HM Revenue & Customs
It has been a year since the HMRC lost the personal records of 25 million UK citizens

HMRC data loss one year on: lessons still being learned

The government needs to implement rigorous policies and procedures to protect sensitive data

Written by Phil Muncaster

The HMRC data loss scandal, in which the personal records of 25 million citizens went missing, happened a year ago, but experts warn that sensitive data will continue to haemorrhage from organisations unless the correct policies, processes and technologies are put in place.

The government has lost an average of one PC a week over the past year, according to figures obtained by the Conservative Party, but a combination of human error and poor processes have continued to undermine attempts to address the failings, said security experts.

Gary Clark, European vice president at data encryption firm SafeNet, argued that the government needs to focus on ensuring that data cannot be accessed by anyone outside the department to which it belongs.

"We should be able to trust that stringent practices are in place to secure our personal data," he said. "These should include identifying process weaknesses, adopting robust security standards and encrypting all sensitive data."

Matthew Tyler, director of consultancy Evolution Security Systems, told vnunet.com that his company had recently been involved with a government project to look at encrypting data on memory sticks.

"Although a good step in today’s internet age, why is there still a requirement to take massive amounts of hugely sensitive data out in the first place?" he said.

"Most recent data breaches have been down to people not following current procedures, so surely the best way forward is to design systems where this sensitive information cannot be taken out en masse as there is no reason to be doing this in this day and age."

Philip Wicks, a security expert at IT services firm Morse, emphasised the importance of stringent policies and procedures that either stop people being able to download sensitive information onto these devices, or make sure that the data is encrypted.

"Organisations need to ensure they have controls in place to protect the data on laptops, phones, memory sticks and other removable storage devices so that, if they are lost and end up in the hands of criminals, the data cannot be used for unscrupulous purposes," he said.

Phil Bridge, UK managing director at data recovery firm Kroll Ontrack, pointed out that human error is a major contributing factor to the government's data loss incidents.

"It is clear that data protection technology is moving faster than human procedure," he said. "Employees must be trained to view methods like encryption as standard business processes, not practices reserved for special occasions."

However, Paula Barrett, a partner at international law firm Eversheds, believes that the government is slowly learning the lessons from the HMRC breach, and that new standards for data protection are being drawn up.

"Organisational and technical changes are needed, but so too is widespread raising of the awareness of what those standards are," she explained.

"This is not something that can be implemented by information assurance personnel alone. Buy-in has to come across the department. Accountability is therefore also a key element."

Barrett added that further legislation could be on the way to force organisations to take data protection more seriously. "Changes are afoot. Await with interest the content of the Queen's Speech in a few weeks' time," she said.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Richard ThomasCommunications

Privacy tzar speaks out against data breach notification laws

But Information Commissioner admits breach levels remain worrying 29 Oct 2008

 

Public demands data breach legislation

Overwhelming majority would want to know if their details were lost or stolen 06 Jun 2008

IT directors call for mandatory data breach disclosure

Insider threats taken to the top of security agendas 29 May 2008

HMRC staff sacked for reading personal data

Over 600 workers disciplined since 2005 01 May 2008

HMRC wins villain of the year award

Another reason to hate the taxman 17 Mar 2008

Zurich Insurance confesses to data loss

Information on 51,000 customers goes missing during transfer 23 Oct 2009

Advisers fear being caught in Liechtenstein tax net

Information gathered by HMRC in its drive for disclosure from Liechtenstein account holders could be used by other UK government agencies 10 Jun 2010

One in 10 Britons on police DNA database

More than 5.5 million records held on controversial system 28 Oct 2009

related white papers

today's top stories

Interview: Jos Creese, chief information officer, Socitm

Head of Socitm, the body for local authority IT professionals, discusses how to get the most from IT services at a time when budgets are being cut to the bone. Dawinderpal Sahota listens in 09 Sep 2010

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

When business brains turn to crime

Cyber criminals are far better organised and more sophisticated than most legitimate e-commerce operations, writes Stuart Sumner 08 Sep 2010

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

Picture of Google logoAnalysis

Will IPv6 boost search engine rankings or is that wishful thinking?

Will search engine providers consider web-server IPv6 support to rank content in the future? 09 Sep 2010

Jos CreeseFeatures

Interview: Jos Creese, chief information officer, Socitm

Head of Socitm, the body for local authority IT professionals, discusses how to get the most from IT services at a time when budgets are being cut to the bone. Dawinderpal Sahota listens in 09 Sep 2010

Primary Navigation