HSBC loses customer data

Details of over 350,000 customers go missing in the post

Written by Rosalie Marshall

HSBC has lost a disc containing details of 370,000 of its customers, in an incident which will raise further questions about firms' data security policies.

The loss occurred four weeks ago when HSBC used the Royal Mail to transport its disc between the bank’s offices in Southampton and Folkestone, an HSBC spokesman told IT Week.

The disc was password protected and contained names, life insurance cover levels, dates of birth and whether or not a customer smokes, said HSBC in a statement. “There is nothing else that could in any way compromise a customer and there is no reason to suppose that the disk has fallen into the wrong hands. "

However this is the latest in a large number of security breaches, ranging from the HM Revenue and Customs loss of computer discs to the loss of patient records and government laptops. Questions are increasingly being asked about why organisations are not learning from each other’s high profile mistakes.

Paul Vlissidis, technical director of pen testing firm the National Computing Centre Group, said the losses indicate “basic stupidity”.

“Organisations need to wake up to the fact that their data is precious and enforce its protection properly at all levels," he said. “This means no more storing hundreds of thousands of sensitive records on unencrypted media, bans on taking critical information off-site and not giving single users access to millions of personal records.”

Vlissidis argued that although it is tempting for managers to take the easy option, they should not entrust courier services with sensitive information. “In the case of customer data, out of sight is most certainly not out of mind,” he said.

Matt Fisher, vice president of security firm, Centennial Software, listed t hree major contributing factors to data loss incidents. “First, there is an institutionalised lax approach to data security, where staff do not fully understand how to handle sensitive data,” he said. “Second, there is no technology in place to manage which computer users are able to copy confidential data to removable media devices like CDs or UB sticks.”

Fisher added that full data encryption is eseential. “On the rare occasion there is a real business need to transfer data of this nature to a third party, I would insist on the data being encrypted with a 256-bit cipher and that it was sent by a private courier (or preferably an employee) direct to its destination.”

Brain Spector, general manager of the content protection group at Workshare, said that the incident would undermine HSBC's attempts to build and maintain customer loyalty.

“Considering the current climate of economic uncertainty HSBC’s loss of sensitive data is unacceptable," he added. "This blunder will cause significant damage to the bank’s reputation and is another example of the lax approach to data security that major organisations continue to take."

The Financial Services Authority (FSA) has been informed of the HSBC’s data loss and HSBC has apologised to all its life assurance customers. The bank plans to contact them shortly, it said.

Tags:

reader comments

related articles

 

HSBC loses customer data

Details of over 350,000 customers go missing in the post 07 Apr 2008

Information on thousands of prisoners missing

Government-hired consultancy causes security breach with prisoners’ unencrypted data 22 Aug 2008

ICO criticises chief executives for lax security

Level of security breaches is "inexcusable" and CEOs must do better 21 Apr 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation