Picture of John Meakin

CBI calls for greater focus on web security

Internet security regulations on liability needs clarification

Written by Tom Young

Employers’ body the CBI is calling for a national strategy to clarify where responsibility for internet security lies.

There are few clear regulations governing online retailers’ liability in protecting their
customers from attacks such as phishing and identity theft.How far businesses could or should take responsibility forcustomers’ security problems is still an open question.

But apportioning blame for security issues needs to be done carefully, and an overarching strategy would be more effective than prescriptive regulations, CBI head of e-business Jeremy Beale told the House of Lords Science and Technology Sub-Committee last week.

‘We need a national information security strategy, where educational and training programmes are linked to enforcement capabilities,’ said Beale. ‘There is mutual responsibility, and a clearer framework needs to be formed for where responsibility lies for different actions along the chain.'

‘Regulations tend to be for a certain set of technologies, which can change quickly, so rather than trying to find a silver bullet we need a co-ordinated national strategy,’ said Beale.

Security concerns are having a considerable impact on customer behaviour. A recent survey by awareness portal Get Safe Online found that 17 per cent of active web users have decided not to use the internet anymore because of a bad experience.

Customer trust is a strategic priority for online payment service PayPal, head of security Michael Barrett told the committee.

‘The issue is that customers that have had their security compromised find it so wholly repugnant, like being burgled, that they do not want to use the internet again, and who can blame them?’ he said.

Businesses such as PayPal refund their customers for any losses they incur, even though the firm is rarely responsible.

‘We never send emails to customers, and we tell them that,’ said Barrett.

‘Our negligence has not led directly to their losses, but obviously we must bear some of the responsibility,’ he said.

Firms cannot solve the problem on their own, says Garreth Griffith, head of trust and safety at online marketplace eBay.

‘Law enforcement, industry and individuals all have responsibility,’ said Griffith. ‘Partnership and education are crucial, one entity standing alone cannot make a significant impact.’

Sharing responsibility maybe fair. But the danger is that no one is left accountable.

‘If I lose my eBay or PayPal account details [to a criminal], it is no consolation to me that everyone is responsible – I need somebody specific to go for,’ said sub-committee member Lord Young of Graffham.

What do you think? Email us at feedback@computing.co.uk

Further Reading:

UK security found wanting

Corporate governance - Special report

reader comments

related articles

 

Lords push Government on web security

Backing for second report to call for measures to protect public and make banks take responsibility 08 Jul 2008

Banks should be liable for e-fraud

House of Lords committee describes current system as 'wholly unsatisfactory' 11 Jul 2008

Latest tactics for fighting e-crime could backfire

Experts warn sting operations may make fraudsters harder to catch in future 28 Oct 2008

related whitepapers

today's top stories

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Government aims to bolster UK's cyber defences

Is the UK’s first national cyber security strategy up to the task of co-ordinating the country’s response to digital threats? Computing investigates 02 Jul 2009

Focus resources on what really matters

IT has become too caught up in the drive for efficiency, at the expense of business success 02 Jul 2009

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation