Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What The Daily Commute Could Mean For Your Data
Articles

What The Daily Commute Could Mean For Your Data

ISBuzz TeamBy ISBuzz TeamApril 16, 20146 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
daily-commute
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The latest intelligence on Al-Qaeda, a high profile Child Protection report and plans for policing the London 2012 Olympics; three very different documents with two things in common: firstly, they all contained highly confidential information and secondly, they were all left on a train.

In each example, an inquisitive fellow commuter picked up the folder, took one look at the contents and promptly handed it to a newspaper. In each case, the newspaper in question was happy to return the folder to its rightful owner after having used the information to craft a front-page news story that was both embarrassing and reputation damaging for the companies ultimately responsible for managing the information.

On reading the subsequent news stories, no doubt many people wondered how anyone could have been so careless. But just how many of us undertake work while commuting with little regard for the security of the information they are working? These few high-profile incidents may have grabbed the headlines but the journey to and from work places every company’s information at risk. Employees are leaving files on trains, laptops in bars, and dropping memory sticks in car parks. Then, there’s the employees who inadvertently display company information to fellow commuters and think that the commuter train is the ideal location to talk sensitive company business on the phone.

As commuter belts grow ever wider around our urban centres, workloads are getting heavier and the working day seemingly longer. Inevitably, many face longer journeys into and out of work (Eurostat puts the European average at just over an hour a day for large urban areas). Consequently more people use their travel time to keep on top of their work load. But information is never more at risk than when it is on the move.

Our latest research reveals that two thirds of Europe’s office commuters have no qualms about peering across to see what the person sitting next to them is working on; and more than one in ten (14 per cent) has spotted confidential or highly sensitive information.

The growing use of mobile devices such as smartphones, tablets and laptops has exacerbated the trend of working on the move. But paper documents appear to remain the most vulnerable. They are easily forgotten or disposed of carelessly.

For employers and their lawyers, this type of inadvertent disclosure is a grey area, particularly if the information spotted or overheard turns out to be rather useful competitive intelligence.

The gathering of competitive intelligence is a legitimate business practice, but the line between what is legal and what is ethical can be a fine one. Guidelines produced by law firms often focus on formal anti-trust activity and the kind of information that employees can and cannot solicit or accept from competitors, suppliers or customers; glossing over the far murkier waters of what to do with information that is obtained by accident. That is, if leaning over someone’s shoulder to read what they are doing or eavesdropping on a conversation can ever be said to be ‘accidental’.

Those brave enough to venture into this field find themselves having to trust employees to understand that some behaviour, while not exactly illegal, is still unethical, and honour and integrity should prevent them from taking some of the opportunities they may find themselves presented with.

In other words, when it comes to information gathering, overhearing a loud conversation between your top competitors on the train is generally not unethical; but deliberately manoeuvring your way to the seat behind them so you can hear exactly what is being said, probably is. Similarly, seeing confidential company information on the laptop screen next to you on the plane is not unethical; but scrolling through the slides while the author is in the washroom is more questionable. Reading documents left behind might be okay but stuffing someone else’s documents into your bag while they’re not looking is theft. Every one of us has a line we are not prepared to cross, and it’s down to the company to establish guidelines and policies to ensure everyone knows where the line should be.

The need to harness and sometimes adjust individual moral codes when it comes to appropriate business practice is incredibly important. One of our earlier studies showed that most people (52 per cent of office workers in Europe) are happy to seize the opportunity to discover confidential information about a competitor and to share it with their employer (51 per cent) – and often regard this as a positive and loyal course of action.

In fact, most employees believe that information exposed in a public area is fair game, and keeping it safe is entirely the responsibility of the person failing to keep it secure. There are practical things an employer can do to protect the organisation and its employees from such activity. These include proper education on information security for all employees, a shared sense of data responsibility and equipping employees with the IT tools to securely manage and handle information while travelling (such as passwords, device encryption, privacy screens and ensuring that sensitive information is only sent over secure virtual networks). It is particularly important not to forget about paper – hard copy documents can be taken out of the business without anyone knowing they’ve gone or who’s got them.

Accidents will happen, but you can keep them to a minimum by educating, supporting and enabling your employees. At the end of the day, most people are honest and want to do the right thing; people just get tired or rushed or distracted and then it goes wrong. None of this is new of course. Wartime propaganda urged those at home not to discuss the movements of troops or supplies for fear of yielding an advantage to the enemy: “loose lips sink ships” and “careless talk costs lives” and many variants thereof were memorable slogans. With the language of military engagement so often used for business purposes, perhaps firms should think of similar campaigns to keep their critical information safe when it’s on the move.

Christian Toon | Risk and Security at Iron Mountain | @christiantoon

Bio: Christian Toon, has a wealth of experience in the industry and ensures that governance, risk and compliance requirements are met within both new and existing contracts from across the continent. These contracts include some of the industry leaders in business today. He enjoys the challenge that comes with interpreting customer problems and solving them with a risk-based approach, with strong interests in the causes of data breaches, identity theft and bring your own device.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}