Are IT suppliers to blame for government data breaches?
By Nicole Kobie,
The government is unfairly targeted for data breaches that are in fact caused by IT suppliers, a Home Office director said today.
The Home Office's group commercial director John Collington made the claim at the Government Computing Live conference in London today, as he explained what happened when a data breach hit last year.
The incident in question was the loss of a memory stick containing data on all 84,000 UK prisoners by an employee of contractor PA Consulting in August last year.
Collington was on vacation when an email popped up on his BlackBerry with the subject line “Urgent: Data Loss”. Upon arriving back in the UK, the Home Office had set up a “disaster recovery team” to handle the loss.
He was told a member of a services supplier's staff had lost a memory stick. The contract in question was worth about £500,000 – a fairly small one by Home Office standards – and involved taking data from the prison service to share with police, to let them know when prisoners were due for release.
To do that, data was merged between the two agencies. To ensure security, that was only done in a secure environment inside known offices. However, the employee in question transferred the entire data set onto an unencrypted memory stick in order to move it onto a laptop she was working on. The stick then disappeared.
The employee immediately told her supervisors, who promptly told the Ministry of Justice (MoJ) and the Home Office. The police were brought in to search the offices and the employee's home and car for the missing memory stick, but it was never found.
Collington described the incident as “genuine human error,” and said that despite this, the “Home Office was vilified in the press,” with headlines calling the department “incompetent” – despite the error being made by the consultancy firm. “It's the MoJ that have blundered, it's HMRC that have blundered... it's rarely the supplier that's blamed,” Collington said.
In the end, PA Consulting did take a hit, very publically losing the contract, with the work brought back in-house. The employee was punished, too. “She lost her job. Her manager lost his job. Their manager lost their job as a consequence of that particular incident,” Collington said.
Now, the Home Office has told suppliers and their own staff not to use data sticks anymore, and to “think carefully before using laptops.” But processes alone are not enough. Collington wondered why the employee would choose to handle the data in such an insecure way, but noted that “kind of behaviour is prevelant.”
Indeed, Collington said the government isn't the only organisation which needs to rethink its data handling – suppliers need to, as well. “The culture change required needs to be embedded within each of our suppliers,” he said.
Fellow panellist William Heath, of data consultancy Crtl-Shift, disagreed with the idea of putting the blame on private contractors, however. He noted that suppliers are simply “part of a systemic and cultural problem” across the government's data plans.
Click here for the lessons the government needs to learn to avoid data breaches.
Sponsored Links
advertisement
Latest Public Sector Analysis & Insight
Striving to solve the security skills crisis
The Cyber Security Challenge is doing a fine job, but flat registration growth and weak Government funding are cause for concern, Tom Brewster discovers.
- 2011: The year in news
- Are the cookie laws crumbling already?
- UK rural broadband: too little, and too late
- How the Data Protection Act's death will punish the UK economy
- Education: glad to be a geek
- Plugging public sector data leaks
- Going for Gold - IT at the London Olympics
- Fujitsu: out to steal HP market share
- What will Windows Mango mean for business?
Latest Public Sector Reviews
HTC Flyer review: First Look
- HP TouchPad review: First Look
- RIM BlackBerry PlayBook review - First Look
- MWC 2011: Acer Iconia A100 and A500 reviews – first look videos
- MWC 2011: HP TouchPad review - first look video
- MWC 2011: RIM BlackBerry PlayBook review - first look video
- MWC 2011: HP Pre3 review - first look video
- MWC 2011: Motorola Pro review - first look video
- MWC 2011: HTC Flyer tablet review - first look video
- MWC 2011: Samsung Galaxy Tab 10.1 review – first look video
advertisement
Most popular
- Will someone rid me of these troublesome Macs?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- Head to Head: Office 2010 vs Open Office 3.1
- Nokia Lumia 710 review
- Virgin 100Mbps rollout 'ahead of schedule'
- BT considering Ofcom price cap appeal
- A data shock warning for Orange customers
- Cisco announces 40GbE and 100GbE switching upgrades
- T-Mobile announces 'UK's first' fully unlimited deals
- BT announces FTTP 'on demand'
Latest News Videos in Public Sector
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.


