Across the pond -- where last March a British spy left a laptop with top-secret information in a tapas bar and another agent's laptop was snatched in a London train station -- an executive at BG Group echoes Albright's statement about security awareness. "It's a cultural thing," says Tom O'Connor, head of knowledge management systems at the U.K.-based energy company, where 220 senior executives around the world have been issued PDAs to supplement their laptops. "We tell people, 'Treat it as if it's your personal piece of property. Look after it as if it's your wallet.'"
Steps to security
Steve Sommer, CIO at Hughes, Hubbard and Reed, relies on a combination of embarrassment and peer pressure to keep the lawyers at his New York City-based firm in check. "If somebody doesn't comply and we're working on a confidential policy, then that person can ruin the whole deal for us," he says, and nobody wants to be that person. On the technology side, however, common sense isn't enough. Especially when users are accessing network resources remotely or dealing with sensitive material, the CIO needs to address three components of security: the hardware, its data and any network connections. Here are some tips for better security:
Cable locks that allow users to tether their machines to a desk or the furniture in a hotel room have been used for years, but some companies are taking physical security to another level. BG Group, for instance, marks all its handheld units with a chemical coding system from U.K.-based SmartWater, O'Connor says. This forensic coding fluid, when dabbed onto a device, dries to leave an ultraviolet marking akin to DNA.
Other companies are taking an approach similar to the LoJack system, in which a hidden transmitter allows police to track down a stolen automobile. Because laptop thefts had become 3Com's largest property theft worldwide, for the past two and a half years, the Santa Clara, Calif.-based networking company has been installing tracking software on every new laptop, says Brad Minnis, manager of security operations. Absolute Software's CompuTrace lets administrators monitor a laptop's physical location whenever and however its user connects to the Internet. If the device is reported stolen, Absolute works with local law enforcement agencies to track down the device. Users may not even be aware of the software, which is designed to survive a reformat of the hard drive. In addition, each 3Com laptop is issued with a cable lock, and the company makes individual departments pay for replacement units. "There's a real monetary incentive for departments to take care of their assets," Minnis says.