Showing posts with label information security breach. Show all posts
Showing posts with label information security breach. Show all posts

Sunday, 20 March 2016

The unencrypted hard drive - missing from a prison…



The Information Commissioner’s Office really had no choice but to come down hard on the National Offender Management Service recently, after a portable hard drive used to back up the prisoner intelligence database went missing from a prison security department.

Although nobody knew when it had actually gone missing, it could have been gone for almost a week since it had last been used on 18 May 2013 for the weekly back up - but was missing when staff went to back up six days later. It had not been locked in the fireproof safe afterwards, contrary to policy.  Not only was it missing, it was also unencrypted and had not been password protected. It contained sensitive information about almost 3000 prisoners, including names and dates of birth, length of sentence, offence(s), physical descriptions and distinguishing marks, plus intelligence information about drug use and links to other prisoners or organised crime - certainly not the sort of details you’d want to lose.

Although only nine staff members had access to the area where the hard drive was used and the area was controlled by a keypad system, the door to the Security Department could be opened by anyone on the prison staff.

To make matters worse, this wasn’t the first time something like this had happened. Back in October 2011, an almost identical breach involving 16,000 prisoners in another establishment had taken place, and the ICO had been told that because of this, encrypted hard drives had been supplied to 75 prisons that had been using unencrypted portable hard drives to back up prisoner intelligence information. Unfortunately, nobody realised that the encryption software required manual activation and the IT provider was never asked to check that the encryption software was working, so all the 75 prisons carried on using insecure portable hard drives for at least a year afterwards.

The software has now been activated and automatic upgrades enabled. The hard drive was never recovered although it doesn’t appear to have been accessed and there was no evidence that it fell into the wrong hands.

Because there had already been a virtually identical serious breach, the Commissioner considered that this was a very serious contravention of the seventh data protection principle;
Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”

The National Offender Management Service was fined £180,000. It just underlines the fact that even though you think you’re doing everything you can to comply with the rules, sometimes it can be the simplest thing you overlook that can lead to a damaging security breach. 

Do you know where your backup drives are kept, and have official policies in place to ensure that they don’t go missing? Are the drives encrypted? Can you imagine what would happen if the personal information you keep backed up were to be lost, either for your business or your clients? If you’re unsure of how to make sure that this sort of faux pas doesn’t ever happen to you, contact me and I will be delighted to provide you with guidance and advice.

Sunday, 14 February 2016

Help, it's all gone Pete Tong (wrong)! What to do when a data breach happens.

I was at a conference the other day where the speaker said that information security is low on the list of a company's priorities until it goes wrong.There was a discussion about Talk Talk and how the weakness in their cyber security was well known in IT circles. How much would it have cost Talk Talk to make the necessary changes to the system? I am guessing significantly less than the £80m it has cost them in the four months since the breach.

So what is a data breach? Simply this is when personal information ends up somewhere it isn't supposed to. The big breaches that hit the press involves lots of people's information but in smaller companies it can be as simple as a letter intended for one person being incorrectly sent to someone else, a spreadsheet of information being sent to the wrong email address or a fax being sent to the wrong number. It should not take your organisation to lose lots of information before it takes action. Each breach is an indication that there is something wrong with your systems, whether that be the actual process followed, the equipment or failing to train the individual. Learn from it.

A report by PWC shows that almost all businesses had experienced at least one data breach incident in the past year, with 90% of large organisations and 74% of small businesses reporting a security breach in the survey. In addition to the reputational damage and the cost of "fixing" the weakness, there is the disruption to the business.

The most costly breaches are malicious or criminal attacks, such as hacking.

Negligent employees are the top cause of data breaches.

In many organisations, the same personal information is available to a number of different departments, this increases the potential of a breach as more staff have access. Personal information is a valuable business asset, yet we don't always treat it that way.

So what happens when it goes wrong and there is a data breach?

