The Rational Outsourcing Blog

Saturday, March 17, 2007

Bangalore nee Boston Globe: why the privacy red herring may come back to haunt the Boston Globe union

If you haven’t heard about the union objections to the Boston Globe outsourcing 50 positions to India, then you should see the Boston.com or Times of India or the Outsourcing Weblog sites. You can also see the actual ad here (as a pdf).

The union says: “Further, billing and account information will now be shipped overseas to Bangalore, India, putting customers’ most vital information at risk.” As I have written several times before, this is a red herring. Outsourcing these task to India may actually improve information security. Remember, just last year Boston Globe saw one of the most absurd privacy breaches I have ever heard of. If you have forgotten, here is a quick reminder from a Boston.com story.
Credit and bank card numbers of as many as 240,000 subscribers of The Boston Globe and Worcester Telegram & Gazette were inadvertently distributed with bundles of T&G newspapers on Sunday, officials of the newspapers said yesterday.

The confidential information was on the back of paper used in wrapping newspaper bundles for distribution to carriers and retailers. As many as 9,000 bundles of the T&G, wrapped in paper containing subscribers' names and their confidential information, were distributed Sunday to 2,000 retailers and 390 carriers in the Worcester area, said Alfred S. Larkin Jr., spokesman for the Globe.

In addition, routing information for personal checks of 1,100 T&G subscribers also may have been inadvertently released.
The Globe and T&G financial information was inadvertently released when print-outs with the confidential information were recycled for use as so-called "toppers" for newspaper bundles. A topper, placed on top of abundle of newspapers, is inscribed with the quantity of papers in each bundle and the carrier’s route number.

Oh, the irony! Before using privacy as a Fear Uncertainty and Doubt (FUD) attack against outsourcing, the union should have remembered that those who live in glass houses should not throw stones.

Related Posts:

Labels: , , , , , ,

Thursday, January 25, 2007

Really informative article on the Information Security laws in India

Thanks to Google alerts I came across a really interesting article in law.com that “surveys the state of data security legal protections in India.” Check out the complete article. To whet your appetite, here are a few excerpts:
The Indian legal system is substantially based on the British common law system. While there is no omnibus Indian data security law, there are several laws that apply to data theft or misuse in India. Typically, when an incident involving data occurs, a complaint is filed for theft, cheating, criminal breach of trust, dishonest misappropriation of data and/or criminal conspiracy under the provisions of the Indian Penal Code, 1860 (IPC) and for hacking under the Information Technology Act, 2000 (ITA). Many of these offenses under the IPC and the ITA allow for an arrest without a warrant, are non-bailable and carry penalties that range from imprisonment for a year to life imprisonment, as well as fines.

the criminal complaint can be made to Anti Cybercrime Cells set up by the State Police Departments. These cybercrime cells have been established specifically to investigate and prosecute cases of data theft and copyright infringement, as well as other cybercrime cases. Cybercrime cells of several state police departments (e.g., Delhi) organize training programs to enhance investigators' skills and knowledge concerning data protection, and use advanced equipment to investigate data security incidents. In fact, the U.S. Department of State recently trained Indian cybercrime investigators on investigating techniques. The investigating officers at Anti Cybercrime Cells have the power to seize infringing or stolen data by conducting searches and raids on the premises of the alleged offenders and can also prosecute the offenders in the criminal court that has jurisdiction over the police station where the complaint was registered. The law enforcement agencies also have the power to arrest offenders and keep them in custody during the course of the investigation and prosecution unless bail is granted to the offenders by the court.

While several measures have been put into place to deal with data security issues, some concerns still remain regarding the Indian legal system. Indian courts are overburdened -- in 2005, the lower courts had more than 20 million pending cases, while the high courts had more than three million. Delays in the system are common, and an average case can take several years to be resolved. However, things are changing. Several measures are underway, and the Prime Minister of India, as well as the Chief Justice of the Indian Supreme Court, have committed to dealing with the issues facing the Indian courts. Further, the system itself, while slow, works. More importantly, as previously discussed, the service providers themselves are putting into place several preventive measures to deal with data security and privacy issues.

Labels: ,

Wednesday, January 24, 2007

Reprise: Consumer privacy protection and outsourcing to India

It really is a small world! I was talking to a friend on Sunday and it turns out she is an active volunteer for the Privacy Rights Clearinghouse. She had been a victim of identity fraud and speaking with her gave me a better appreciation for what the Privacy Rights Clearinghouse was talking about in the Statement on Outsourcing and Privacy. For example, my friend had her information stolen by an employee of a hospital she visited. She actually had to privately track down the person who had stolen her information. I can see how this would have been more difficult if the thief had been in a foreign country. However, I do believe that outsourcing if done right would actually improve privacy protection rather than harm it.

