Showing posts with label weaknesses. Show all posts
Showing posts with label weaknesses. Show all posts

Sunday, 14 February 2016

Help, it's all gone Pete Tong (wrong)! What to do when a data breach happens.

I was at a conference the other day where the speaker said that information security is low on the list of a company's priorities until it goes wrong.There was a discussion about Talk Talk and how the weakness in their cyber security was well known in IT circles. How much would it have cost Talk Talk to make the necessary changes to the system? I am guessing significantly less than the £80m it has cost them in the four months since the breach.

So what is a data breach? Simply this is when personal information ends up somewhere it isn't supposed to. The big breaches that hit the press involves lots of people's information but in smaller companies it can be as simple as a letter intended for one person being incorrectly sent to someone else, a spreadsheet of information being sent to the wrong email address or a fax being sent to the wrong number. It should not take your organisation to lose lots of information before it takes action. Each breach is an indication that there is something wrong with your systems, whether that be the actual process followed, the equipment or failing to train the individual. Learn from it.

A report by PWC shows that almost all businesses had experienced at least one data breach incident in the past year, with 90% of large organisations and 74% of small businesses reporting a security breach in the survey. In addition to the reputational damage and the cost of "fixing" the weakness, there is the disruption to the business.

The most costly breaches are malicious or criminal attacks, such as hacking.

Negligent employees are the top cause of data breaches.

In many organisations, the same personal information is available to a number of different departments, this increases the potential of a breach as more staff have access. Personal information is a valuable business asset, yet we don't always treat it that way.

So what happens when it goes wrong and there is a data breach?

Here's your basic action plan:
1 - Can you get it back? Do you know where it is and can you retrieve it?
2 - Do you know what information has been breached, who it is about and what the information was? In this case you will need to consider whether the information that has been released could cause potential damage or distress to the individual. You may then need to contact affected individuals and inform them of the breach. You may also need to contact the ICO and notify them of the breach.
3 - Investigate and remedy how the breach occurred so that further breaches are avoided. This may involve specialist advice or skills.
4 - Contact the police if applicable.
5 - Continue to update those who need to know with information about the incident.
6 - Create a policy which shows how you will handle a loss of data. This helps everyone understand what they should be doing.
7 - Train your staff in data protection compliance so they understand the importance of good data management and security.

Please remember that these are the basics, I would always advise that you seek professional advice for your circumstances. Remember you have already made a mistake by losing the information, don't compound it by not dealing with the breach correctly.

If you would like to discuss your data protection arrangements then please get in touch. 

Sunday, 29 November 2015

What is your process for checking outgoing email attachments?



This case really showcases the importance of keeping track of all of the information that comes from your business!

On 2 August 2011 a member of the public reported that they had received an email from HMP Cardiff with a file accidentally attached that contained the details of 1,182 inmates. As if that wasn’t bad enough, it wasn’t the first time the mistake had been made - on 4th and 5th July 2011 the prisoner details had been sent to two other unintended recipients who hadn’t yet contacted the data controller or the prison. 

A total of three emails with the attachment had been sent to three different individuals, after a new prison booking clerk had been arranging the prison visits. The clerk had only meant to email a family member about a visit but had accidentally pasted the text file as an attachment. All three mistakes were made by the same clerk, doing the same thing by accident. Because the file had to be manually cut and pasted on a daily basis onto a disk, and then saved onto a database, the paste action had picked up the last file from the clipboard instead of the correct one and accidentally sent the sensitive data - three times.

Once the mistake had been discovered, the police became involved and each recipient was asked to confirm in writing that the message had been deleted and not shared. The police even accessed their email accounts to make sure that it had been fully deleted. 

HMP Cardiff has since put in place measures to stop this ever happening again; existing training and on-going support is now topped up with monthly checks and the data transfer procedure has been changed so that rather than a disc, an encrypted memory stick is used for data transfer. And instead of copying and pasting it to the stick, staff are told they have to locate the text file and use the ‘send to’ function, which stops it being left on the clipboard to be pasted where it ought not to be.

Most of us would cringe, just thinking about a mistake like this - how many times have you attached the wrong document to an email or not attached it at all? When you’re dealing with sensitive data though, the repercussions can be extremely serious. The National Offender Management Service was fined £140,000 for the breach.

This error, made by an inexperienced member of staff, would not even have come to light if the third person who had received it hadn’t realised the seriousness of the mistake and reported it. Is it possible that this sort of thing could happen to you? What measures do you have in place to prevent sensitive data being accidentally shared with the wrong people?

Do you have a contingency plan in place for emails, and for protecting sensitive information? If you need advice on procedures and policies that keep your information safe, contact me and I will be delighted to provide you with guidance and advice.

Sunday, 7 December 2014

Here's how to deal with an information security breach......

We all hope that we will not be the subject of an informations ecurity breach but the chances are that all organisations will have a form of data breach at some time. Your effective response to an information Security Breach may have an impact on your company's public profile and the costs involved with the breach.
  • Have a plan. Don't wait to have a security breach before deciding what you should be doing in the event of one. Have a strategy in place that you can bring into action as and when the breach occurs.
  • Avoid Panic. Whether you are CEO, CIO, or any other senior officer, an information security breach can be alarming, but you should not panic. Evaluate the situation and decide on a plan of action as you would with any other business problem.
  • Secure the System. Take appropriate steps to contain and control the breach, to prevent further unauthorised access to or use of the personal information. You should preserve records and any other evidence. If the breach involves a lost or stolen computer or other portable media, secure any back-up files that show the information contained in the compromised system. It is helpful to make a mirror image of the records on your computer system or perform a comprehensive backup to ensure the preservation of information.
  • Organise a Response Group. You should take steps to ensure that other key members of staff and board members are notified of the information breach. Decide on a group who can make decisions to deal with the breach. the team should comprise of people who have technical expertise to deal with the situation and also who understand the nature of the information which has been breached and can advise on the information which may have been compromised or is at risk.
  • Retain Outside Advice. Retain outside advisors who have relevant expertise to help you decide upon a strategy, manage an internal investigation and comply with any notice or regulatory requirements.
  • Engage a Computer Forensic Investigator. Enlist the services of a firm specialising in computer forensics, cyber-crime response, internal investigations, and the preservation, analysis and production of electronic data.
  • Notify the relevant authorities. This should include the Information Commissioners Office if the breach is severe enough. Other organisations may include your insurer and the police depending on the type of breach.
  • Plan a Media Response. Any company which has been the subject of an information security breach should consider how they are going to deal with the press enquiries which may result. A severe breach which results in an ICO investigation will bring an interest in t the organisations which may need professional media experts to handle effectively. Any public statement should be factually accurate but reassure customers, potential customers and staff.
  • Review Your Company’s Privacy and Data Security Policies. If your company has adopted written privacy or data protection policies, review them to assess the company’s compliance with those policies in the context of the incident. Any response to the incident should be consistent with your internal policies. Also consider whether additional staff training is required to enforce the correct procedures when dealing with personal information.
  • Check Your Insurance. Check your insurance policies and other policies for potential coverage. Take the steps necessary to ensure that you do not lose insurance coverage by failing to give the required notice to the insurer or to meet any other procedural requirements. Make sure that you understand the company’s indemnity obligations under contracts with any third party involved in the incident, such as a client or vendor.
If you need any help or advice, we would love to help. Please contact me for further information at ask@audit-and-risk.co.uk