Security firms condemn HMRC for breach
By Nicole Kobie,
Security experts from around the UK have come out in full force to criticise the massive data breach at HM Revenue and Customs - and to offer advice on how other organisations can avoid a similar fate.
Chancellor Alistair Darling admitted the breach yesterday afternoon, telling parliament that records of 25 million child benefit recipients were lost after they were put on two password-protected discs and sent through an internal mail system - contrary to HMRC's own procedures.
Prime Minster Gordon Brown said today that all government agencies will undergo a data security check. The HMRC is set to be investigated by the Information Commissioner's Office, PricewaterhouseCoopers, and the Independent Police Complaints Commission, alongside the Metropolitan Police's search for the missing discs.
Security analysts criticised the HMRC's data notification policy, and said the lack of encryption, use of discs as opposed to electronic transfer, and poor information management contributed to the fiasco.
Symantec's director of technical services Richard Archdeacon said the data breach would lead to a change in how consumers view data security. "It's a tipping point of data leakage... it's the accidental loss as opposed to an external hacker," said Archdeacon. "It's so large an event that we'll see a change amongst consumers."
Archdeacon said organisations will need to be more transparent about their data policies. "This is the big one, which will change consumers' levels of trust," he said.
Companies should also be prepared to notify costumers in the event of a breach, as its likely legislation will eventually force that, said Archdeacon.
Data can be protected even if discs are lost, said some industry leaders, who expressed dismay that the discs were so poorly secured, with just a password.
Joseph Hoban, vice president at GuardianEdge, said: "Securing two disks with only a password is not sufficient... To put an end to this catalogue of errors, the government needs to encrypt any removable devices like USBs or CDs that are to be transported - otherwise people should go to that data not the other way around. This way, if a removable device falls into the wrong hands - which it well might - it cannot be accessed and compromised."
"The cost of data breaches can run into millions, but the cost of encryption is relatively low," he added.
But it's possible to avoid the pain of lost discs and laptops by sending data over networks, said others.
Gayna Hart, managing director of Quicksilva, said that the data should have been sent electronically - in the way the NHS is planning. "In the 21st century to be sending confidential information through the post is inexcusable and completely unnecessary given the technology available," she said, adding that electronic records systems are working well for Connecting for Health's (CfH) Spine database, which allows patient records to be transmitted to medical organisations.
"This delivers role-based security, audit trails and a straightforward way of enforcing information governance standards rather than relying on the vagaries of the internal post. I know there is a trend toward CfH-bashing but there are valuable lessons to be learned from the NHS which can be applied across the whole of government IT," Hart said.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Data Leakage Analysis & Insight
Do British police get cyber security?
Davey Winder listens to telephone conversations between the FBI and the Metropolitan Police, courtesy of Anonymous, and isn't impressed.
- Who to trust after the VeriSign hack?
- Striving to solve the security skills crisis
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- How the Data Protection Act's death will punish the UK economy
- Business of IT: Building a business case for security
- Q&A: Graham Palmer, Intel UK MD
- Is your enterprise making the same mistakes as the NHS?
- Enterprise security shoot-out: iPad vs. Android
Latest Data Leakage Reviews
TITUS Aware for Microsoft Outlook review
Rating: ![]()
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



