UK data breach: stripping data 'would not have been costly'

Less than £50,000 would have paid for data stripping in HMRC disc fiasco

LONDON (12/06/2007) - It would have cost less than £50,000 (US$102,000) to strip confidential data from the records of 25 million people lost in transit between HM Revenue and Customs and the National Audit Office, HMRC's acting chair Dave Hartnett told MPs today.

Hartnett - acting up in place of Paul Gray, the former HMRC chair who resigned as the data loss scandal broke - made the admission to MPs on the Commons Treasury committee.

The acting HMRC chief also admitted that the child benefit data on the two CDs was the latest in a string of data security breaches, acknowledging that there had been seven breaches "of some significance" since the merger between Inland Revenue and HM Customs and Excise in April 2005.

The data held on the two CDs lost in Britain's biggest data security breach included bank details, NI numbers, and children's names, addresses and dates of birth.

Emails released by the National Audit Office last month confirmed that HMRC officials did not want to remove the sensitive information from the child benefit data sent to the NAO because this would cost extra.

Quizzed by the Treasury committee on the cost of desensitizing the information, Hartnett initially said: "I don't know the answer to that," noting that the "key issue is that the data should not have left our premises anyway".

But when pressed, he added: "I'd have thought it would be less than £50,000 but I haven't got the precise figure."

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Hartnett later told the MPs that HMRC had subsequently established how easy it was to ensure data management contractor EDS stripped out the confidential details when it passed information to U.K. payments association Apacs as part of measures to protect bank accounts in the wake of the data loss scandal.

"When we needed to pass data to Apacs... we were able to segregate the data in the way you [the committee member] describe with our IT supplier -- and quickly -- and it is therefore a matter of huge regret that we did not do that before," he said.

In a statement that suggests HMRC believes the NAO is partly to blame for the data loss, Hartnett added: "But I think the important issue is that those who asked for and provided that data had stepped outside the procedures we had established."

Hartnett said he did not know how much the filtering of data for despatch to Apacs would have cost, but said no-one had alerted him that it was going to be a significant amount.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

The challenge of strategic alignment

Recent research also shows that many organisations give too much prominence to internally generated KPIs – controlling the controllable – rather than looking outwards at threats and opportunities on the horizon which can ultimately be far more influential on performance.

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Managing email: Exploring common email management challenges (and how to overcome them)

We surveyed 157 IT professionals to understand the difficulties and opportunities faced by email managers. From this we were able to highlight some easy-to-manange solutions to their most pressing problems.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation - The 'black hole' of security?

Covering the set of issues, ideas and perceptions discussed during a recently held debate about the effect of virtualisation techniques on organisational security. This paper provides a comprehensive account of all the subject matters debated and concludes with key takeaways and IDC recommended actions.

DOWNLOAD

Trend Micro



* *