For example, a significant part of basic data-entry in the US is done by temporary workers or high school graduates who do not see data-entry as a career path. On the other hand, a BPO in India typically employs people with some or significant college education, who expect to have a career in the BPO industry. Thus, I believe these Indian workers have less of an incentive to break the law. If crime rates are anything to go by, an Indian college graduate is far less likely to commit a crime than a young American earning close to minimum wage.

My friend did raise an interesting argument that an Indian worker earns significantly less than an US worker and thus may be more tempted to carry out identity theft. I actually disagree with this for several reasons:
  • We should consider the lifestyle that the salary can purchase, not just the dollar amount. While Americans earning close to minimum wage struggle to feed their families, Indian BPO operators earn enough that they have significant disposable income. In many cases they earn significantly more than their parents did. In general, a young Indian fresh out of college actually sees a BPO job as a somewhat good life and most of them are focused on the prize of being promoted to management and achieving a better life than the vast majority of Indians. An American making close to minimum wage certainly does not see his job as a path to the good life.
  • In both India and the US identity theft is not prosecuted as aggressively as it should. Many US companies do not conduct sufficient background checks on their employees. Indian companies face a different problem in that it is more difficult to carry out formal background checks in India. However, in India two factors ameliorate this problem. First, most BPO operators are recruited / recommended by an existing employee. In some BPOs I felt like they had recruited away entire classes from certain universities! These strong peer bonds serve as informal background checks as well as a strong inhibitor for illegal activities. Second, Nasscom, the association of Indian BPO vendors, has been aggressively pushing for stricter information security laws and a national database of certified operators.
    The new National Skills Registry (NSR) is backed by Indian IT trade association Nasscom and was set up following a series of customer data breaches at offshore call centres last year. The NSR, set up by Nasscom and the National Securities Depository, is a centralised database that will store information about each IT worker's educational and professional background. Biometric technology will be used to verify the identity of individuals. [from a silicon.com story]
    This database is still in its infancy and only about 30% of the industry’s total workforce registered with it in the first nine months [See this Indian Express story for details] but this is already better than what you would expect in the US where it would be very difficult to set up such a registry.
  • Moreover, generally information security is the lifeblood of a BPO vendor. Even one information security problem could completely ruin its reputation and subject it to severe financial liability to its customer. As such, BPO vendors tend to be far more careful about information security and put in far better safeguards than most US firms. For examples of what Indian BPO vendors are doing to improve data security, see the “Indian BPO providers tighten data security” story from SearchDataManagement.com:
    Take a look inside a typical BPO outfit, "where you will find airport-style frisking at the entrance a routine," said Raghu Iyer, a Bangalore-based call center worker. Agents (BPO workers) are required to surrender everything they carry, like mobile phones, PDAs, pens, notebooks and even tissue papers, which could enable smuggling data.

    Access to personal e-mail accounts is not allowed and firewalls block access to any Web site not necessary for work. At the end of the day, workers have to shred notes of conversation with customers, and workers are forbidden from socializing with non-employees during work hours. Visitors are required to seek permission and are required to sign a document of non-disclosure as well. "Above all these measures, with closed-circuit TV cameras watching your every move, the job of a typical BPO worker has never been so suffocating," Iyer added.

    It may be uncomfortable for many workers, but "BPO firms have little choice but to follow more quality checks and more auditing, and impose more regulations that could be demanded by their customers," said Sudhin Apte, country manager of Forrester Research Inc.

In conclusion, I believe information security is stronger in a leading Indian BPO than in most US companies. As such, organizations such as Privacy Rights Clearinghouse may actually find that their privacy goals are better met when companies outsource their processes to leading Indian BPOs than when they keep these processes in-house. The major caveat here of course is that the BPO contracts have to be structured appropriately, the BPO vendor’s information security procedures have to be carefully evaluated, and the final BPO decision has to be based on Total Cost of Ownership (including expected PR expenses and regulatory risk stemming from potential information security breaches) rather than just labor cost.

Labels: ,

Friday, December 08, 2006

Nasscom’s new Data Security Watchdog: it has bark, will it have bite?

It seems Nasscom is trying to address the information security perception problem in India by creating a new Data Security Watchdog (as reported in CIO India).
The National Association of Software and Services Companies (Nasscom) is setting up a watchdog organization that will focus on the introduction and monitoring of best data security and privacy practices in the country's IT services, call center and business process outsourcing industries. The move is one of several measures by Nasscom and the IT industry to strengthen data security and privacy in the Indian call center and BPO industries.

