Feeds

Data loss fines hit £500K from today

Hundredfold increase to scare firms into shape

Top three mobile application threats

From Tuesday 6 April, the Information Commissioner’s Office (ICO) will get enhanced powers to fine organisations up to £500,000 for serious breaches of the Data Protection Act. Previously the maximum fine was a paltry £5,000.

The tougher measures will be imposed alongside compulsory audit notices to central government departments found culpable for data breaches. The new powers for the UK's privacy watchdog are designed to deal with serious personal data breaches that arise through negligent behaviour. Precautions an organisation had previously applied as well as the circumstances of a breach will be taken into account in deciding a fine.

Revised guidelines (pdf) state that the most severe fines will be imposed in cases where the "data controller has seriously contravened the data protection principles and the contravention was of a kind likely to cause substantial damage or substantial distress".

The enhanced powers for the ICO were approved by parliament three months ago. However a recent survey found that two thirds of 500 city workers (65 per cent) are still blissfully unaware that they could cost their organisation £500K if their actions cause a “deliberate or negligent” breach of personal data. The study, sponsored by Cyber-Ark Software, found that employers are often doing little or nothing to inform workers of important changes in UK data privacy rules.

The survey found that 64 per cent of those quizzed carry customer data on mobile devices, with only 12 per cent using encryption to protect data from prying eyes in the event of a loss. A further 50 per cent of mobile devices are protected only by basic password defences, and 38 per cent store sensitive data without any protection at all.

CyberARk called on firms to develop and apply appropriate security policies to minimise the impact of device loss, which now carries the possibility of much larger fines.

However other security watchers are unconvinced that the increased fines alone will prompt major changes in behaviour by corporates, at least in the short term. That's because far too many organisations still reckon that data breaches are something that happen only to other people, despite reports of data loss stories almost every day.

Chris McIntosh, CEO of Stonewood, said:

Despite the danger to reputation and business that can come from a data loss, it is still a hard truth that many organisations feel they will be one of the fortunate few that remain untouched. As a result, planning for options such as encryption and the correct handling of data is put off for another day.

While this report will be a useful tool to those seeking to convince their organisations to secure data, it does not address the crucial issue of organisations trusting to luck.

Amichai Shulman, chief technology officer with data security specialist Imperva, drew parallels between the enforcement of the DPA and that of the Payment Card Industry Data Security Standards (PCI DSS) imposed on credit card merchants.

"PCI DSS," he explained, "takes the pragmatic approach of defining exactly what has to be done and effectively giving the IT manager a blueprint for their data security plans." ®

Combat fraud and increase customer satisfaction

More from The Register

next story
EU: Let's cost financial traders $400m a day, because EVIL BANKERS. Right?
Wait 'til this one hits your pension fund where it hurts
Systems meltdown plunges US immigration courts into pen-and-paper stone age
Massive outage could last four weeks, sources claim
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
prev story

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.