Groundhog day as sensitive data lost in the post by government…again

I’ve said this before, but I’m going to say it again. By all means, worry about hackers – after all, they may be out to get you. Go ahead and buy that firewall; pay that technology company for their perimeter defence audit. Invest in anti-malware and anti-virus software. Have effective and tested plans in case you’re flooded, or snowed in, or everyone gets Ebola.

Do all these things.

But you won’t be secure. Not unless you also – in fact, first of all – spend money and time on training your staff and modifying your business procedures to put thinking and acting securely in the front of people’s minds. Hackers might get in; viruses might infect you; God might act – but your staff will drop the ball. No ifs, no buts, no modal verbs.

If you don’t train them, they won’t learn. We’ve not had the need for data security long enough, it seems, for it to be basic human instinct. You’d think we’d have figured it out, wouldn’t you, after HMRC managed to leak 25 million individual child benefit records by sending unencrypted CDs in the post – causing a grand furore and the resignation of the Chairman. The first sentence of the article I linked to in the previous sentence reads “The practice of sending across the country unencrypted, CD-based files … could have continued indefinitely if the discs hadn’t gone missing…”.

Could have gone on indefinitely? That was in 2007. A little over seven years ago. Long enough to learn by now, don’t you think? From the BBC today:

Discs containing information from three of the UK’s most sensitive inquiries have gone missing after being put in the post.

Apparently the government “takes information security extremely seriously”. No it plainly doesn’t. These are the first four relevant results of one quick search for “police lose sensitive data”:

Lost USB stick costs police £120,000 (2012)

Crime victims’ data lost in post (2009)

Home Office has lost … personal details [of] tens of thousands of criminals (2008)

Lancashire police fined after losing data on vulnerable girl (2007)

It’s a little ironic, isn’t it, that the Prime Minister recently spoke out against encryption, for fear that spooks might not be able to intercept all our communications. Perhaps instead he should have focused on getting government departments to use encryption in the first place, so that we have less chance of intercepting theirs.

From the government’s perspective, this is an embarrassment. If the ICO fines the police, this will just be money moving about inside the State. But if you make the same mistake, I expect the ICO’s six-figure fine might not be so easily shrugged off. There’s not a competitive market in policing, either, so we don’t get to change suppliers just because they have data security policies made out of Swiss cheese. Your customers, on the other hand, do have a choice, and they will exercise it.

TL;DR? Get security awareness training for your staff. Now.

2 thoughts on “Groundhog day as sensitive data lost in the post by government…again

    1. [fx]Google[/fx]. So it is; funny, I always thought of modality as having an implication of uncertainty (or instruction – epistemic or deontic). Learn a new thing every day. Perhaps I should have written “It is certain that…”; but given that I also start sentences with “but”, have sentences without verbs, and generally abuse the English language in this blog, well, meh.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s