Advertisement
Promo

Security threats Toolkit

Infosecurity Europe 2008

HMRC data loss blamed on targets

David Meyer ZDNet.co.uk

Published: 23 Apr 2008 13:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Last year's data-loss debacle in which HM Revenue & Customs lost millions of UK citizen's personal details was the result of excessive targets, according to a member of the House of Lords.

In November 2007, HMRC admitted it had lost two CDs containing the details of 25 million individuals. The CDs are assumed to have been lost while in transit to the National Audit Office. According to Merlin, The Earl of Erroll — a noted IT expert who is widely regarded as the only Lord with programming skills — the scandal was "because of targets [and] budgets" rather than being the fault of individuals.

Someone had to get the data somewhere else to meet a target, said Lord Erroll, during a panel discussion at the Infosecurity security conference in London on Tuesday. Having simple procedures doesn't work if the only way to hit targets is to bypass those procedures, he added. "We live in a complex world. The moment you try to use simple rules and controls, they don't work."

Richard Thomas, the information commissioner, was speaking on the same panel. He said that Gus O'Donnell's review of the HMRC data loss would lead to new guidance for the public sector being issued "later this month", and suggested this guidance would have an "emphasis on accountability".

Read this

Infosecurity Europe 2008: Special report

All the latest news and blogs from the security industry's biggest UK event...

Read more +

"It has to be the chief executives and the permanent secretaries who take responsibility when things go wrong," Thomas said, referring not only to the results of the O'Donnell report but also the Burton report into the loss of 600,000 people's data by the MoD — an incident in which unencrypted data was held on a laptop that was stolen from a car seat.

Thomas also questioned the amount of data being held, stored and shared in such cases. "Data protection is not just about data security," he said. "Data protection is to a large extent about data minimisation. Why were 600,000 people's details being kept and why for so long? Why was the entire database transferred to a laptop, and why unencrypted? Only then do you get to the question of why it is left in a car."

In the case of the missing HMRC data, it emerged soon after the loss occurred that sensitive information, such as bank details, was supposed to have been stripped out of the databases on the discs before they were sent to the National Audit Office. It had, however, been left on the discs because of the extra costs that would have been incurred by stripping the information.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
9 out of 9 people found this useful


Full Talkback thread

0 comments


More in this Special Report

Blog: Social networking and portability

Blog: Social networking and portability

One of the more interesting speakers at Infosec's "Locking Down Social Networking Vulnerabilities" event today was Giles Hogben of the European Network and Information Security Agency (ENISA) more

ICO: Data-protection spot checks due this year

ICO: Data-protection spot checks due this year

The information commissioner has confirmed that his office will be getting new powers to carry out spot checks on any company in the UK holding data on individuals more

Infosecurity Europe 2008: Preview

Infosecurity Europe 2008: Preview

Over 11,000 delegates and 320 exhibitors will attend one of Europe's largest IT security shows on Tuesday at London's Olympia conference centre more

Security breaches down, says IT security report

Security breaches down, says IT security report

The latest Information Security Breaches Survey has reported that while the number of security breaches has fallen in the past two years, the average spend on defences has increased more

Facebook admits to increased attacks by spammers

Facebook admits to increased attacks by spammers

The social-networking site has come under increased attack by spammers and phishers this year, according to its head of security more

Security industry gears up for biggest UK event

Security industry gears up for biggest UK event

Infosecurity Europe 2008 is underway in London and will include keynotes and product demos from the some of the leading organisations in IT security more

Vendors urged to take responsibility for security

Vendors urged to take responsibility for security

When it comes to the security of hardware and software, suppliers should be put on the spot, argue experts at Infosecurity Europe 2008 more

Media lobbying 'watered down' data-misuse laws

Media lobbying 'watered down' data-misuse laws

As a result of media lobbying, the information commissioner says another serious data breach will need to occur before prison sentences for data misuse are imposed more

HMRC data loss blamed on targets

HMRC data loss blamed on targets

Merlin, Lord Erroll, believes targets and budgets rather than individuals should be blamed for the loss of 25 million UK citizens' confidential records last year more

Former White House adviser talks mobile threats

Former White House adviser talks mobile threats

Security strategist Howard A Schmidt discusses whether mobile attacks are overhyped and what new risks have been introduced by virtualisation more

Security expert voices virtualisation concerns

Security expert voices virtualisation concerns

Mikko Hyppönen, chief research officer for security specialist F-Secure, claims virtualisation technology will have its own specific security threats more

Lord: No proof any data was lost from HMRC

Lord: No proof any data was lost from HMRC

Security expert Merlin, The Earl of Erroll, claims no evidence has come to light to prove data was actually lost in last year's HMRC missing-disc incident more

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

INIFiles: Getting those legacy files i...

Handling INI files can be a little tricky these days when you have to consider new security restrictions, virtualized environment restrictions (App-V and Citrix) and legacy applications... More

Post a comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters