Beyond the pail

Looking at government's data disasters should provide a warning sign for all...

Written by Andrew Sawers

The HMRC data disaster brought to mind a bucket. A bucket full of water. And a bucket full of holes. And a bucket full of water and holes and which, therefore, leaks remorselessly. But no matter how much the bucket leaks, it never empties. Never. It’s always full of water. It sounds like a sorcerer’s apprentice’s nightmare. And in a way, it is. Because although two CDs containing data relating to 25 million beneficiaries of child benefit has been lost, the fact is that the data itself hasn’t been lost. Data is probably the only thing that can be stolen or carelessly mislaid, while never actually being lost. Ctrl-c, ctrl-v has a lot to answer for. Ditto drag-and-drop. Hence the bucket: data can leak out of an organisation, and yet never be lost.

Imagine for a moment what would happen if the leak of data meant its permanent loss. Imagine slapping the details of 25 million people onto a couple of CDs and the data simultaneously and permanently being wiped from the computer whence it came. (If it makes it easier to get your head around this concept, try imagining removing 25 million Roladex cards and then shipping them in a few dozen crates.) You would take a lot better care of your data if you could actually, permanently be deprived of it like this.

This then brought to mind the issue of risk, which also features quite heavily in this month’s magazine: if the downside of having data stolen is simply that someone else has a copy, then there’s certainly nowhere near as much downside as if the data had actually been lost. Companies would take so much better care of the information in their possession if improper use or copying of data meant that they would no longer have it themselves. That’s the way it used to be. And this could well be a good starting point for a data security strategy: to treat information as precious as if the organisation could be permanently deprived of it. If the data is so valuable that you would pay a fortune for its safe return, then it probably makes sense to prioritise its security.

Simple concept, more difficult in practice. Moreover, it’s not exactly true to say that data misuse has no downside. The reputation of HMRC has certainly taken a knock but that’s no big deal. We’re still going to have to pay our taxes. For companies in the private sector, though, reputational risk is very real, if a little intangible. When companies such as Norwich Union get hit with a £1.26m fine, that does make the eyes water. Perhaps what is needed is some really swingeing financial penalties in order to bring home the fact that data comes with bone-crushing responsibilities.

But I readily concede there wouldn’t have been a lot of point in fining the taxman.

Tags:

reader comments

related articles

 

Ringfencing amnesty would be a nightmare

Plans to ‘ringfence’ a second offshore disclosure regime could prove an administrative nightmare, advisers have warned 29 Nov 2007

related whitepapers

today's top stories

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

City in pressing need of skilled IT matchmakers

With the financial services sector plunging ever deeper into an M&A maelstrom, IT leaders are having their systems integration skills and due diligence expertise tested as never before 09 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Podcast imageAudio

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation