ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Nationwide fined £1m over laptop theft

Graeme Wearden ZDNet.co.uk

Published: 14 Feb 2007 13:28 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK building society Nationwide has been fined almost £1m after a laptop containing sensitive customer data was stolen from an employee.

The Financial Services Authority (FSA) hit Nationwide with the £980,000 fine on Wednesday, following an investigation into the theft, which occurred in November 2006 at the employee's house.

According to the FSA, Nationwide was guilty of failing to have effective systems and controls in place to manage its information security risks. The FSA also discovered that Nationwide was not aware that the laptop contained confidential customer information and did not start an investigation until three weeks after the theft.

"Firms' internal controls are fundamental in ensuring customers' details remain as secure as they can be and, as technology evolves, firms must keep their systems and controls up-to-date to prevent lapses in security," said Margaret Cole, director of enforcement at the FSA.

"The FSA took swift enforcement action in this case to send a clear, strong message to all firms about the importance of information security," Cole added.

The FSA took swift enforcement action in this case to send a clear, strong message to all firms about the importance of information security

Margaret Cole, FSA

Nationwide has apologised for the incident, and claims to have tightened up its security procedures in an attempt to avoid a repeat of the incident.

"We have extensive security procedures in place, but in this isolated incident our systems of control were found wanting," said Nationwide's chief executive, Philip Williamson, in a statement. "We have made changes to fill the gap and improve our procedures further."

It's still unclear exactly what customer data was held on the laptop. Nationwide insists that the information couldn't have been used to commit identity theft, and says that no customers have lost money as a result.

Nationwide admitted that the employee in question had not been following its existing procedures at the time of the theft. Although it's unclear exactly how procedures weren't followed, it seems likely that the laptop should not have left the company's offices or that the data shouldn't have been stored there at all.

"We can't comment on any action that may have been taken against the employee," a Nationwide spokesperson told ZDNet UK.

Laptop thefts are a growing security problem. Earlier this week, it was revealed that America's FBI loses three or four laptops each month. In many cases, the FBI hasn't known what sensitive data might have been contained on the missing devices.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
23 out of 23 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Electronics Hardware Engineer East Midlands

Candidates will also be specifying test and investigation action and managing process and reporting on findings. Our prestigious client is looking to ...

S55189: Security/Quality Analyst

Experience dealing with IT security controls and the associated policies. Perform a quarterly review and action updates to this plan where required. ...

2nd Line Support Manager

To establish strategic relationships with Incident, Support and Operations Managers and to leverage those relationships to improve overall service ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation