Now It's Ofcom's Turn To Face The Shame Of A Data Breach

Mar 11, 2016

Reports emerged yesterday that media regulator Ofcom suffered a mass data breach after a former employee leaked sensitive information on TV companies to a major broadcaster.

According to reports, the former Ofcom employee downloaded as much as six years worth of data before leaving the company, which was then offered to his/her new employee in an attempt to gain an advantage over the competition.

A statement from Ofcom said: “On 26 February we became aware of an incident involving the misuse of third-party data by a former Ofcom employee,” said a spokesman for Ofcom. “This was a breach of the former employee’s statutory duty under the Communications Act and a breach of the contract with Ofcom.”

“Ofcom takes the protection of data extremely seriously, and we are very disappointed that a former employee has chosen to act in this manner,” said the spokesman. “The extent of the disclosure was limited and has been contained, and we have taken urgent steps to inform all parties.”

Various industry professionals have offered their thoughts on the news.

Ross Brewer, VP and MD of EMEA at LogRhythm:

“This is a perfect example of how a breach isn’t always a high-tech hack. Sometimes the culprit really can be someone who sits next to you at work, and not the anonymous, faceless, perpetrator that has become synonymous with modern-day cybercrime. Companies need to be aware that when sensitive information is readily available amongst employees, there is the possibility for anyone to abuse their trusted position.

“Companies like Ofcom hold huge quantities of confidential data and this will no doubt be a big wake-up call for the communications regulator. A big problem is that many businesses use the majority of their resources fighting the external threat, often underestimating the impact that the insider threat can have. However, as Ofcom will likely discover, employees can pose a very real threat to a company’s reputation.

“As well as having strict access control policies, it’s vital that businesses have full visibility of their network activity so they are aware of what is happening at all times. Indeed, by continuously monitoring the network, businesses can identify abnormal activity – such as downloading large batches of sensitive data – as soon as it occurs.”

Louise Bulman, ?Vice President & General Manager, EMEA at Vormetric:

“Ofcom is just one of many businesses to be affected by the ‘insider threat’, involving the inappropriate or unauthorised access and theft of confidential company data, an aspect of security which organisations are continuing to find difficult to address.

“The incident is a perfect example of how firms struggle to protect their data resources from those already legitimately ‘inside the fence’. It is often a case of ineffective management of ‘privileged’ users oncorporate networks that causes this type of data breach incident. Every organisation will have employees or contractors who have far reaching, privileged, computer network access rights – and it is how these users are controlled and secured that is often a weak link in the data security framework.

“Organisations, no matter what their size, need to adopt a layered ‘defence-in-depth’ approach using transparent encryption with access control to ensure that, no matter how or where information exists on systems, it remains secure. Furthermore, an ‘encrypt everything’ strategy reduces the damage that hackers can cause further, as it renders any stolen data illegible and virtually useless.”

David Gibson, VP of strategy and market development at Varonis:

“A vast number of data breaches are due to insiders, malicious or otherwise. The root of the problem is that most employees have access to far more information than they need to do their jobs, their data activities are not monitored or analysed for malicious behaviour. This is especially true for unstructured data – the largest, fastest growing kind of data that often contains an organisation’s intellectual property, financial records, and other important content.

“As a result, low-level workers can access and make off with highly sensitive information, often without anyone knowing. To make matters worse, outsider attackers often hijack employee or contractor credentials and then have the same free access as insiders. Organisations have to start doing a better job of tracking and analysing how users use data, profiling their roles and behaviours, mapping and reducing unwanted access, discovering sensitive data and locking it down or moving it out of harm’s way.”

Mark Bower, global director for product management at HPE Security:

“This event illustrates that even with a strong network perimeter in place, it just isn’t enough. Perimeter security is similar to a fence around a house. However, what if someone inside the house is the thief? Today it’s imperative that organisations adopt a data-centric security approach that defends the data itself, typically by encryption or tokenisation. This ensures that no matter where the data resides, if a hacker gets it, or in this case, an employee who is granted legitimate access, the data is protected and isn’t useful. This ability to render data useless if lost or stolen is an essential benefit to ensure data remains secure.

“The EU is introducing aggressive new data privacy laws under the General Data Protection Regulation (GDPR) that will force any breached organisation to pay substantial fines that are a percentage of revenues, issue notification within 72 hours and implement modern data security strategies like data-centric security as best practice.

“This major regulatory shift is a result of breaches like this, and the ineffective nature of traditional controls that are unsuited to today’s data workflows, the extended enterprise, insider threats and advanced malware.

“Organisations have to be planning to meet GDPR now, and more critically, significantly reducing access to live data to minimise future threat impact.”

