Learning Hub Graphics-6-White Paper

The Importance of Operational Security Measures In A Travel Agency

Tyrone Mattison, CTC

 

Introduction

Operating a travel agency can be an exciting and rewarding business venture. Professional travel agents have the resources and professional training to help individuals or families fulfill their dream vacations or managing corporate and small business travel needs. Individuals and corporations provide travel agencies with huge amounts of personal identifying information, banking information, credit card numbers, travel itineraries, employment information, and individual addresses. Prior to advancements in technology, travel agencies collected customer data with the use of a land-line telephone system, pen & paper, or typewriter and stored the data in a file folder. The file folder would be filed in a filing cabinet with a lock or secured in a locked room. This was the most effective way at that time to protect customer data.

With the passing of time, technology has made great advancements in ways travel agencies or able to collect and store customer data. Travel agencies now have access to various consumer management systems to collect and managed customer data. Instead of using filing cabinets to store customer data, travel agencies are now able to store large amounts of costumer data using digital platforms. Technology advancements have made operating a travel agency more efficient and effective.

Although technological advancements have made life easier for travel agencies, technology also comes with a whole new set of problems and issues that travel agency owners must focus on. The age of computers expanded not just to digital media storage, it extended to internet, computer networks, mobile services, cloud servers, and blue tooth capable devices. Computers and digital technology use has become the norms in the travel industry. Criminal Organizations and unethical individuals are aware that corporations and small business owners in all industries are storing vast amounts of sensitive data using this advanced technology. These organizations and individuals are using unlawful, creative, and unethical means to access this sensitive data to use to their own advantage.

In today’s digital age, travel agency owners need to be extremely aware of the importance of operational security. Protecting your business, customer data, and reputation is paramount. “Many companies believe they will not be affected by potential cyber threats due to their size, industry or location. As global cyberattacks continue to rise, all organizations must understand the importance of cybersecurity protection. Organizations also need to realize that cyber threats are constantly evolving, which is why cybersecurity must be viewed as an always-on company priority. The involvement of executive management is critical here as well; recent research from Mandiant indicates that 67% of businesses believe their senior leadership team underestimates the cyber threat to their organization (Kris Lahiri, Forbes Technology Council).”[1]

Steve Ursillo, Jr and Christopher Arnold with the International Federation of Accountants (IFAC) states, “In today’s computerized world, new risks emerge every hour of every day. Connecting to the Internet opens up the possibility of a hacker targeting your organization. Cybercrime is becoming big business and cyber risk a focus of organizations and governments globally. Monetary and reputational risks are high if organizations don’t have an appropriate cybersecurity plan.”[2]

“Cyberattacks cost the U.S. economy billions of dollars a year, and pose a threat for individuals and organizations. Small businesses are especially attractive targets because they have information that cybercriminals (bad actors, foreign governments, etc.) want, and they typically lack the security infrastructure of larger businesses to adequately protect their digital systems for storing, accessing, and disseminating data and information (U.S Small Business Administration)”.[3]

Travel agencies owners also must consider and embrace the fact that cyberattacks are not all conducted by external actors and sources; they also can be conducted by internal actors from within their own organization. Any employee with access to customer data or any sensitive data can be viewed as a risk or threat, especially if the employee is disgruntle or have interior unethical motives. Yes, for some, it is a bitter pill to swallow to believe that there are organizations and individuals out there that specifically and purposely look for ways to access sensitive and confidential information unethically. However, that is the reality of the world we live in today.