"We are planning a self-regulatory organization (SRO) that will be initially set up by Nasscom, but will operate independently with an independent chief executive officer and board," said Sunil Mehta, vice president of Nasscom in Delhi.

"Being a member of the SRO will in effect be a certification, as member companies will have to follow the best practices specified by the SRO," he said.

Besides setting benchmarks and training companies on the best data protection and data privacy practices, the new organization will also have the authority to punish and expel erring member companies

The SRO will be funded for one year by Nasscom, which has budgeted Rs 1.35 crore for the purpose. After the first year, the SRO is expected to finance itself from membership, training, and audit fees.

This sounds like a great idea, especially as this organization can become a forum for sharing information security best practices. I have been impressed by the information security and fraud detection methodologies used by some Indian vendors and if they start helping each other they can improve even more rapidly. I am a firm believer in incentives, and here I think the outsourcing vendors’ incentives are properly aligned: When one Indian outsourcer has an information security or fraud problem, every Indian outsourcing vendor suffers from the negative press. Japanese manufacturers helped each other build the “made in Japan = quality” perception, Indian outsourcing firms have to do likewise.

I am however not sanguine about the incentives for the enforcement component of this watchdog. After the first year, the watchdog will be funded by the dues paid by its membership and the only way for it to punish a member would be to “expel” the “erring member” and thus lose their “membership, training, and audit fees.” This sounds like classic incentive misalignment. I hope that the Nasscom leadership will address this problem before the organization goes live. Perhaps the organization could be funded by the outsourcing customers instead? Rs 1.35 crore (approximately $300,000) split among even thirty large outsourcing customers sounds like a very good investment. If that $10,000 a year helps them avoid a single information security breach, or more likely a PR headache, it would be money well-spent.

Labels: , , , ,

Thursday, December 07, 2006

Who would you trust with your credit card number: an Indian college grad, or an American felon?

Recently there have been a series of articles on Indian companies’ problems with information security and fraud. However, the BPO vendors I personally evaluated in India tended to have as good if not better information security procedures than most US companies. I was recently semi-joking with the CEO of an Indian BPO that workers in California would never accept the kind of restrictions Indian companies regularly place on their employees to prevent information theft. Some of these restrictions (such as keystroke monitoring) may even be illegal in countries like Germany. However, right now when it comes to outsourcing, perception is reality and the pervasive perception is that India has a data security problem.

I must admit, I am a bit confused by this. If Americans are OK with felons in US prisons accessing their information, surely they would be OK with trusting a college graduate in India? Strange as this sounds, I am not making this up. In July 2004, USA Today reported:
About a dozen states — Oregon, Arizona, California and Iowa, among others — have call centers in state and federal prisons, underscoring a push to employ inmates in telemarketing jobs that might otherwise go to low-wage countries such as India and the Philippines. Arizona prisoners make business calls, as do inmates in Oklahoma. A call center for the DMV is run out of an all-female prison in Oregon.

At least 2,000 inmates nationwide work in call centers, and that number is rising as companies seek cheap labor without incurring the wrath of politicians and unions. At the same time, prison populations are ballooning, offering U.S. companies another way to slash costs.

As expected, there are some “information security problems” with using prison labor in call centers:
executives shudder at the prospects of inmates sharing the personal information of customers with fellow prisoners, as some did in Utah in 2000.

An article from NPR comments:
Labor unions and some states say they believe it's too much of a security risk to have prisoners talking to the outside world, even if they're being monitored. Private businesses say it's also a security risk to have prisoners taking down customers' credit card information.

Maybe it is just me, but it seems that if information security outcries restrict offshore outsourcing, companies are more likely to shift the work to similarly priced prison-based call centers than to hire American workers who even at the minimum legal wage are several times more expensive. To quote the UNICOR Federal Prison Industries website: “Imagine... All the benefits of domestic outsourcing at off shore prices. It's the best kept secret in outsourcing!” By the way, you also have to see the slick marketing video on their website. Maybe it is just me, but I would prefer to share my credit card information with an Indian college graduate than with a felon. [To be fair, I am sure UNICOR works hard to restrict their operators access to private information, as do Indian BPOs. The problem arises when the system does not work as planned.]

I am not trying to belittle the information security problem in India. It exists, just like similar problems exist in the US, and needs to be addressed proactively. But, let’s please take the politics out of business decisions and stick to Rational Outsourcing.

Labels: , , , ,