Here's your basic action plan:
1 - Can you get it back? Do you know where it is and can you retrieve it?
2 - Do you know what information has been breached, who it is about and what the information was? In this case you will need to consider whether the information that has been released could cause potential damage or distress to the individual. You may then need to contact affected individuals and inform them of the breach. You may also need to contact the ICO and notify them of the breach.
3 - Investigate and remedy how the breach occurred so that further breaches are avoided. This may involve specialist advice or skills.
4 - Contact the police if applicable.
5 - Continue to update those who need to know with information about the incident.
6 - Create a policy which shows how you will handle a loss of data. This helps everyone understand what they should be doing.
7 - Train your staff in data protection compliance so they understand the importance of good data management and security.

Please remember that these are the basics, I would always advise that you seek professional advice for your circumstances. Remember you have already made a mistake by losing the information, don't compound it by not dealing with the breach correctly.

If you would like to discuss your data protection arrangements then please get in touch. 

Sunday, 31 January 2016

Data Protection Training - Are you doing it for your staff (and Volunteers)?

The Information Commissioners Office has reprimanded the Alzheimer's Society for a number of breaches of the Data Protection Act, including failing to provide regular training to staff and volunteers on Data Protection Compliance.

The enforcement notice states that the charity has failed to comply with two data protection principles and has issued a set of ten action points which need to be complied with within a period of six months.

The key issue is that the charity has not been training its staff or volunteers on a regular basis with regard to the requirements of the Act. This has led to breaches of the Act, probably due to lack of knowledge. So what do you need to do to avoid the wrath of the ICO?

All organisations should be regularly training their staff (and volunteers) in the requirements of the Data Protection Act at least every two years. 

So what should your training cover? As a minimum you would want to inform all staff:
  • Who the Data Protection Officer
  • What personal information is
  • How information should be collected, stored and destroyed
  • The time-scales for destruction (i.e. a retention policy)
  • An awareness of the checks they should be undertaking before providing information to someone (Subject Access Requests)
  • How to ensure that sharing information via email is carried out securely
  • The constraints on using their own devices for work purposes.
An organisation should also have policies and procedures to support these elements. Remember, these are THE BASICS! 

Any training undertaken should be recorded as to what the training covered, who attended and the date. You will need to keep these records in case of an issue with the ICO at a later date. Showing that you have trained the staff (and volunteers) on a regular basis shows a commitment to compliance with the Act.

If you have any questions or want to run a training session for your staff, we run in house courses tailored to your needs, so please contact me.

Sunday, 20 December 2015

Data loss - the obvious ways your business can avoid it



The top reasons cited for data loss from small businesses aren’t international hacking or grand scale cybercrime -  they are obvious, easily rectified things that would have been avoidable with a little advance attention to detail, proper training and a staff data security policy.

According to surveys, a staggering more than 78 per cent of organisations worldwide report that they have suffered from one or more data breaches in just the last two years. If you want to avoid your business being affected by careless data loss, you need to make sure that all employees - including you - are fully aware of the risks.

Surprisingly, one of the top reasons businesses lose data is that many employees (and their managers) still don’t understand the importance of not opening unexpected or suspicious attachments or clicking links embedded in spam emails. Other basic measures such as leaving systems unattended, visiting restricted websites and not changing passwords regularly also led to critical business data becoming at risk from data-stealing cybercriminals and malicious insiders.

It’s estimated that cyber criminals steal as much as US$1 billion a year from SMEs in the US and Europe. This is partly down to inadequate or poorly enforced data security policies, leaving companies at a risk of losing vital and sensitive data, as well as costing money through lost productivity, revenue and of course, if the breach becomes public, the business reputation too.

Working from home and being able to take work out of the office makes working life easier but can be a nightmare for data security. With an estimated 56 per cent of employees reporting that they either very frequently or frequently stored sensitive data on their laptops, smartphones, tablets, and other mobile devices, the chances of confidential information getting lost or into the wrong hands are very high. Protecting data on mobile devices can be as simple as encrypting it and/or password protecting it - it won’t stop the devices being lost but IT admin will be able to selectively remove sensitive encrypted data and the chances of someone using it maliciously are much smaller if it’s not possible to get straight into any files that may be sensitive.

