Data watchdog lacks bite for business lapses

COMMENT

The Tory focus on punishing data breaches in the public sector risks letting business failings off the hook, says Alan Calder.

Last week, the Conservatives announced plans to 'reverse the rise of the surveillance state', with expanded powers for the Information Commissioner's Office (ICO) to police the public sector.

There is much to be applauded in this document, which recognises how shockingly inept government is at protecting our personal data. But its treatment of the private sector is weak in comparison and fails to recognise that the ICO needs greater powers to bring directors to heel.

Personal information
A vast amount of personal information is held by the private sector. Store cards, banking systems and social media are just some of the things that are now central to our lives. While the Tories are technically correct that we surrender information to these voluntarily, their position overstates our freedom. If the alternative is to live 'off the grid' in today's technological world, just how much choice do we have?

The Conservative document states blithely that "business is generally much better at protecting data", and that companies have ample incentive to safeguard customer information. But if that were true, then why are we faced with stories of corporate data lapses on a regular basis, which companies could so easily avoid?

The Tories are overlooking essential truths. Time and again, businesses have failed in their duty to customers, indulged by our puny regulatory climate that gives little incentive for them to improve.

Real penalties
When businesses fail in data protection, the Financial Services Authority is presently the only body able to impose real penalties. The fine it recently imposed on three subsidiaries of HSBC is the costliest yet brought against a business.

The FSA's intention was to make executives focus on this responsibility, and at least it was turning up the heat. However, will a £3m fine make any difference to an organisation that counts its profits in billions?

While HSBC will have felt some embarrassment, the financial penalty is almost a pinprick. If penalties like this actually had an effect, then why was it necessary to take action against HSBC only two years after Nationwide's £980,000 fine?

And yet, it is incredibly cheap for companies to do their duty in this area. Nobody has to reinvent the wheel — ISO 27001 sets out how to manage data systems securely, while BS10012 shows how to meet the requirements of the Data Protection Act. Even for a Goliath such as HSBC, the necessary work and staff training would not exceed £100,000; smaller businesses can become compliant for far less.

Given that fines seem ineffectual, the prosecution of individuals, sadly, seems the only alternative. It is time for data security to be given proper emphasis, which means custodial sentences for chief executives, chief information officers and senior civil servants who wilfully disregard the law.

Read this

Sloppy risk assessment raises web fear factor

Security researchers must be able to distinguish between real and theoretical risks on the web...

Read more +

But here is where we fall down. The ICO is the obvious body to pursue such actions, but it has neither the resources, nor the power, for real change. The Health and Safety Executive has a budget and staff about 20 times the size of the ICO's, as well as powers to fine and inspect. Is it any wonder, therefore, that health and safety legislation has thrived, while data protection is so weak?

The ICO is also hamstrung by the lack of sentencing guidelines. Although repeatedly promised, these seem endlessly stuck in committee, allowing offenders to continue their work unpunished.

Opening salvo
So, while I welcome this opening salvo from the would-be next government, the Conservatives need to focus as much on business as on the public sector. Merely floating the idea of a voluntary kitemark scheme in a private sector consultation is almost an invitation for boards to put their feet up.

I would like to see the Conservatives pledge an ICO budget raised significantly from its present low level, and expedite the publication of the essential sentencing guidelines. They should make the adoption of ISO 27001 and BS10012 mandatory for UK businesses above a certain size.

As their crowning achievement, they should also champion a pan-European data breach directive; companies that fail to protect personal data must meet in full the costs of restitution, as well as pay substantial financial penalties.

If not, it is time to start demanding that our elected representatives take this subject seriously. They must enact legislation that has teeth, and commit the level of financial support that enables those teeth to bite.

Alan Calder is an information security author and chief executive of security and compliance organisation IT Governance.

Talkback

Totally agree with this one hundred percent well put, most in particularly I liked this part;

"Given that fines seem ineffectual, the prosecution of individuals, sadly, seems the only alternative. It is time for data security to be given proper emphasis, which means custodial sentences for chief executives, chief information officers and senior civil servants who wilfully disregard the law."

It worked when the government started to threaten BT chairmen with jail time, in the row over BT monopolizing their long distance trunk lines.

http://community.zdnet.co.uk/blog/0,1000000567,10013694o-2000331777b,00.htm#comment20103805

CA 26 September, 2009 04:18
Reply

This post has been removed by a moderator.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

3 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

5 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

9 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

14 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

18 hours ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

22 hours ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

23 hours ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

1 day ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

1 day ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

1 day ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

1 day ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

1 day ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

2 days ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

2 days ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

2 days ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT