Feeds

Win XP security deadline: Biz bods MUST protect user data – ICO

Keep printouts AWAY from skips, make plan for XPocalypse. Simples

Maximizing your infrastructure through virtualization

The end of support for XP on Tuesday doesn't only mean increased risk from hackers exploiting vulnerabilities that will never be patched. It also creates a heightened data protection risk to businesses, the UK's data privacy watchdog has warned.

The Information Commissioner's Office (ICO) also warned that the end of support for Office 2003, which also falls today, also creates the same ramping up of risk.  

Next Tuesday (8 April) sees the end of official support for Microsoft’s Windows XP and Microsoft Office 2003 products. PCs running either of these two products will not stop working at this point, but it does mean that if a security flaw is discovered, Microsoft will not release an update to fix it.   This is important news for businesses using those products, as it means their systems, and the personal data stored within it, could potentially be vulnerable. The problem will get worse over time as more vulnerabilities are gradually discovered, creating more opportunities for an attacker to exploit and potentially gain unauthorised access to systems.

Estimates vary but Netmarketshare reckons Windows XP still has a death bed market share of 27 per cent. Cloud security firm Qualys has put together Windows XP usage stats by country and industry based on figures from its BrowserCheck (consumer security tool to check browsers and plug-ins for security updates) and corporate QualysGuard tools.

On the consumer side of the house, UK and US XP usage dropped from 18 per cent in Q1 2013 to 8 per cent in Q1 2014. In a separate scan of QualysGuard data from 6,700 companies, use of XP is at 21 per cent in finance but just 3 per cent in health.

Dr Simon Rice, the ICO’s technology group manager, explained that IT products reaching end of life is a regular occurrence. So the end of days for Win XP is just the same issue played out on a much grander scale.   "Organisations regularly end support for their older products," Rice said. "And those with supported systems still need to be vigilant, as vulnerabilities will be discovered over time."

The practical upshot is that data controllers in business still running Windows XP or Windows 2003 will face additional responsibilities to "make sure you have the measures in place to keep people’s details safe", according to Rice.

“Anyone using either of these two products must consider their options and ensure that personal data is not unduly placed at risk. Failure to do so will leave your organisation’s network increasingly vulnerable over time and increases the risk of a serious data breach that your actions could have prevented," he concluded.

Dr Rice covers the data protection implications of Win XP's end of days in a blog post published by the ICO last month here. ®

The Power of One eBook: Top reasons to choose HP BladeSystem

More from The Register

next story
Sysadmin Day 2014: Quick, there's still time to get the beers in
He walked over the broken glass, killed the thugs... and er... reconnected the cables*
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
SHOCK and AWS: The fall of Amazon's deflationary cloud
Just as Jeff Bezos did to books and CDs, Amazon's rivals are now doing to it
BlackBerry: Toss the server, mate... BES is in the CLOUD now
BlackBerry Enterprise Services takes aim at SMEs - but there's a catch
The triumph of VVOL: Everyone's jumping into bed with VMware
'Bandwagon'? Yes, we're on it and so what, say big dogs
Carbon tax repeal won't see data centre operators cut prices
Rackspace says electricity isn't a major cost, Equinix promises 'no levy'
Disaster Recovery upstart joins DR 'as a service' gang
Quorum joins the aaS crowd with DRaaS offering
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.