Where do travel agency owners go from here? How do they prepare their agencies for the future and combat potential threats of cyberattacks on their consumer data and sensitive information? Travel agency owners who fail to take these potential threats seriously are subjecting their agencies to the real possibilities of serious legal ramifications. A great place to start is for travel agency owners to implement a comprehensive Operational Security (OPSEC) program within their organization. “As the digital transformation takes hold of the modern business environment, implementing safeguards to your organization’s critical information is only going to become more critical for survival-and if you aren’t doing so already, it’s time for your organization to take proactive protective measures (RiskOptics)”.[4]

 

What is Operational Security (OPSEC)

Businesses of all kind that maintain sensitive data or customer data, including travel agencies have a moral duty to protect that data from unauthorized users and outside sources. Failure to implement some form of information security even at the basic level can be catastrophic for a business owner and their customers. “By prioritizing cybersecurity, organizations can mitigate the risk of data breaches, financial losses and reputational damage. Whether you’re an individual or an organization, understanding the importance of cybersecurity is fundamental to navigating the threat landscape safely and securely (CompTIA)”.[5]

The United States military counterintelligence team came up with the concept of operational security (OPSEC) during the Vietnam War. During the war the United Sates military felt as if their enemies were able to predict their strategies, and they needed away to prevent this from happening. After conducting research the United States military counterintelligence team adopted five (5) key security strategies and designated it has their operational security plan. These five components of operational security are: 1. Identifying Sensitive Data, 2. Identifying Potential Threats, 3. Analyzing Security Vulnerabilities, 4. Determining Each Vulnerabilities, and 5. Implementing Threat Mitigation Plans.

“OPSEC is both a process and a strategy. As a strategy, OPSEC is designed to help your IT and security managers think about your organization’s business operations and its systems from the perspective of a potential attacker. As a process, OPSEC can help your organization identify actions that could expose your sensitive information to unauthorized parties (RiskOptics)”.[6] According to Ellen Zhang, “Operational security (OPSEC) is an approach to risk management that promotes viewing operations from the perspective of an antagonist. The goal is to identify potential vulnerabilities and address them to prevent sensitive information from being lost, stolen, or compromised. OPSEC was developed by military organizations and is becoming increasingly popular in private business and industry.”[7] As a travel agency owner implementing an operational security plan is a great beginning to preventing unauthorized users and outside forces from gaining access to sensitive customer data. Let’s discuss the five (5) key components of operational security, and how it benefits a travel agency.

Identifying Sensitive Data

The first thing that a travel agency owner needs to do while creating an operational security plan is to identify the agencies sensitive data. Most information collected by travel agencies in their customer management systems are sensitive data. This information contains personal identifying information of the agency’s customers. The agency’s business financial records are classified as sensitive data. Any intellectual property the agency owns and any records of employees are considered as sensitive data. As an agency owner whatever you believe to be sensitive data is your sensitive data. This is the information you believe someone would want to steal or access illegally to benefit their schemes or objective. Sensitive data is where you want to concentrate your resources and efforts to protect.

Identifying Potential Threats

Once sensitive data has been identified, the next step is to determine who would want to gain access to this sensitive data. Who would want to destroy this sensitive data or use it to cause harm to the agency. It is important to identify any and all potential threats to your sensitive data. This is also a great time to meet with the key employees or members of the agency and have an in-depth discussion about potential threats as a collective body. Threats are not only outside actors but inside actors as well and can complicate the threat analysis process. “Insider threats are threats that originate with authorized users—employees, contractors, business partners—who intentionally or accidentally misuse their legitimate access, or have their accounts hijacked by cybercriminals. Insider threats can be more difficult to detect than external threats because they have the earmarks of authorized activity, and because they’re invisible to antivirus software, firewalls, and other security solutions aimed at blocking external attacks (IBM).”[8] This is something that must be taken under advisement when meeting with the key employees and members of the agency.

Analyzing Security Vulnerabilities

The next important section in the operation security plan is identifying potential security vulnerabilities. “Vulnerability exists when the adversary is capable of collecting critical information, correctly analyzing it, and then taking timely action to exploit the vulnerability to obtain an advantage (defense.gov)”.[9] Travel agency owners should first look at their information technology processes and procedures along with their network security. This is an area easily accessible for outside perpetrators if security measures are not proper. From within the agency, how easy is it for unauthorized employees to access customer data and sensitive information. Does the agency have any safeguards in place to monitor this type of activity? Another area agency owners should address is how does the agency do away with old customer data or sensitive information? How easy is it for customers inside the agency to gain access to unattended computers? These areas are only examples of places to look for vulnerabilities in security. Agency owners should look at all areas of operation to find weak spots in their security.

