Clients kept in the dark over data breaches, says survey
Logica survey reveals only 40% of UK organisations whose data is breached tell clients
LONDON – A survey conducted by IT and business services firm Logica reveals companies are failing to report data security breaches to clients. Some 60% of those who have experienced a data breach did not tell their clients and half failed to tell the police or authorities.
The study surveyed 300 public and private sector organisations in the UK over the past two months. The findings revealed more than half (57%) of those surveyed have “no idea” or understanding of the impact of a security breach on their business or organisation. A continued lack of engagement with the issue is evident, with just 16% of firms having a value-at-risk profile for information assets they own or control. Half of respondents believe security is solely an issue for the IT department.
Tim Best, director of enterprise security solutions at Logica, says: “Data losses put customers at risk and can lead to large contracts being withdrawn. With some organisations failing to disclose security breaches, this complacent attitude not only increases the likelihood of financial and reputational consequences but also highlights the inadequate security policies and protocols that UK organisations have in place. It is time to take action – it should be mandatory for all organisations to report significant breaches of confidential personal information to the Information Commissioner or their regulatory body. Only through mandatory reporting will the scale of the problem be understood, which will lead to the correct solutions being applied.”
The study also demonstrated many organisations lacked awareness of how to securely manage data and how to prevent a security breach. Only 30% were found to educate staff in IT security and information-handling procedures on a regular basis and less than a third employ a specific security incident response team. The survey also revealed that, while 63% of those surveyed hold personal data subject to EU data-handling regulations, only a quarter comply with ISO 27001/2, meaning companies are not adhering to security procedures when storing personal data.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Risk management
Banks feel regulatory heat on op resilience
Op Risk Benchmarking: supervisors dial up reporting expectations and on-site inspections
BofA’s rates revamp leans into multi-strategy boom
New rates head Laura Chepucavage prioritises collateral efficiency, e-trading and central risk book for enlarged rates, futures and financing unit
Revolutionising credit surveillance: part two
Does GenAI live up to the hype? How prioritising AI and digitisation projects reveals data as the power behind AI initiatives
Elevating risk management to a strategic partner in investment decision-making
How risk management is evolving from a compliance role to a strategic partner, highlighting such themes as collaboration with portfolio teams, forward-looking approaches, advanced analytics and integrating emerging risks, enabling firms to navigate…
Withholding tax trips up Eurex agency clearing model
Clearing members rely on CCP to resolve potential problem with German tax authorities
Thin-skinned: are CCPs skimping on capital cover?
Growth of default funds calls into question clearers’ skin in the game
Independent audits drive compliance in FRTB data solutions
The EU and the Basel Committee have introduced strict audit standards for data vendors to uphold the FRTB rules. With deadlines approaching, audited solutions are critical for banks to ensure compliance, minimise NMRFs and reduce capital requirements
New CME guidance to drive tighter margin call management
Clearing house rule clarified to limit the use of grace periods to cases of admin/operational errors only