Information Commissioner: security still on alert

Information security must remain a priority in difficult economic times warns outgoing government official

Since the autumn of 2007, information security has been an even more major issue for businesses and CIOs. When the chancellor Alistair Darling announced to the House of Commons that the file containing the records of almost all child benefit claimants in the UK had been lost, information security became headline news. But as organisations struggle in the new recessionary economic climate and public-sector CIOs discover that their funding levels are being slashed will the issue slide into the background. CIO UK discussed the continued importance of information security with Richard Thomas, the outgoing information commissioner and Mike Payne, CTO at the Ministry of Justice.

The personal details of 25 million British people were lost in 2007 when HM Revenue and Customs (HMRC) lost two CDs containing the records. It was described as a systematic failure and "woefully inadequate" by the Poynter report. For the last two years, HMRC's name could not be uttered without being instantly connected with the biggest loss of personal information in British history. Poynter discovered that the IT systems at the newly merged HMRC organisation were too complex and too fragmented. As a result, Poynter advised HMRC to upgrade its IT systems, which the organisation then committed to spending £155m on IT renewal projects.

HMRC was the first sighting of a major problem within the public sector and private companies. Like the periscope of an enemy submarine emerging first, as more and more details arose, the submarine surfaced, revealing itself to be the U-boat set to sink the information fleet. Prison staff details were lost, while banks and building societies also revealed failures in records keeping.

<

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Richard Thomas steps down as the Information Commissioner in June after six years in the post. He has been by far and away the most effective and prolific campaigner for good information practices. His department is responsible for ensuring the Freedom of Information Act and Data Protection Acts are upheld. The Information Commissioner is an entirely independent role and is appointed by the Queen.

"The technology has demonstrably changed and that has been the major driver," Thomas says of the internet and his time as Commissioner. Since taking over the department, Thomas has been the public face and voice of information security, he told CIO UK at an event organised by Dtex, an information security specialist. The department he inherited was poorly funded and had just one PC and no internet connection. Today, C-level management, insurance companies and across the government have respect for the department Thomas has honed. Thomas himself says the big-ticket disasters have also driven up the interest and prioritisation of information security.

"It was seen as a nerdy role and we were seen as remote from reality," he says. We worked very hard to make it more relevant." Thomas says this was achieved through "language, pragmatism and common sense". "We put a lot of emphasis on communications and this has transformed our relationship with businesses."

Mike Payne, CTO at the Ministry of Justice, concurs: "The powerful thing is that it's [information security] gone from being very arcane to one that is now using a language that the business understands."




Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Unleashing the power of virtualisation 2010

Find out more about cloud computing in European enterprises.

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Modernising IT: Strategies for improving service quality and reducing IT costs

No matter how many people you allocate, sinking more labour into old IT practices cannot concurrently meet rising demands on IT and cut costs. Read about cost-effective, automated ways to meet this challenge head-on.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

DOWNLOAD

Trend Micro



* *