Picture of Richard Thomas, information commissioner
Thomas: More must be done to eradicate security breaches

Privacy watchdog plans spot checks

Information Commissioner's Office will begin inspections by the end of the year

Written by Tom Young

The UK’s privacy watchdog will start security spot checks on government departments by the end of the year, after the idea was approved by prime minister Gordon Brown.

Currently the Information Commissioner’s Office (ICO) can only examine the data sharing and data protection policies within government departments, and then only by prior arrangement.

Information commissioner Richard Thomas told an audience of IT security specialists in London that his office will soon be given new powers.

“The Ministry of Justice will bring forward proposals on inspection powers and increases in funding,” he said. “We hope to be inspecting government departments later this year.”

The ICO chief has been pushing for extra powers and funding since his appointment in 2002.

Brown granted a review of the watchdog’s resources after a number of high-profile security breaches – ­ including a lost Ministry of Defence laptop with the details of 600,000 potential recruits and the loss of two discs by HM Revenue and Customs (HMRC) containing the personal details of 25 million families.

Meanwhile, the ICO announced last week that since the HMRC security breach last November, another 94 serious breaches have occurred in both public and private sector organisations.

A third occurred in central government and associated agencies and another third at a local government level.

Of the 30 private sector breaches, half were reported by financial services firms.

Of the total, 16 cases prompted the ICO to force the organisation concerned to make changes to security policies, such as implementing data encryption technology. It said that in three instances the lost information had been recovered.

Thomas welcomed the implication that organisations were taking security responsibilities more seriously, but said the figures must not lead to board-level complacency.

“I am encouraged that more chief executives and permanent secretaries appear to be taking data protection more seriously, but the evidence shows that more must be done to eradicate inexcusable security breaches,” he said.

Security update

The cost to the UK of information security breaches fell 35 per cent from £10bn in 2006 to about £6bn in 2007, according to a PricewaterhouseCoopers survey.

It found 60 per cent fewer companies reported malware attacks than in 2007 but almost all (96 per cent) very large companies had some kind of security incident.

Some 54 per cent of firms now allow staff to access networks remotely, thanks to improved security, with 94 per cent of respondents now encrypting wireless networks, up from 48 per cent a year ago.

But 52 per cent conduct no staff risk assessments and 67 per cent do nothing to prevent portable media data leakage.

reader comments

related articles

Picture of Richard Thomas

Further security breaches uncovered at HMRC

"Systemic failures" in security have lead to seven breaches since 2005 13 Dec 2007

 

Privacy watchdog to get new powers

Office will be given ability to spot check central government 22 Apr 2008

UK population wises up to data protection

Recent media attention on information loss has made the British public more astute 14 Mar 2008

Gateway reviews must look at privacy, says Information Commissioner

But Office of Government Commerce rejects use of assessments as standard 06 Mar 2008

M&S breached Data Protection Act

Watchdog rules loss of 26,000 employees' details on unencrypted laptop breaks the law 25 Jan 2008

Government assesses security procedures in light of data breach

Information Commissioner’s Office given power to carry out spot checks on government departments 23 Nov 2007

Privacy watchdog to get new powers

Office will be given ability to spot check central government 22 Apr 2008

ICO criticises chief executives for lax security

Level of security breaches is "inexcusable" and CEOs must do better 21 Apr 2008

related whitepapers

today's top stories

Driving up performance through better software development

We talk to IT chiefs who are using new software development methodologies to modify legacy systems and crank up web performance 08 Oct 2008

Case Study: Justgiving.com

Dynamic web development boosts online donations 08 Oct 2008

Hot tips for virtualisation

Migrating systems to a virtualised environment can deliver significant efficiency gains and cost savings, but it has to be planned carefully. Martin Courtney explains how IT leaders can improve the odds of success 08 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Horse raceFeatures

Hot tips for virtualisation

Migrating systems to a virtualised environment can deliver significant efficiency gains and cost savings, but it has to be planned carefully. Martin Courtney explains how IT leaders can improve the odds of success 08 Oct 2008

The pIT stop panelAnalysis

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

Advertisement

Primary Navigation