time on more proactive activities, such as strategy, training and root cause analysis….
” ‘The astonishingly high rate of data breaches is undermining public trust in both commercial and governmental organizations and points to an urgent need for privacy and security to be elevated as a coordinated, strategic imperative within all organizations,’ said Dr. Larry Ponemon, chairman and founder, Ponemon Institute. ‘Our research suggests that privacy and security are still largely reactive, siloed functions; this mindset needs to change immediately if we are to stem the swelling tide of data breaches plaguing consumers and enterprises.’
“Additional key findings and analysis include:
“The survey pointed out a couple of realities. The privacy function is siloed between legal and compliance on one hand, and IT security on the other hand. The privacy program itself is still immature. And, there does not appear to be real integration with the risk function and business processes of the enterprise. Until that integration occurs, it is likely that privacy incidents and reportable data breaches will continue….”
For the full press release, Dec. 11, click here.
Editor’s Note: Deloitte is a corporate sponsor of Ethics Newsline®.
“Depend not on fortune, but on conduct.”
– Publilius Syrus (Latin writer, 1st century B.C.)