Showing posts with label data privacy. Show all posts
Showing posts with label data privacy. Show all posts

Sunday, 12 June 2016

Does your unsubscribe work?

I have been receiving spam email, lets face it who doesn't?

So I tried to unsubscribe and the link didn't work it took me to the contact us page of the financial services company. On this page there was a complaint phone number which I called. This took me to a menu where the selections all related to credit card applications, so as well as not keen on your unsubscribing, they weren't keen on you complaining either. When I eventually got through to a human I asked to speak to their Data Protection Officer and was told they didn't have one! I asked about unsubscribing and they said they would take my details and pass them on (they weren't sure who to). Really!

Anyway while I was holding on for a person to answer the phone, I went online and reported them to the ICO for spamming me, so my time wasn't wasted ;-)

Always check that your unsubscribe function works. You don't want someone to report you to the ICO while they wait.

Make sure your staff are adequately trained and you have a named person who knows how to deal properly with the data protection queries.

Sunday, 17 April 2016

Incident Trends for Data Protection Breaches


The Information Commissioners Office has published the list of ways in which personal data has been inadvertently disclosed over the last quarter. This is based on the information received by the ICO. There are undoubtedly a significant number of breaches which are never disclosed to the ICO but those that are show a definite trend.

The graph below is reproduced from the ICO website. Here's the link to the full page https://ico.org.uk/action-weve-taken/data-security-incident-trends/
 
Data security incidents by type
Top of the incidents reported is sending an email to the wrong person. Surprisingly this is followed by information being posted or faxed to the wrong person. In contrast, providing personal information verbally to the wrong person is quite low. Is this because we are more sceptical about providing information over the phone or in person to someone? The training provided by companies often focusses on this area and that may also be why this figure is so low.

The above list should be an indication to all organisations of the key areas where there is scope for losing personal information, so what steps do you have in place to make sure that information is not leaked or disclosed from your organisation in the same ways?

Monday, 28 March 2016

Do you have a strong password?

Recently the most used passwords were announced by Splashdata. You can follow the link to see the list - https://www.teamsid.com/worst-passwords-2015/.

The top three being password, 123456 and 12345678.

Passwords used to be simple 6-8 character words but with so many software packages able to crack simple passwords, we need to ensure that the most common source of security works for us. Here are some basic rules. At a recent security seminar, a speaker was suggesting that a password needed to be at least 25 characters long to be effective! (try remembering numerous 25 character passwords)

1. Make sure you use a password that is not linked to you personally, so no names, birthdates, addresses, pet names, children names, etc.

2. The best passwords are a mixture of lower case and upper case characters, numbers and symbols and should be at least 10 characters long.

3. The longer the password, the more difficult you make it for a hacker to access your information.

4. Make sure you have different passwords for different things. Your work passwords should be different from your personal ones.

5. Change passwords regularly, at least every three months and more regularly for sensitive information access. Work based computer systems can be set to prompt the change of password on a regular basis and this should be part of your password policy.

6. Do not write your passwords down on a sheet of paper or on a post it note stuck by the desk  - I have been to a number of organisations where this was the case!

7. For businesses, do not share passwords between colleagues. Each member of staff should have their own individual login and you shouldn't share your passwords with someone else.

8. Do not use characters which are adjacent to each other on the keyboard. So no qwerty, zxcvbnm, etc.

9. One of the best ways to create a password is either to use a phrase, song lyric or opening sentence of a book.You could use the initials of the sentence instead of the whole sentence if you want, even better if you add punctuation as well.

10. If you are using your web browser to store your passwords for websites make sure you use the master password option, otherwise anyone who has access to your machine has access to all your passwords.

11.There are online security services which can help users safeguard passwords, these include LastPass, DashLane, and 1Password. These store passwords and user names in the cloud and are secured with a master password (make sure it is a strong password). Additionally, there are ones which will store passwords on your computer, these include RoboformPasswordSafe or Keepass. If you can't remember the master password you are pretty much out of luck.

As your password is one of the key lines of security for your information, make it the best it can be.