Knowledge Vault


Follow us





Security experts lambast HMRC

'Breach likely to give birth to a number of phishing scams'

Security experts have assailed HM Revenue and Customs (HMRC) for being responsible for the loss of 25 million confidential child benefit records, which has opened up fraud risks.

What to do to prevent data loss

Jonathan Armstrong, partner at international law firm Eversheds, said: "The HMRC breach will undoubtedly focus attention on the security procedures of the private sector as well as government. Now is the time for businesses to update their response plans. For organisations yet to suffer a breach there are a number of things they should do now including:
- looking at where and how they hold data and who else has access to it
- picking their response team for when they have a breach
- implementing thorough training systems and an awareness of the consequences of a breach
- making sure they have a system for concerned customers or employees to get in touch
- looking into the costs of buying credit checks in advance
- looking at third party contracts and the security systems of those contractors"

The government blunder involved the loss of computer discs sent via courier, which contained the details of over seven million people's bank details. HMRC chairman Paul Gray has resigned.

Jonathan Armstrong, partner at international law firm Eversheds, said: "The breach is also likely to give birth to a number of phishing scams. Even if the data on the CDs does not get into the hands of fraudsters it is likely that even now a large email campaign is being planned to prey on the British public."

"We have been involved with a number of major multinational breaches and have spoken with clients after the event to help others learn from their experience. In many cases the consequences of the data breach are worse than first anticipated," he added. "Often the losses are due to failures with third parties, including couriers where back-up tapes or CDs go astray. A common theme is that the contracts with those couriers are often inadequate to cover loss - in one case for example losses were well over $1m when the contract with the courier made their maximum liability half that."

Fred Piper, professor, director, of information security group at Royal Holloway University of London, said it "beggars belief" as to how this data loss could have occurred.

"It shouldn't happen. It beggars belief as to who authorised this, and whether they had authority to send the data or just did it," he said. "It's a straightforward, irresponsible cock up. If you must transfer data, there should be a clear reporting structure to the value of data. If it is valuable data, then only senior staff should authorise it and that data needs adequate protection."

Yesterday, the Chancellor of the Exchequer, Alistair Darling issued a statement, which admitted that the discs were password protected. However, Darling but did not state whether the discs were encrypted. Calls to HMRC were not returned at time of writing.

Piper said: "Had it been encrypted, that's the first thing they would have said. HMRC said the discs were password protected, but had they been protected properly, they would have been stated this. Don't know what level of protection, but we can only surmise that if HMRC are not stating that the data is encrypted, then it isn't."

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Darling added that an independent review of HMRC’s security procedures is taking place, with the full results being published in spring 2008.

Bob Ayers, associate fellow at Chatham House's International Security Programme, questioned how this could have happened. "The most obvious reason is it was either poor security procedures, or poor compliance with those procedures... What kind of data protection regime is there in place in which highly sensitive information is stuffed in an envelope and given to guy on a motorbike to courier across London? What kind of protection regime treats such vitally important information in such cavalier fashion?"

Ayers urged government to review its processes, technology and compliance. "The solutions to correcting this problem could be technical, procedural, legislative and administrative."

"We are getting a lot of head-patting from the government that they are in charge and they are trying to figure out what happened. We are being told not to panic and not to change our bank accounts," he said. "I would want to know how did this happen. I'm not talking about the mechanics, but how did we get to the position that such critically sensitive information is being treated like a package of fish and chips and moved around London. Until we understand the answer, there can be no assurance that this is not going to happen again and again and again."



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

The financial economics of cloud email

This white paper evaluates cloud computing as a flexible alternative to your current IT capability that delivers tangible benefits including: projects delivered earlier, faster adoption to change, lower risk, reduced costs and easier to scale up or down services.

Beyond Dropbox: Requirements for Enterprise Secure File Sharing

This whitepaper explores the danger “Dropbox” type services pose for enterprises, and the security and compliance requirements for deploying enterprise-wide file sharing solutions.

Top 10 considerations for your IT operations management in the cloud

This paper explores ten questions every IT organization should answer to help determine their cloud based ITOM needs.

How to get your business ready for the 2012 Olympics

IT Manager: "I'm working on contingency plans to ensure that we can keep the business running whatever happens during the Olympics. Hopefully, it'll just be a case of letting people work from home but we need to be ready for anything".


CIO UK - Business - Technology - Leadership

Voice Applications in the Cloud

Watch this webcast to learn about new network and telecoms options.

Register now

Download the CIO BlackBerry App -
Access CIO's Content on the Move


The CIO UK BlackBerry App provides daily business and technology news, opinion and indepth features direct to your BlackBerry device.

Find out more

CIO Transformation Summit

CIO Roundtable:
The Private Cloud

Wed 29 Feb 2012
Tower 42, London, 7pm.

Join a select group of your fellow CIO's to discuss private cloud computing and how best to apply the private cloud to your organisation

Register here to book your place.



Knowledge Vault


* *