Determining Each Vulnerability’s Risk Level

At this point in the operation security plan, there should be enough information obtained to determine the risk level of each identified vulnerability. “The vulnerabilities should be ranked based on the likelihood of attackers targeting them, the level of damage caused if they are exploited, and the amount of time and work required to mitigate and repair the damage. The more damage that could be inflicted and the higher the chances of an attack occurring, the more resources and priority that organizations should place in mitigating the risk (Fortinet.com)”.[10] Being able to rank and prioritize the vulnerability based on the severity of damages caused and cost to remediate the situation should help the agency owner assign a budget and resources to secure it.

Implementing Threat Mitigation Plans

The final part of the operation security plan after the potential threats and vulnerabilities have been identified, it is time to mitigate those threats and risks. Now that the amount of resources has been allocated to each identified vulnerability it is time for the agency owner to put security countermeasures in place to protect customer and sensitive data. Starting with the area of information technology, there are many security measures that can be used to help prevent cyberattacks. Agency owners can make sure all their hardware and software have the latest security updates. Professional firewalls and antivirus can be used to help counter cyberattacks. The agency owner can use encryption and complex passwords to further strengthen security measures. Virtual private networks (VPN) can also be used to help secure agency owners’ sensitive data.

Countermeasures can be used when sensitive data is no longer needed. Agency owners should get rid of sensitive that is no longer needed as soon as possible. They can use personal shredders or a professional shredding company to dispose of sensitive data instead of just throwing it in the trash can. Screen protectors can be placed on all computers, as well as making sure employees lock their screens upon leaving their desks. Another important mitigation tool for agency owners is to make sure that all employees have some form of training on cybersecurity and put policies in place for proper adherence.

It is always a good idea to have a contingency plan in place in the event a security breach occurs. The agency owner needs to have a legal team in place along with a good public relations representative. These people can quickly respond to the security breach and reduce the impact of such breach. There is no such thing as a flawless security plan. Even with the best security measures in place, a breach can occur accidentally or purposely. In events such as these, it is a good idea for agency owners to have the proper insurance protections to help reduce the financial impact on the agency.

 

Conclusion

Across the globe, cyberattacks are constantly increasing on the world’s technology infrastructure. Employers are having to face the realities that the threats of inside actors are growing and pose a serious risk to the organization’s sensitive data. Whether you are a single member travel agency or an agency with multiple members, you are at risk of a cyberattack or breach of sensitive data. It is not a matter of if it happens; it is a matter of when will it happen. Failure to implement an operational security plan is a high-risk with catastrophic consequences to the owner and customers of the agency.

As an agency owner, the implementing of an operational security plan should be a high priority. The basic steps to implementing an operational plan have been provided. An operational security plan is not the end-all of securing your most important information, but it is a good place to start. Once the operational security plan have been implemented, it is important to continue to strengthen security countermeasures and reduce areas of vulnerability within the agency. As an agency owner it is up to you to protect your agency, agency reputation, and protect your customer’s personal identifying information with a proactive operational security plan.

 

References

Why Cybersecurity Should Still Be A Top Priority For Businesses (forbes.com)

Cybersecurity Is Critical for all Organizations – Large and Small | IFAC

Strengthen your cybersecurity | U.S. Small Business Administration (sba.gov)

What is Operational Security & Why is it Important? — RiskOptics (reciprocity.com)

Why Is Cybersecurity Important | Cybersecurity | CompTIA

What is Operational Security & Why is it Important? — RiskOptics (reciprocity.com)

What is Operational Security? The Five-Step Process, Best Practices, and More (digitalguardian.com)