About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Information Commissioner
Information Commissioner tells CEOs to be vigilant about data protection
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

ICO criticises chief executives for lax security

Level of security breaches is "inexcusable" and CEOs must do better

Dinah Greek, Computeract!ve 21 Apr 2008
ADVERTISEMENT

Information Commissioner Richard Thomas has said that the “alarming” number of security breaches reported to his Office in the past six months is “inexcusable.”

Since the security breach at HM Revenue and Customs in November last year, the Information Commissioner’s Office (ICO) has been notified of almost 100 data breaches by public, private and third-sector organisations.

Of the security breaches that the ICO has been made aware of by private sector organisations, half were reported by financial institutions. Of those reported by public bodies, almost a third occurred in central Government and associated agencies and a fifth in NHS organisations.

He reiterated a warning to chief executives about the vital importance of protecting staff and customers’ personal information.

Information Commissioner Richard Thomas said: “It is particularly disappointing that the HMRC breaches have not prevented other unacceptable security breaches from occurring. The Government, banks and other organisations need to regain the public’s trust by being far more careful with people’s personal information.

“Once again I urge business and public sector leaders to make data protection a priority in their organisations. The level of understanding about data protection and the need to safeguard people’s personal information have no doubt increased and I am encouraged that more chief executives and permanent secretaries appear to be taking data protection more seriously. But the evidence shows that more must be done to eradicate inexcusable security breaches.”

Information that has gone missing includes unencrypted laptops and computer discs, memory keys and paper records. Information has been stolen and gone missing in the post and while in transit with a courier. The material includes a wide range of personal details, including financial and health records.

The ICO is investigating the circumstances of the breaches. In 16 cases the ICO has required the organisation to make procedural changes to improve data security, such as encryption. In three instances the lost information has been recovered.

The ICO encourages organisations to report data breaches and can advise on dealing with breaches and notifying affected customers. The ICO has recently published new guidance for organisations on how to deal with security breaches. A copy of the ICO’s Guidance on data security breach management can be downloaded.

See also:

Cards give access to patient records  08 Feb 2008
MPs want to make the punishment fit the crime  03 Jan 2008
Public should be protected from cyber-criminals and 'idiots' who break the data protection laws  05 Dec 2007
image: cdLib Dem steps in as Government admits security error could happen again  28 Nov 2007
Loss is "one of the world's biggest ID protection failures"  20 Nov 2007
shoppingDetails of 26,000 M & S employees could be at risk  11 May 2007
Image of the EU flagEuropean Commission to make retailers declare theft of customer data under proposed directive  16 Apr 2007
Has your card been maxed out to the limit?  30 Mar 2007
image: Barclays bank logoCustomers' details discarded into bins  16 Mar 2007

All Internet Privacy & Data Protection

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Central London, United Kingdom | MI5 Security Services
Windows Technician - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help us ... more >
NEWCASTLE UPON TYNE, Tyne And Wear, United Kingdom | EDS
Position # 396338 Job Description We require a Network Architect who is responsible for the day to day technical oversight of the GNE organization within their assigned account. The GNE Network Architect is responsible for ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT