Showing posts with label Data. Show all posts
Showing posts with label Data. Show all posts

Sunday, 20 March 2016

The unencrypted hard drive - missing from a prison…



The Information Commissioner’s Office really had no choice but to come down hard on the National Offender Management Service recently, after a portable hard drive used to back up the prisoner intelligence database went missing from a prison security department.

Although nobody knew when it had actually gone missing, it could have been gone for almost a week since it had last been used on 18 May 2013 for the weekly back up - but was missing when staff went to back up six days later. It had not been locked in the fireproof safe afterwards, contrary to policy.  Not only was it missing, it was also unencrypted and had not been password protected. It contained sensitive information about almost 3000 prisoners, including names and dates of birth, length of sentence, offence(s), physical descriptions and distinguishing marks, plus intelligence information about drug use and links to other prisoners or organised crime - certainly not the sort of details you’d want to lose.

Although only nine staff members had access to the area where the hard drive was used and the area was controlled by a keypad system, the door to the Security Department could be opened by anyone on the prison staff.

To make matters worse, this wasn’t the first time something like this had happened. Back in October 2011, an almost identical breach involving 16,000 prisoners in another establishment had taken place, and the ICO had been told that because of this, encrypted hard drives had been supplied to 75 prisons that had been using unencrypted portable hard drives to back up prisoner intelligence information. Unfortunately, nobody realised that the encryption software required manual activation and the IT provider was never asked to check that the encryption software was working, so all the 75 prisons carried on using insecure portable hard drives for at least a year afterwards.

The software has now been activated and automatic upgrades enabled. The hard drive was never recovered although it doesn’t appear to have been accessed and there was no evidence that it fell into the wrong hands.

Because there had already been a virtually identical serious breach, the Commissioner considered that this was a very serious contravention of the seventh data protection principle;
Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”

The National Offender Management Service was fined £180,000. It just underlines the fact that even though you think you’re doing everything you can to comply with the rules, sometimes it can be the simplest thing you overlook that can lead to a damaging security breach. 

Do you know where your backup drives are kept, and have official policies in place to ensure that they don’t go missing? Are the drives encrypted? Can you imagine what would happen if the personal information you keep backed up were to be lost, either for your business or your clients? If you’re unsure of how to make sure that this sort of faux pas doesn’t ever happen to you, contact me and I will be delighted to provide you with guidance and advice.

Monday, 25 January 2016

Don’t leave your important information on the bus…



A school in York has been left red-faced after a member of the school staff left an unencrypted removable memory stick on public transport.

The Information Commissioners Office has launched an investigation after being made aware of the incident.  St Peter’s School in Clifton, which is one of York’s top public schools, admitted that there were a number of documents on the memory stick that related to school governance, and which could potentially include information about a ‘small number of individuals’ although thankfully there were no bank or financial details on the device. There was no suggestion that the information had been accessed or used by anyone since being lost in October.

The school's head, Leo Winkley, has also been forced to write to the parents of children at the school to inform them about the blunder, and is working with the ICO to make sure that all the correct procedures are followed - although it would have saved the school a great deal of trouble if they had simply encrypted their memory stick so that it was unusable without a password.
 
The loss has caused consternation in York as the device was said by a source to contain highly sensitive information about pupils and former pupils - and worryingly, the public transport operator has not been able to locate the missing memory stick - so nobody knows where it is, or whether it has been found by a member of the public and accessed.

A source told the York Press that they there had also been confusion with the ICO claiming to not know about the allegation, but after some investigation, subsequently confirmed that they were making enquiries into what had happened.

This case just underlines the necessity for all removable memory devices to be encrypted or password protected; with the best will in the world, memory sticks and other removable storage devices can go missing, but if the information is protected by a password, if it should be found by someone, the data will be protected from anyone unscrupulous using it.

Do you have a security policy in place and train your staff in how to protect sensitive information? If you’re unsure of how to protect your data, contact me and I will be delighted to provide you with guidance and advice.

Monday, 18 January 2016

Did you attend a training course? Whoopee, lets share your details!

I have been on a couple of business training courses over the last week. Both of them were signed up to online and neither told me what they would do with my information, so that's the first mistake!

When I got to the training courses, both provided an attendee list which showed name, business name and a brief outline of what the business does.

A few days later I received an email from the training company asking if they can share my contact details with the other attendees. If I do not wish to share my information I have 24 hours to send an email opting out. Mistakes 2 and 3.

The email requesting that I share my contact details does not tell me which contact details they are planning to share. They may have my postal address but definitely have my email address and mobile number as a minimum so are they planning on sharing all my contact details or just some of them and if so which ones?

Also by requesting that you respond by opting out, they run the risk of sharing someone's contact details who may not have had time to review their emails and respond within the timescale laid down but who doesn't want to share their information. They should have asked people to opt in.

So how could this have been done more effectively?
1 - When they collected the information, they should have said how they are going to hold that information and for how long.
2 - Will I be on a mailing list?
3 - Stating that it will be on an Attendee list.
4 - What information they plan to share with other delegates and seeking permission to do so.
All of this could have been completed at the time of sign-up.

It would have been more straightforward to tell all the attendees to find each other on LinkedIn and connect that way. Needing no facilitation by the training company. 

So with a bit of planning and some knowledge of Data Protection requirements, life could have been a lot easier for the training company. 

Sunday, 10 January 2016

The top three business security risks - and what to do about them




Businesses have been aware for many years of the very real threat to their business from security breaches, distributed denial-of-service (DDoS) attacks and more, but despite warnings from concerned security professionals about keeping better control over their sensitive data, many small businesses still aren’t taking security as seriously as they should.