Image source: Shutterstock/Andrea Danti

Author: Sam Pudwell
View the original article here.
Published under license from ITProPortal.com

 

 

 

https://lifeinsys.com/user/david01
https://app.roll20.net/users/14015474/david-s
https://www.quia.com/profiles/dasmith469
https://www.divephotoguide.com/user/david01
https://photoclub.canadiangeographic.ca/profile/21326904
https://starity.hu/profil/471349-david01/
https://www.facer.io/user/fcuA6R3PWA
https://swaay.com/u/dubaimetro01/about/
https://bootstrapbay.com/user/David02
https://www.trovagas.com/author/david02/
https://mycableengineering.com/activity-feed/userId/11883
https://slideslive.com/david02?tab=about
https://outof.games/members/david02/
https://mentorship.healthyseminars.com/members/david02/
https://onlinevetjobs.com/author/david02/
http://jobboard.piasd.org/author/david02/
https://rnstaffers.com/author/david02/
https://www.bitsdujour.com/profiles/ZKxOus
https://hanson.net/users/david02
http://fid101.ldd.go.th/Activity-Feed/My-Profile/UserId/430
https://cyprus.com/author/david02/
https://ca-riverside-acr.publicaccessnow.com/ActivityFeed/MyProfile/tabid/24/UserId/21065/Default.aspx
https://www.openrec.tv/user/david02/about
http://www.in-almelo.com/User-Profile/userId/2408692
https://www.metaculus.com/accounts/profile/198168/
https://homment.com/fujScGVD3slgtJSo2Hmt
https://www.dnnsoftware.com/activity-feed/my-profile/userid/3207527
https://www.showmethesite.us/lazychicken/ActivityFeed/MyProfile/tabid/2622/UserId/552473/Default.aspx
https://buyandsellhair.com/author/davidmerchant02/
http://aldenfamilydentistry.com/UserProfile/tabid/57/userId/864985/Default.aspx
https://postgresconf.org/users/david-merchant
http://www.worldchampmambo.com/UserProfile/tabid/42/userId/391127/Default.aspx
https://www.pearltrees.com/davidmerchant02
https://useum.org/myuseum/David%2015
https://employbahamians.com/author/david02/
https://www.lotusforsale.com/author/david02/
https://guidetoiceland.is/traveler-profiles/dubaimetro01
https://medibang.com/author/26628380/
https://www.provenexpert.com/david02/
https://independent.academia.edu/DavidMerchant8
https://www.mixcloud.com/davidmerchant02/
https://public.tableau.com/app/profile/david.smith4458/vizzes
https://fitinline.com/profile/david02/
https://www.guiafacillagos.com.br/author/david02/
https://aboutcasemanagerjobs.com/author/david02/
https://www.reddit.com/user/According-Pipe-4349/
https://hfonline.org/members/david02/
https://edgeforscholars.org/author/David02/
https://boersen.oeh-salzburg.at/author/david02/
https://www.allmyusjobs.com/author/david02/
https://medium.com/@dubaimetro01/about
https://conifer.rhizome.org/david02
https://maltajobs.com.mt/author/david02/
https://solo.to/david02
https://olderworkers.com.au/author/dubaimetro01proton-me/
https://www.nieveaventura.com/author/david02/
https://fast-mag.com/author/david02/
https://therealblackfriday.com/author/david02/
https://my.djtechtools.com/users/1428921
https://allmynursejobs.com/author/david02/
https://producerbox.com/users/david02
https://willysforsale.com/author/david02/
https://maactioncinema.com/archives/author/david02
https://aboutnursinghomejobs.com/author/davidsmith02/
https://aboutdirectorofnursingjobs.com/author/davidsmith02/
https://divisionmidway.org/jobs/author/davidsmith02/
https://rndirectors.com/author/davidsmith02/
https://aboutnursernjobs.com/author/davidsmith02/
https://www.diversityofficermagazine.com/diversityjobs/author/davidsmith02/
https://worldranksite.com/author/david02-20618/
https://topbilliondirectory.com/author/david02-19255/
https://microlinksite.com/author/david02-18397/
https://schoolido.lu/user/David02/
https://crypto-potential.com/user/david-smith2
https://www.phraseum.com/user/39572
https://blog.rackons.in/profile/david02
https://blatini.com/profile/David02
http://www.fanart-central.net/user/David02/profile
https://www.zerohedge.com/user/UugyBpExMQaJ1PEunfLJLgRCuDh2
https://www.thebostoncalendar.com/user/84389
https://www.lingvolive.com/en-us/profile/5affccd8-53c7-481c-8163-1e6a751ee318/translations
https://www.pressregister.com/user/public-profile/62355
https://orangelifemagazine.com/author/david02/
https://www.adproceed.com/author/david02/
https://read-blogs.com/author/david02/
https://www.ziparticle.com/author/david02/
https://www.outlived.co.uk/author/david02/
https://classifieds.villages-news.com/author/david02
https://wayranks.com/author/david02-718065/
https://www.mangalorean.com/author/david02/
https://www.tumblr.com/davidsmith-02/758144649588293632/david
https://confengine.com/user/david-smith-3-1
https://handyclassified.com/profile/david02
https://etwinningonline.eba.gov.tr/author/david02/
https://www.vtforeignpolicy.com/author/david02/
