Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Research leads to fresh calls for data-breach laws

Steve Ranger silicon.com

Published: 26 Sep 2008 09:22 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies that suffer data breaches are unwilling to tell their clients about the mishap, leading to renewed calls for mandatory reporting of information security lapses.

In a survey of 300 IT directors, chief technology officers and IT security managers in the public and private sector, one in 10 admit to falling victim to a security breach.

IT services company Logica, which sponsored the research, said the true number of organisations suffering data breaches is probably far higher.

Of those organisations that have experienced a data breach, 60 percent did not tell their clients and half did not alert the police or authorities.

The survey also found that only 30 percent of organisations educate staff in IT security and information handling procedures on a regular basis, and less than a third have a specific security-incident response team.

Read this

Q&A
Gartner: Authentication systems are 'fatally flawed'

Security analyst Jay Heiser gives his take on the rash of UK public-sector data losses and explains why authentication systems aren't up to scratch...

Read more +

It also revealed that while 63 percent of those surveyed hold personal data subject to EU data-handling regulations, only a quarter comply with ISO27001/2, which Logica said meant companies are not adhering to appropriate security procedures when storing personal data.

More than half of organisations admitted to having "no idea" of the potential impact of a security breach on their business.

The research has led to renewed calls for organisations to be required to report information security lapses.

Tim Best, director enterprise security solutions at Logica, said in a statement: "It is time to take action — it should be mandatory for all organisations to report significant breaches of confidential personal information to the information commissioner or their regulatory body. Only through mandatory reporting will the scale of the problem be understood, which will lead to the correct solutions being applied."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters