The Register®

Biting the hand that feeds IT

Security firm Guidance settles FTC breach charges

Negligence rebuke

Guidance Software, the security company whose computer forensics software helps firms identify the source of hacking attacks, has settled with the Federal Trade Commission (FTC) over charges that it failed to protect its own customers' data from attack.

The FTC said Guidance failed to take "reasonable security measures to protect its consumers' data from tampering, in contradiction of its own security policies and federal law. As a result, hackers were able to get access to sensitive credit card information on thousands of customers' stored admin passwords in clear text on its servers, an oversight that allowed attackers to access credit card information on its network.

In agreeing the settlement, Guidance agreed to implement a comprehensive information-security programme and obtain audits by independent third-party security firms every two years for 10 years.

According to the FTC complaint (PDF), Guidance failed to implement "simple, inexpensive and readily available security measures" to protect consumers' data. As well as failing to take precautions to prevent web attacks, Guidance failed to detect unauthorised access to its network, a particularly embarrassing oversight given the nature of Guidance's business".

The case is the FTC's fourteenth case challenging faulty data security practices by firms that handle sensitive consumer information. ®

Free Report - "High-level Best Practices in Software Configuration Management: How to deploy SCM software to the maximum advantage"

Don’t Miss

Warning: roadworksNetbooks and Mini-Laptops

Buyer's Guide They're little and we love 'em. But which ones are best?

Warning: roadworksIntel shakes AMD's chip-fabbing baby

Cross-licensing custody battle

Emails show journalist rigged Wikipedia's naked shorts

Overstock's Byrne vindicated amidst economic meltdown

Warning StopYours truly, angry mob

Book extract Bringing Nothing To The Party: Cleaning up the net, one satirical vigilante page at a time