Showing posts with label business efficiency. Show all posts
Showing posts with label business efficiency. Show all posts

Sunday, 3 April 2016

Who is letting your organisation down?

There have been a number of high profile data breaches by members of staff in organisations.

From the disgruntled Morrison's employee who leaked the salaries of staff onto the internet and was subsequently jailed for 8 years to the Tesco employee who was emailing details of customers to his personal email account and the Enterprise car rental employee who was selling customer information to a claims company, the main weaknesses in most organisations are the staff.

So what do you do about it? The cases shown above have been high profile and widely reported but organisations are probably suffering breaches on a regular basis and may not even be aware of them. We get used to what we see and do and so often we forgot to stand back and view the situation with fresh eyes. 

When I start to work with organisations, I am that fresh pair of eyes. I often also represent your clients. Are you collecting information to help you communicate effectively with them? We can easily identify the areas in your business where there is potential for losing your business information.

If you want to find out  more, we offer a free initial consultation so you can see how we would work with you. Contact us today to book a meeting.

Sunday, 20 March 2016

The unencrypted hard drive - missing from a prison…



The Information Commissioner’s Office really had no choice but to come down hard on the National Offender Management Service recently, after a portable hard drive used to back up the prisoner intelligence database went missing from a prison security department.

Although nobody knew when it had actually gone missing, it could have been gone for almost a week since it had last been used on 18 May 2013 for the weekly back up - but was missing when staff went to back up six days later. It had not been locked in the fireproof safe afterwards, contrary to policy.  Not only was it missing, it was also unencrypted and had not been password protected. It contained sensitive information about almost 3000 prisoners, including names and dates of birth, length of sentence, offence(s), physical descriptions and distinguishing marks, plus intelligence information about drug use and links to other prisoners or organised crime - certainly not the sort of details you’d want to lose.

Although only nine staff members had access to the area where the hard drive was used and the area was controlled by a keypad system, the door to the Security Department could be opened by anyone on the prison staff.

To make matters worse, this wasn’t the first time something like this had happened. Back in October 2011, an almost identical breach involving 16,000 prisoners in another establishment had taken place, and the ICO had been told that because of this, encrypted hard drives had been supplied to 75 prisons that had been using unencrypted portable hard drives to back up prisoner intelligence information. Unfortunately, nobody realised that the encryption software required manual activation and the IT provider was never asked to check that the encryption software was working, so all the 75 prisons carried on using insecure portable hard drives for at least a year afterwards.

The software has now been activated and automatic upgrades enabled. The hard drive was never recovered although it doesn’t appear to have been accessed and there was no evidence that it fell into the wrong hands.

Because there had already been a virtually identical serious breach, the Commissioner considered that this was a very serious contravention of the seventh data protection principle;
Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”

The National Offender Management Service was fined £180,000. It just underlines the fact that even though you think you’re doing everything you can to comply with the rules, sometimes it can be the simplest thing you overlook that can lead to a damaging security breach. 

Do you know where your backup drives are kept, and have official policies in place to ensure that they don’t go missing? Are the drives encrypted? Can you imagine what would happen if the personal information you keep backed up were to be lost, either for your business or your clients? If you’re unsure of how to make sure that this sort of faux pas doesn’t ever happen to you, contact me and I will be delighted to provide you with guidance and advice.

Sunday, 13 March 2016

Why hire a Data Protection Specialist?

When I am out networking, one of the questions I frequently get asked is "why do I need to hire a data protection specialist?".

There are lots of skills that an organisation is happy to buy in because they recognise that there is a need for specialist knowledge. You would always ask for legal advice when entering into a contract or lease, you obtain insurance advice as to the level of cover you require and the type of insurance that best suits your business, when implementing a new software package you would seek the advice of the software developers to ensure it meets your needs. So what stops you seeking qualified advice for your data protection compliance? 

The Data Protection Law is a complex piece of legislation and has been around for about 18 years; additionally over the years good practice guides and enhancements have been made. I have been a Data Protection Officer for about 12 years and I have studied for and gained the qualification to show that I have the skills and knowledge to provide advice to organisations.

There is lots of advice on the Information Commissioners Website (the regulator for data protection in the UK) and you can find out the basics there. If your business is complex, has more than 25 employees or holds personal information about an individuals health, well-being or criminal convictions, then you really need to get specialist advice.

A data protection specialist, like me, will look at your organisation and the information you are collecting and holding. They'll also provide tailored advice to protect the information you hold and also help you identify how to use it more efficiently. The requirements of the Data Protection Act should not be onerous as they are based on good practice for information security.

The cost of getting advice is likely be far less than any monetary cost that your organisation might suffer as a result of the loss of information, either through accidental or malicious means.

If you want to have a discussion with me about your organisation and how we can help, we offer a free initial discussion so contact us to see how we can help improve your use of the information you collect.