If you have a feeling that this may well be you, what can you do to up your game when it comes to protecting sensitive data from security threats? First, you need to look at the most common causes - here’s our top three.

1: Resentful or disgruntled employees
A disgruntled member of staff can do a lot of damage to your internal security, especially one that has access to your networks, data centres and IT admin accounts. However hard you try, you’re not going to be able to eliminate staff dissatisfaction, so you need to mitigate the risks by identifying privileged accounts and credentials and deleting any that are connected to ex-employees who may have an axe to grind. Privileged accounts should be routinely monitored and there should also be a protocol in place to track, log and record activity on these accounts so that anything suspicious or malicious can be quickly spotted and dealt with.

2. Human error & lack of training
An employee who leaves their laptop unlocked and on a train is just as dangerous as an ex-employee who maliciously breaches your security.  If your employees aren’t properly trained in data security, they also pose a risk. Make sure that your employees are up to date on cyber security. Hold regular, mandatory training sessions so that they know the risks of weak passwords, unencrypted or non-password protected portable memory, and even basics such as not opening suspicious email attachments. It’s vital to drive the point home about passwords; they are the first line of data defence and so staff members need to know about basic rules;  choosing a password with upper and lowercase letters, numbers and symbols, keeping separate passwords for different sites and devices and changing them regularly. Encrypting data is another way of avoiding data breaches through human error; even if an employee hasn’t locked their phone, you can get the IT department to wipe any selected data just by revoking decryption keys specifically used for company data. You can then go a step further and use authentication methods like a One Time Password (OTP), smart card, fingerprint reader or even retina scanning if you need an extra layer of security.

3: Unpatched - or Unpatchable - Devices
If you have hardware such as servers, routers or printers that use software or firmware for which there’s no patch for vulnerability, or their hardware isn’t  designed to enable them automatic updating if a vulnerability is detected, it leaves you open to attack. Out of date servers are especially vulnerable; Microsoft no longer supports Windows Server 2003 and with an estimated 10 million or more Windows 2003 servers still being used, outdated servers are prime targets.
Put a patch management program in place to make sure that all of your hardware and software is constantly updated. Vulnerability management technology is available to check your network for anything that’s out of date, and a policy of taking anything that hasn’t been updated for a long time offline will also minimise the risk.

Do you know where your business is vulnerable? If you need advice on procedures and policies that keep your sensitive data safe, or want to know more about staff training, contact me and I will be delighted to provide you with guidance and advice.

Monday, 4 January 2016

Thinking of selling your email list? - think again

I have had an enquiry this week from a business owner who has been approached to sell their email list. Sounds simple doesn't it?

It is simple if you have collected the information in the right way and sought permission to share the information with other companies. If you haven't it can be a costly mistake to make, as Pharmacy2U found out. Pharmacy2U was fined £130,000 for selling its mailing list and other details without having the correct permissions to do so. A sobering and costly exercise.

So how do you know if you can sell your list? Broadly, when you collected the information, did you ask the subscriber whether they would be happy to have their information passed to a third party? If you didn't, then you shouldn't be selling the information. If you did and they agreed to the information being shared, then you can. I would suggest that you get a professional Data Protection Officer to review how the information was collected before you go through with the sale just to be sure that you have the correct permissions. You wouldn't want a request for £130,000 dropping through the letterbox.

If you need to discuss how you are collecting information, please contact me.



Sunday, 20 December 2015

Data loss - the obvious ways your business can avoid it



The top reasons cited for data loss from small businesses aren’t international hacking or grand scale cybercrime -  they are obvious, easily rectified things that would have been avoidable with a little advance attention to detail, proper training and a staff data security policy.

According to surveys, a staggering more than 78 per cent of organisations worldwide report that they have suffered from one or more data breaches in just the last two years. If you want to avoid your business being affected by careless data loss, you need to make sure that all employees - including you - are fully aware of the risks.

Surprisingly, one of the top reasons businesses lose data is that many employees (and their managers) still don’t understand the importance of not opening unexpected or suspicious attachments or clicking links embedded in spam emails. Other basic measures such as leaving systems unattended, visiting restricted websites and not changing passwords regularly also led to critical business data becoming at risk from data-stealing cybercriminals and malicious insiders.

It’s estimated that cyber criminals steal as much as US$1 billion a year from SMEs in the US and Europe. This is partly down to inadequate or poorly enforced data security policies, leaving companies at a risk of losing vital and sensitive data, as well as costing money through lost productivity, revenue and of course, if the breach becomes public, the business reputation too.

Working from home and being able to take work out of the office makes working life easier but can be a nightmare for data security. With an estimated 56 per cent of employees reporting that they either very frequently or frequently stored sensitive data on their laptops, smartphones, tablets, and other mobile devices, the chances of confidential information getting lost or into the wrong hands are very high. Protecting data on mobile devices can be as simple as encrypting it and/or password protecting it - it won’t stop the devices being lost but IT admin will be able to selectively remove sensitive encrypted data and the chances of someone using it maliciously are much smaller if it’s not possible to get straight into any files that may be sensitive.

Do you back up your data on a regular basis or just when you remember? Regular backups are a vitally important part of a good data security policy, so make it a regular daily, weekly or at least regular task. Automate it if possible so that it doesn’t get missed. Without an automated backup and recovery strategy in place, your business may well be devastated if the worst happens, and if you want to avoid unnecessary downtime, loss of revenue and more in the event of a serious incident, you need a contingency plan in place at all times.

Lastly - even if you have a top notch data security policy, it’s of no use unless you enforce it.
If you need advice on up to date data security procedures and policies that keep your sensitive data safe, or want to know more about staff training, contact me and I will be delighted to provide you with guidance and advice.