The Information Commissioner, Richard Thomas, in April reminded chief executives of the vital importance of protecting staff and customers’ personal information.
This is following what the Information Commissioner’s Office (ICO) terms an alarming number of security breaches reported to his Office in the past six months.
Since the security breach at HM Revenue and Customs in November 2007, the Information Commissioner’s Office (ICO) has been notified of almost 100 data breaches by public, private and third sector organisations. Of the security breaches that the ICO has been made aware of by private sector organisations, half were reported by financial institutions. Of those reported by public bodies, almost a third occurred in central government and associated agencies and a fifth in NHS organisations.
ICO disappointed
Richard Thomas, Information Commissioner, said: “It is particularly disappointing that the HMRC breaches have not prevented other unacceptable security breaches from occurring. The government, banks and other organisations need to regain the public’s trust by being far more careful with people’s personal information. Once again I urge business and public sector leaders to make data protection a priority in their organisation. The level of understanding about data protection and the need to safeguard people’s personal information have no doubt increased and I am encouraged that more Chief Executives and Permanent Secretaries appear to be taking data protection more seriously, but the evidence shows that more must be done to eradicate inexcusable security breaches.”
Information that has gone missing includes unencrypted laptops and computer discs, memory sticks and paper records. Information has been stolen, gone missing in the post and whilst in transit with a courier. The material includes a wide range of personal details, including financial and health records. The ICO is investigating the circumstances of the breaches. In 16 cases the ICO has required the organisation to make procedural changes to improve data security, such as encryption. In three instances the lost information has been recovered.
The ICO encourages organisations to report data breaches and can advise on
dealing with breaches and notifying affected customers. The ICO has recently
published new guidance for organisations on how to deal with security breaches. A copy of the ICO’s Guidance on data security breach management can be downloaded from www.ico.gov.uk
Control Risks the London-based consultancy adds that ‘Government department loses confidential information’ has become such a commonplace it hardly merits a headline. Despite concerns about how our personal data is kept safe, a survey by business risk consultancy Control Risks suggests that people have a lax attitude to protecting personal information.
In a survey of over 1000 people, 60 per cent said that they have overheard someone giving away private information such as their bank account details on the phone in a public place or at work. With people having such lax attitudes to their own sensitive information what can companies do to ensure that information is safe in the hands of their employees?
Despite having firewalls and IT systems in place, the weakest link for a company is its employees – even if their intentions aren’t necessarily malicious. The survey reveals that almost a quarter of employees (24 per cent) have written down or told someone else their password, allowing others not only to access and download company information but also to potentially carry out fraud in another employee’s name. Other dangers include using someone else’s email to act maliciously and harass staff or downloading banned information from a website in the guise of another employee.
Control Risks reports that it has often been called in to employee tribunals to show how employees facing the sack may have been the victim of ‘identity theft’ at work and had their identity used for nefarious purposes. In the last 20 years, changes in the way we can access information means 55 per cent of people interviewed say they could easily walk out of their office with data on a memory stick or CD. Recruitment agents, for example, could take away details of their clients and candidates, finance department staff could steal an entire database of financial information. Even if staff are taking work home perfectly innocently, information could disappear from their PCs through loss or theft of a memory stick. Moreover, working on company information at home exposes this information to software that is probably much more open to attack than a work computer. With protection systems much less rigorous on personal computers, staff could be unwittingly supplying competitors with confidential information.




