Feeds

Consumers baulk at returning to hacked stores

Breach of trust

Beginner's guide to SSL certificates

Consumers are wary about returning to shop at retailers that have been the subject of security breaches, according to a new study.

The survey of 1,200 UK consumers revealed that the majority would take their business elsewhere in the event of loss of customer data as a result of a security breach or hack attack.

One in seven of the high income earners among those quizzed in the poll confessed to having been the victim of data theft. Four in five (82 per cent) would expect to be notified immediately in the event of a data breach, an issue brought to the fore by the recent high profile security flap involving the loss of up to 45 million card records by discount retailer TJX.

One third of punters polled avoided putting their personal information online. Even so, 11 per cent of this group still became the victim of data theft, illustrating that the problem on data security extends beyond internet security.

Nearly all (95 per cent) the respondents to the survey expressed concern about some aspect of the security of their personal data, with 83 per cent singling out the security of credit and debit cards as their principle priority. A sizable minority (45 per cent) of those quizzed reckon banks and online retailers are not doing enough to protect their personal information.

More and more UK-based firms are deciding to outsource their database storage and management facilities overseas. The survey reveals that two in three (63 per cent) are concerned about the ability of data centres to protect their data, in the UK and abroad.

Paul Davie, chief exec of Secerno, the UK-based database security firm that sponsored the survey, said recent high-profile data breach cases are beginning to affect public attitudes. He called for US-style information security disclosure laws to be applied in Europe.

"Consumers have a right to be told immediately whenever their personal information may have been compromised, yet those companies holding personal data know that they are likely be punished when a breach becomes known - by loss of customers, damage to reputation, cost of clear up, and share price impact. This means that companies have an immediate disincentive to do the right thing in such cases," Davie said.

"A new legal framework is needed in Europe to force disclosure of breaches. Currently, there is no EU Directive to enforce disclosure – which means a TJX/TKMaxx could already have happened but, unlike US companies, European companies would not necessarily be obliged to warn their customers," he added. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.