Do you back up your data on a regular basis or just when you remember? Regular backups are a vitally important part of a good data security policy, so make it a regular daily, weekly or at least regular task. Automate it if possible so that it doesn’t get missed. Without an automated backup and recovery strategy in place, your business may well be devastated if the worst happens, and if you want to avoid unnecessary downtime, loss of revenue and more in the event of a serious incident, you need a contingency plan in place at all times.

Lastly - even if you have a top notch data security policy, it’s of no use unless you enforce it.
If you need advice on up to date data security procedures and policies that keep your sensitive data safe, or want to know more about staff training, contact me and I will be delighted to provide you with guidance and advice.

Sunday, 14 June 2015

Paper Forms - Do you have the basics in place?

It's been a busy week and whilst I have been out and about I have needed to complete some forms. I completed three different forms and not one of them met the requirements of the Data Protection Act with regard to collection notices.
Most of the forms were collecting basic details -  the usual - name, address, DOB. The forms were being used by a health professional, charity and college.

So what did I learn this week. Ultimately most of the organisations who collected information about me did not even meet the basic requirements of a collection notice on the form. A collection notice tells the person providing the information what their information will be used for, how it will be stored and for how long and if it is going to be shared with anyone. I have asked each of the organisations for whom I have completed a form what they intend to use my information for. It is worrying that if an organisation cannot even collect the information properly, how are they storing it and who has access to it. Given the significant rise in identify theft, I have provided enough information for this to happen.

Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law!

If you need help to produce a collection notice or require a review of your forms, please contact me.


Sunday, 7 December 2014

Here's how to deal with an information security breach......

We all hope that we will not be the subject of an informations ecurity breach but the chances are that all organisations will have a form of data breach at some time. Your effective response to an information Security Breach may have an impact on your company's public profile and the costs involved with the breach.
  • Have a plan. Don't wait to have a security breach before deciding what you should be doing in the event of one. Have a strategy in place that you can bring into action as and when the breach occurs.
  • Avoid Panic. Whether you are CEO, CIO, or any other senior officer, an information security breach can be alarming, but you should not panic. Evaluate the situation and decide on a plan of action as you would with any other business problem.
  • Secure the System. Take appropriate steps to contain and control the breach, to prevent further unauthorised access to or use of the personal information. You should preserve records and any other evidence. If the breach involves a lost or stolen computer or other portable media, secure any back-up files that show the information contained in the compromised system. It is helpful to make a mirror image of the records on your computer system or perform a comprehensive backup to ensure the preservation of information.
  • Organise a Response Group. You should take steps to ensure that other key members of staff and board members are notified of the information breach. Decide on a group who can make decisions to deal with the breach. the team should comprise of people who have technical expertise to deal with the situation and also who understand the nature of the information which has been breached and can advise on the information which may have been compromised or is at risk.
  • Retain Outside Advice. Retain outside advisors who have relevant expertise to help you decide upon a strategy, manage an internal investigation and comply with any notice or regulatory requirements.
  • Engage a Computer Forensic Investigator. Enlist the services of a firm specialising in computer forensics, cyber-crime response, internal investigations, and the preservation, analysis and production of electronic data.
  • Notify the relevant authorities. This should include the Information Commissioners Office if the breach is severe enough. Other organisations may include your insurer and the police depending on the type of breach.
  • Plan a Media Response. Any company which has been the subject of an information security breach should consider how they are going to deal with the press enquiries which may result. A severe breach which results in an ICO investigation will bring an interest in t the organisations which may need professional media experts to handle effectively. Any public statement should be factually accurate but reassure customers, potential customers and staff.
  • Review Your Company’s Privacy and Data Security Policies. If your company has adopted written privacy or data protection policies, review them to assess the company’s compliance with those policies in the context of the incident. Any response to the incident should be consistent with your internal policies. Also consider whether additional staff training is required to enforce the correct procedures when dealing with personal information.
  • Check Your Insurance. Check your insurance policies and other policies for potential coverage. Take the steps necessary to ensure that you do not lose insurance coverage by failing to give the required notice to the insurer or to meet any other procedural requirements. Make sure that you understand the company’s indemnity obligations under contracts with any third party involved in the incident, such as a client or vendor.
If you need any help or advice, we would love to help. Please contact me for further information at ask@audit-and-risk.co.uk