Feeds

Norwich Union Life fined £1.26m for security holes

Bullet proof policies - if you're a director

Providing a secure and efficient Helpdesk

The Financial Services Authority (FSA) has fined Norwich Union £1.26m for failing to safeguard customers against fraud.

The City regulator said it had slapped the firm's UK life insurance biz, Norwich Union Life, with a record-breaking financial penalty because of a number of glaring system weaknesses which exposed confidential customer data to fraudsters.

Security lapses in the firm's caller identification procedures allowed fraudsters to impersonate customers by using information, including names, addresses, and telephone numbers, obtained from public sources such as Companies House.

The FSA said Norwich Union Life first learned that it was the victim of organised fraud in April last year. This led to 74 life policies being falsely surrendered with funds, said to be worth a total of around £3.4m, paid out to accounts controlled by the criminals.

A further 558 policies were also put at risk where fraudulent attempts had been made.

Norwich Union Life had failed to assess the risks posed to its business by financial crime and also failed in its duty of care to its customers in a timely manner, said the FSA.

The regulator added that by the end of July 2006, Norwich Union Life discovered that a number of current and former directors of the firm and its parent company Aviva had been hit by the fraud scam. It identified and quickly informed nine of its directors that their life policies had been targeted.

The FSA said Norwich Union Life prioritised protecting the risks posed to policyholders who were Aviva directors rather than responding to the security loophole in its caller identification system that exposed its seven million strong customer base to possible fraud.

A number of FSA recommendations were issued to the life insurance provider in May last year, including a suggestion that callers wanting access to their account must give their policy numbers over the phone.

Norwich Union Life ignored that advice on the grounds that it would impact customer service before backing down in October 2006 when it finally implemented the changes.

FSA director of enforcement Margaret Cole said the fine sent out "a clear message" that the regulator takes information security seriously.

"Norwich Union Life let down its customers by not taking reasonable steps to keep their personal and financial information safe and secure.

"It is vital that firms have robust systems and controls in place to make sure that customers' details do not fall into the wrong hands. Firms must also frequently review their controls to tackle the growing threat of identity theft," she said.

Norwich Union Life apologised to its customers for the monumental security cock-up and said it had taken appropriate steps to prevent such a problem arising in the future.

"Whilst the number of customers affected is very small compared to the number of policies we manage overall, any breach in customer confidentiality is clearly unacceptable.

"Our customers can, however, be assured that we have taken this matter extremely seriously and have thoroughly reviewed our systems and controls as a result," said Norwich Union Life CEO Mark Hodges.

The firm has until 31 December to pay the fine to the FSA in full. Norwich Union said it will compensate all the customers affected by the frauds. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Lords take revenge on REVENGE PORN publishers
Jilted Johns and Jennies with busy fingers face two years inside
Yes, yes, Steve Jobs. Look what I'VE done for you lately – Tim Cook
New iPhone biz baron points to Apple's (his) greatest successes
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.