The Register® — Biting the hand that feeds IT

Feeds

Eden laptop theft sparks ID theft fears

Innocence lost

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

There's trouble in paradise after a third-party supplier lost a laptop containing the personal details of hundreds of workers at Cornwall's Eden Project. The theft of the PC from the car of a worker for Moorepay, the firm that handles the project's payroll, has sparked ID theft fears.

Information held on the PC included the names, addresses, bank particulars, National Insurance numbers for 500 workers at the attraction. It's unclear whether the payroll details of other firms were compromised by the attack.

Tim Smit, Eden's creator, told the BBC: "A computer containing the personal details of employees of a number of companies, including the Eden Project Ltd, has been stolen from the car of an employee working for a contracted payroll company. Suffice to say we are appalled at the lapse of security and are making sure that our personal data is never put in such a vulnerable position again," he added. Police are investigating the 1 June theft, which became public this week.

Security experts said the case highlighted the fact that a firm's security exposure was reliant on that of its suppliers. "As well as putting internal security measures in place - enterprises need to be more cautious regarding third party companies that they share sensitive information such as payroll details with," said Jamie Cowper, marketing director at data encryption firm PGP, "Without a thorough assessment of the threat status of companies such as Moorepay, existing security policies can easily be rendered useless." ®

Agentless Backup is Not a Myth

Latest Comments
Anonymous Coward

Security and working

1. If the employee works from home as part of his normal contract, what on earth is ANY company data doing on the laptop, rather than being reached over VPN on a secure, shared drive? How about back-up of changed data etc.?

2. If working from home is extra to the normal working hours, sort out the resourcing, that makes this necessary, to make it unnecessary.

3. As said, data on disc can be encrypted on the fly (lucky MAC OS users have this available as standard software).

4. Many laptops now can be secured by requiring a fingerprint to enable booting.

5. As has been said, data that really must be taken off site can be on a USB memory stick that can itself be secured with passwords, encryption etc..

Too many people honestly believe that nothing on their laptop is sensitive or believe that their presentations hold nothing confidential and, if lost, can be recreated within a few hours (my partner for one), whatever you tell them, whatever horror stories they read.

0
0
Anonymous Coward

hd encrption. childs play

such laptops SHOULD have hard drive encryption. even a basic auditor would be dumb not to ensure that was company policy. I can foresee that even with Vista, many companies just arent going to use BitLocker. 'too much effort' and 'you're very paranoid arent you?' would be the usual comments.

0
0

nine till five

Of course, Staff who can work from home as part of their contract should have a secure access. For the rest, if the employers didn't require staff to work well beyond their contracted hours they wouldn't be taking the stuff home to work on.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving