Lessons to learn from a year of data breaches

In the year since the HMRC data breach, many more have been made public – here’s a roundup of 11 lessons (we should have) learned.

Merchant Securities Group was fined 77,000 even though it didn't even have a security breach, but simply because its methods risked enabling one.

At the time, Margaret Cole, the director of enforcement at the FSA, said: "It is unacceptable that despite increased awareness of data security issues, a firm should be so careless about its systems for protecting customers' personal details. People have a right to expect their details to be kept secure and firms should be committed to treating their customers fairly in all aspects of their business." Right on, Margaret. Right on.

Lesson 11: The ICO needs more powerOf the 277 data breaches the ICO has investigated over the past year, it's taking action against 30 organisations. That's not a lot.

The actions it can take generally consist of sending an angry letter demanding changes to processes, to ensure the guilty body learns to comply with the Data Protection Act. For the most part, this means deleting unnecessary data and encrypting portable media devices which is what the watchdog made Virgin Media do in the wake of a lost disc.

Advertisement
Advertisement - Article continues below

Under the threat of prosecution, most organisations seem to just buy some encryption software and get on with business. Not really much of a deterrent, is it?

Members of the government and the information commissioner himself have all called for stronger powers. Thomas said last year that his limited powers were a "very bizarre situation, unlike virtually all the other data protection authorities around the world and most other regulatory bodies, such as the Financial Services Authority."

Indeed, until the watchdog gains the power to fine like the FSA or data breaches become criminalised, it's going to continue to be little more than a source of good advice often ignored and some nasty letters now and then.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/operating-systems/microsoft-windows/354297/this-exploit-could-give-users-free-windows-7-updates
Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019