Laptops and other mobile devices have a much greater chance of being stolen because of their mobility and small size. A thief could easily hide a laptop in a briefcase or under a coat. Even organizations that have tight physical security are susceptible to this type of theft. For example, there are several high profile, documented accounts of laptops and removable laptop hard drives containing top-secret information being stolen from a conference room and office, from places including U.S. State Department and the U.S. Department of Energy s top secret research facility at White Sands. Furthermore, although some laptops will always remain within the boundaries of company facilities, most users will work on their laptops away from the office. Consequently, the network security of such laptop computers is enforced by those organizations corporate security and IT departments. But the users themselves are responsible for the physical security of their laptops. Users take their laptops home, on business and personal trips, and to school, and they sometimes leave their laptops in their cars unattended and in plain view during those stops. In July 2000, a commander in the British Royal Navy had his laptop stolen from his car, which was parked outside his house. His laptop was reported to hold top-secret information. Thieves target laptops because they are small, high-value items that can easily be sold. If a thief is sufficiently computer-savvy or sells the laptop to an attacker, he or the attacker can potentially retrieve all the information from the laptop. This information includes cached passwords for network accounts; cached personal information from Microsoft Internet Explorer; personal information, such as names, addresses, and birthdates for people in address books; and the actual company data on the laptop. An attacker can use this information to attack the organization s network or steal the identity of the user or her friends and family. Furthermore, the stolen laptop might contain information that is confidential or secret. An information leak resulting from a stolen laptop could have a tremendous impact on your organization if that information falls into the wrong hands. This might sound alarmist, but several high-profile incidents of laptop theft have occurred in the past few years, including those government examples mentioned earlier. The corporate world has not been immune to such incidents of laptop theft. A few years ago the laptop belonging to the CEO of Qualcomm was stolen after he delivered a presentation at an industry conference. According to the media, the CEO was less than 30 feet away when his laptop was stolen from the podium from which he had been speaking. Because the CEO had been using his laptop to give the presentation, it is likely that he left it unlocked when he walked off the podium, rendering many types of data protection, such as encrypting file system (EFS), useless. Although the thieves in the cases we have mentioned so far might not have been targeting the organizations whose laptops they stole or the information on those laptops, no evidence to the contrary exists.
