Showing posts with label cyber attacks. Show all posts
Showing posts with label cyber attacks. Show all posts

Sunday, 14 February 2016

Help, it's all gone Pete Tong (wrong)! What to do when a data breach happens.

I was at a conference the other day where the speaker said that information security is low on the list of a company's priorities until it goes wrong.There was a discussion about Talk Talk and how the weakness in their cyber security was well known in IT circles. How much would it have cost Talk Talk to make the necessary changes to the system? I am guessing significantly less than the £80m it has cost them in the four months since the breach.

So what is a data breach? Simply this is when personal information ends up somewhere it isn't supposed to. The big breaches that hit the press involves lots of people's information but in smaller companies it can be as simple as a letter intended for one person being incorrectly sent to someone else, a spreadsheet of information being sent to the wrong email address or a fax being sent to the wrong number. It should not take your organisation to lose lots of information before it takes action. Each breach is an indication that there is something wrong with your systems, whether that be the actual process followed, the equipment or failing to train the individual. Learn from it.

A report by PWC shows that almost all businesses had experienced at least one data breach incident in the past year, with 90% of large organisations and 74% of small businesses reporting a security breach in the survey. In addition to the reputational damage and the cost of "fixing" the weakness, there is the disruption to the business.

The most costly breaches are malicious or criminal attacks, such as hacking.

Negligent employees are the top cause of data breaches.

In many organisations, the same personal information is available to a number of different departments, this increases the potential of a breach as more staff have access. Personal information is a valuable business asset, yet we don't always treat it that way.

So what happens when it goes wrong and there is a data breach?

Here's your basic action plan:
1 - Can you get it back? Do you know where it is and can you retrieve it?
2 - Do you know what information has been breached, who it is about and what the information was? In this case you will need to consider whether the information that has been released could cause potential damage or distress to the individual. You may then need to contact affected individuals and inform them of the breach. You may also need to contact the ICO and notify them of the breach.
3 - Investigate and remedy how the breach occurred so that further breaches are avoided. This may involve specialist advice or skills.
4 - Contact the police if applicable.
5 - Continue to update those who need to know with information about the incident.
6 - Create a policy which shows how you will handle a loss of data. This helps everyone understand what they should be doing.
7 - Train your staff in data protection compliance so they understand the importance of good data management and security.

Please remember that these are the basics, I would always advise that you seek professional advice for your circumstances. Remember you have already made a mistake by losing the information, don't compound it by not dealing with the breach correctly.

If you would like to discuss your data protection arrangements then please get in touch. 

Sunday, 20 December 2015

Data loss - the obvious ways your business can avoid it



The top reasons cited for data loss from small businesses aren’t international hacking or grand scale cybercrime -  they are obvious, easily rectified things that would have been avoidable with a little advance attention to detail, proper training and a staff data security policy.

According to surveys, a staggering more than 78 per cent of organisations worldwide report that they have suffered from one or more data breaches in just the last two years. If you want to avoid your business being affected by careless data loss, you need to make sure that all employees - including you - are fully aware of the risks.

Surprisingly, one of the top reasons businesses lose data is that many employees (and their managers) still don’t understand the importance of not opening unexpected or suspicious attachments or clicking links embedded in spam emails. Other basic measures such as leaving systems unattended, visiting restricted websites and not changing passwords regularly also led to critical business data becoming at risk from data-stealing cybercriminals and malicious insiders.

It’s estimated that cyber criminals steal as much as US$1 billion a year from SMEs in the US and Europe. This is partly down to inadequate or poorly enforced data security policies, leaving companies at a risk of losing vital and sensitive data, as well as costing money through lost productivity, revenue and of course, if the breach becomes public, the business reputation too.

Working from home and being able to take work out of the office makes working life easier but can be a nightmare for data security. With an estimated 56 per cent of employees reporting that they either very frequently or frequently stored sensitive data on their laptops, smartphones, tablets, and other mobile devices, the chances of confidential information getting lost or into the wrong hands are very high. Protecting data on mobile devices can be as simple as encrypting it and/or password protecting it - it won’t stop the devices being lost but IT admin will be able to selectively remove sensitive encrypted data and the chances of someone using it maliciously are much smaller if it’s not possible to get straight into any files that may be sensitive.

Do you back up your data on a regular basis or just when you remember? Regular backups are a vitally important part of a good data security policy, so make it a regular daily, weekly or at least regular task. Automate it if possible so that it doesn’t get missed. Without an automated backup and recovery strategy in place, your business may well be devastated if the worst happens, and if you want to avoid unnecessary downtime, loss of revenue and more in the event of a serious incident, you need a contingency plan in place at all times.

Lastly - even if you have a top notch data security policy, it’s of no use unless you enforce it.
If you need advice on up to date data security procedures and policies that keep your sensitive data safe, or want to know more about staff training, contact me and I will be delighted to provide you with guidance and advice.

Sunday, 9 November 2014

ICO warns organisations about cyber security. Could you be at risk?

The Information Commissioners Office has suggested that organisations need to act to ensure that the information collected via their websites is secure. This is after a hotel booking website was hacked and the details of 3814 customers were accessed. You can read the full ICO comment here.

This isn't the first incident of websites being hacked for their customer details. In May 2014, Ebay was the subject of hackers and they advised all their account holders to change their password.

In April 2012, the British Pregnancy Advise Service website was hacked the name and logon details of the administrator leaked. At the time the ICO said “Ignorance is no excuse. It is especially unforgiveable when the organisation is handing information as sensitive as that held by the BPAS. Data controllers must take active steps to ensure that the personal data they are responsible for is kept safe."

Ernst and Young have researched cyber attacks and produced a report. Ernst and Young report. Cyber threats are regularly reported in the media and this indicates that attacks are becoming more sophisticated and persistent. If your organisation has not experienced an attack yet, it will no doubt be targeted.

PWC reports that cyber attacks have increased 41% over the last year and the report shows that most attacks are undertaken by a current employees.

Both the PWC and Ernst and Young report are interesting and show the importance of ensuring appropriate security and policies are in place.

If you would like some help identifying any potential weaknesses, please contact me at Lesley@audit-and-risk.co.uk. I shall be happy to help.