Feeds

Consumers baulk at returning to hacked stores

Breach of trust

SANS - Survey on application security programs

Consumers are wary about returning to shop at retailers that have been the subject of security breaches, according to a new study.

The survey of 1,200 UK consumers revealed that the majority would take their business elsewhere in the event of loss of customer data as a result of a security breach or hack attack.

One in seven of the high income earners among those quizzed in the poll confessed to having been the victim of data theft. Four in five (82 per cent) would expect to be notified immediately in the event of a data breach, an issue brought to the fore by the recent high profile security flap involving the loss of up to 45 million card records by discount retailer TJX.

One third of punters polled avoided putting their personal information online. Even so, 11 per cent of this group still became the victim of data theft, illustrating that the problem on data security extends beyond internet security.

Nearly all (95 per cent) the respondents to the survey expressed concern about some aspect of the security of their personal data, with 83 per cent singling out the security of credit and debit cards as their principle priority. A sizable minority (45 per cent) of those quizzed reckon banks and online retailers are not doing enough to protect their personal information.

More and more UK-based firms are deciding to outsource their database storage and management facilities overseas. The survey reveals that two in three (63 per cent) are concerned about the ability of data centres to protect their data, in the UK and abroad.

Paul Davie, chief exec of Secerno, the UK-based database security firm that sponsored the survey, said recent high-profile data breach cases are beginning to affect public attitudes. He called for US-style information security disclosure laws to be applied in Europe.

"Consumers have a right to be told immediately whenever their personal information may have been compromised, yet those companies holding personal data know that they are likely be punished when a breach becomes known - by loss of customers, damage to reputation, cost of clear up, and share price impact. This means that companies have an immediate disincentive to do the right thing in such cases," Davie said.

"A new legal framework is needed in Europe to force disclosure of breaches. Currently, there is no EU Directive to enforce disclosure – which means a TJX/TKMaxx could already have happened but, unlike US companies, European companies would not necessarily be obliged to warn their customers," he added. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.