sb-eu logo
Story image

ICO report reaction: UK data security incidents rocket 224%

20 Oct 2018

Following the recent release of the Informaition Commissioner's Office' data security incident trends report, Egress Software CEO Tony Pepper has some thoughts on the topic and what the startling numbers actually mean for the industry as a whole.

"After reviewing the short report, it comes as no real surprise that we have seen a pronounced uptick in the overall number of incident reports filed by organisations to the ICO," says Pepper.

"This increase is likely due to the new data breach notification requirements under GDPR, which require organisations to report incidents within 72 hours of becoming aware of them," Pepper says.

However, Pepper says while the numbers are certainly bad, they may not be as bad as at first glance.

"What must be taken into consideration is that whilst we have seen a 228% increase in reported data security incidents (from 957 in January to March 2018 to 3146 in April to June 2018), this does not necessarily mean that organisations are experiencing more breaches than before; it simply means that more are now being reported and forced into the light," Pepper says.

"Drilling further into the statistics, it is interesting to see that most data breach incidents are again down to people, processes and inadequate policies. The data reveals 3146 ‘security incidents’, which frequently involve internal actors making mistakes (including incorrect disclosure of data, which counted for 65%), as opposed to the 414 that are ‘cyber threats’ caused by malware, ransomware, brute force attacks and phishing. In terms of industry sectors, Healthcare, General Business and Education were the most affected. Where cyber threats were concerned, nearly 40% of these are attributed to phishing."

Other stats show the ICO to be nailing down hard on penalties - and there could be more to come.

"In terms of the monetary penalties we can see that the fines have doubled, rising to £1,030,000 in April to June of this year compared to £653,000 in the same period last year, and since 25th May to beginning of October this has gone up again to £1,425,000.  Interestingly, all these fines are still under the Data Protection Act, as to date no company has actually been fined under GDPR," says Pepper.

"At Egress, we believe that organisations should take a user-centric approach to data security, ensuring that every employee is as security savvy as they need to be. In the run up to GDPR, a survey we conducted sought to find out whether the data compliance mantra that has been drilled into the tech team had trickled down to the average worker. It revealed that 20% of employees were still using insecure channels to share company documents, including personal email, social media, cloud sharing and messaging apps. Moreover, 39% did not know if their company was doing enough to protect customer data in the light of recent data breaches and 1 in 5 did not know what kinds of personal information should be protected when sharing data via email."

Pepper says businesses need to clamp down on users, as that is where the sheer majority of breaches come from.

"Today, the user is the only constant within organisations and by taking a user-centric approach and equipping staff to handle personal data –through technology that supports and secures the work they do, as well as more training and awareness – companies will be better placed to close the gap in their compliance programme," Pepper says.

"It will be interesting to see how these statistics breakdown further when the full report becomes available."

Story image
CrowdStrike integrates with ServiceNow program to bolster incident response
As part of the move, users can now integrate device data from the CrowdStrike Falcon platform into their incident response process, allowing for the improvement of both the security and IT operation outcomes.More
Story image
Phishing scam imitates SharePoint & OneNote for nefarious clicks
Sophos researchers say that the attackers take a slightly different approach to the standard ‘fake login’ phishing email.More
Story image
How security awareness training can safeguard companies from cyber-attacks
Training goes a long way in embedding a culture of cybersecurity compliance within the company.More
Story image
Check Point acquires Odo Security to bolster remote security offering
The deal will integrate Odo’s remote access software with Check Point’s Inifinity architecture, bolstering the latter company’s remote security capabilities in a time where working and learning from home has become the norm, and looks to largely remain that way in the near future.More
Story image
High-tech heist: why fending off ransomware attacks is more challenging than ever in 2020
The COVID-19 crisis has unleashed a wave of sophisticated and disruptive ransomware attacks, and the onus is on businesses to ramp up their security measures if they’re to avoid falling victim, writes Attivo Networks regional director for A/NZ Jim Cook.More
Story image
Gartner predicts 75% of CEOs to be liable for cyber-physical security incidents by 2024
The nature of CPSs means incidents can quickly lead to physical harm to people, destruction of property or environmental disasters – and Gartner’s new research indicates that these incidents will increase drastically in the next few years if the lack of spending on these assets continues.More