https://shareresearch.us/profile/David02
https://www.rafabasa.com/author/david02/
https://www.flowcode.com/page/david02
https://linkpop.com/david02-slug-david02
https://fashonation.com/members/david02/profile/
https://hpad.dataone.org/s/NEZhn8JFX
https://trabajo.merca20.com/author/davidsmith02/
http://amabilis.com/?bbp_user=44909
https://start.me/u/19K1Qj/david
https://arzookanak112.xobor.de/u81_david.html
https://www.sonicbids.com/band/david02/
https://log.concept2.com/profile/2388919
https://activepages.com.au/profile/david02
https://www.popdaily.com.tw/user/459272
https://petites-annonces.commeuncamion.com/author/davidsmith02/
https://linkingdirectory.com/author/david02-17831/
https://blognow.co.in/profile/david02
https://glamorouslengths.com/author/david02/
https://www.sabahjobs.com/author/david02/
https://mercadodinamico.com.br/author/david02/
https://www.sitiosecuador.com/author/davidsmith02/
https://rnmanagers.com/author/david02/
https://progresspond.com/members/david02/
https://toparticlesdirectory.com/author/david02/
https://topacted.com/author/david02-15327/
https://my.archdaily.com/us/@david-smith-38
https://gwar.net/a/bohabs/users/163621
https://www.evtv.me/author/david02/
https://hinative.com/profiles/8234548
https://www.bigoven.com/user/davidsmith02
https://jobs.motionographer.com/employers/3225567-david
https://suzuri.jp/David02
https://maxternmedia.com/author/david02/
https://my.desktopnexus.com/davidsmith02/
https://www.kniterate.com/community/users/david02/
https://cars.yclas.com/user/david-smith-6
https://www.workathomejobsboard.com/employers/3225596-david
https://www.herlypc.es/community/profile/david02/
https://www.deviantart.com/davidsmith02/about
https://jobs.siliconflorist.com/employers/3225646-david-smith
https://eternagame.org/players/394815
https://soundcloud.com/dubaimetro01
https://list.ly/David02/lists
https://slides.com/davidsmith02
https://www.komoot.com/user/4337847745084
https://myanimelist.net/profile/davidsmith02
https://www.mountainproject.com/user/201889914/david-smith
https://www.stem.org.uk/user/1369736
https://www.anobii.com/en/011cdc68c654c023a8/profile/activity
https://foro.kechollazo.com/members/david02.14643/#about
https://yellowfever.co.nz/users/davidsmith02
https://jobs.tdwi.org/employers/3225740-david-smith
https://profile.hatena.ne.jp/davidsmith02/profile
https://bandori.party/user/209596/david02/
https://jobs.employabilitydallas.org/employers/3225755-david-smith
https://jobs.nefeshinternational.org/employers/3225758-david-smith
https://akniga.org/profile/david02/
https://desksnear.me/users/david-smith-ae9110
https://app.impactplus.com/users/david-smith-fe6a3ba6-8c79-4208-a383-7e2d9b0e950a
https://losangeles.bubblelife.com/users/dubaimetro01_b60719
https://www.diigo.com/item/note/b5rx6/8irk?k=92c94fd58c81a79c32216d80ef8b9154
https://www.rafabasa.com/author/diana01/
https://fashonation.com/members/diana01/profile/
http://amabilis.com/?bbp_user=45540
https://trabajo.merca20.com/author/diana01/
https://hpad.dataone.org/s/3i4B21VcZ
https://www.sonicbids.com/band/diana01/
https://participedia.net/user/428445
https://mikropragmata.lifo.gr/meli/23267/
https://petites-annonces.commeuncamion.com/author/diana01/
https://linkingdirectory.com/author/diana01-25276/
https://www.quora.com/profile/Diana-Walker-262
https://www.kniterate.com/community/users/diana01/
https://gravesales.com/author/diana01/
https://www.inspireglobalsolutions.com/profile/Diana8
https://www.letsknowit.com/diana25241
https://glamorouslengths.com/author/Diana01/
https://www.sitiosecuador.com/author/diana01/
https://www.beatstars.com/realdoctorsnotes/about
https://rnmanagers.com/author/diana01/
https://progresspond.com/members/diana01/
https://certified.heartmath.com/user/diana-walker/
https://profile.pmc.org/DW0282
https://bumpy-hope-641.notion.site/Diana-a518233dc6b04ab3a369f97336d420c4?pvs=25
https://www.stampstampede.org/society-stampers/members/DI01/
https://blogzone.hellobox.co/6976396/diana
https://econarticle.com/profile/Diana01
https://www.makerist.de/users/realdoctorsnotes
https://businessleed.com/author/Diana01/
https://next.nexusmods.com/profile/Dianawalker01/about-me
https://generalmagazine.org/author/diana01/
https://theduran.com/author/diana01/
https://dictanote.co/n/1065634/
https://www.fbtb.net/author/diana01/
https://www.polywork.com/diana_walker
https://utahsyardsale.com/author/diana01/
https://www.slmath.org/people/72373
https://speakerdeck.com/dianawalker01
https://www.niftygateway.com/@dianawalker1511/
https://pantip.com/profile/8384071#topics
Geeta
19/09/2024 12:14

Comment

 

Understanding the risks and rewards of public sector cloud 

Download the Whitepaper now

Partner

24Newswire
Sign up to receive latest news