Reports emerged yesterday that media regulator Ofcom suffered a mass data breach after a former employee leaked sensitive information on TV companies to a major broadcaster.
According to reports, the former Ofcom employee downloaded as much as six years worth of data before leaving the company, which was then offered to his/her new employee in an attempt to gain an advantage over the competition.
A statement from Ofcom said: “On 26 February we became aware of an incident involving the misuse of third-party data by a former Ofcom employee,” said a spokesman for Ofcom. “This was a breach of the former employee’s statutory duty under the Communications Act and a breach of the contract with Ofcom.”
“Ofcom takes the protection of data extremely seriously, and we are very disappointed that a former employee has chosen to act in this manner,” said the spokesman. “The extent of the disclosure was limited and has been contained, and we have taken urgent steps to inform all parties.”
Various industry professionals have offered their thoughts on the news.
Ross Brewer, VP and MD of EMEA at LogRhythm:
“This is a perfect example of how a breach isn’t always a high-tech hack. Sometimes the culprit really can be someone who sits next to you at work, and not the anonymous, faceless, perpetrator that has become synonymous with modern-day cybercrime. Companies need to be aware that when sensitive information is readily available amongst employees, there is the possibility for anyone to abuse their trusted position.
“Companies like Ofcom hold huge quantities of confidential data and this will no doubt be a big wake-up call for the communications regulator. A big problem is that many businesses use the majority of their resources fighting the external threat, often underestimating the impact that the insider threat can have. However, as Ofcom will likely discover, employees can pose a very real threat to a company’s reputation.
“As well as having strict access control policies, it’s vital that businesses have full visibility of their network activity so they are aware of what is happening at all times. Indeed, by continuously monitoring the network, businesses can identify abnormal activity – such as downloading large batches of sensitive data – as soon as it occurs.”
Louise Bulman, ?Vice President & General Manager, EMEA at Vormetric:
“Ofcom is just one of many businesses to be affected by the ‘insider threat’, involving the inappropriate or unauthorised access and theft of confidential company data, an aspect of security which organisations are continuing to find difficult to address.
“The incident is a perfect example of how firms struggle to protect their data resources from those already legitimately ‘inside the fence’. It is often a case of ineffective management of ‘privileged’ users oncorporate networks that causes this type of data breach incident. Every organisation will have employees or contractors who have far reaching, privileged, computer network access rights – and it is how these users are controlled and secured that is often a weak link in the data security framework.
“Organisations, no matter what their size, need to adopt a layered ‘defence-in-depth’ approach using transparent encryption with access control to ensure that, no matter how or where information exists on systems, it remains secure. Furthermore, an ‘encrypt everything’ strategy reduces the damage that hackers can cause further, as it renders any stolen data illegible and virtually useless.”
David Gibson, VP of strategy and market development at Varonis:
“A vast number of data breaches are due to insiders, malicious or otherwise. The root of the problem is that most employees have access to far more information than they need to do their jobs, their data activities are not monitored or analysed for malicious behaviour. This is especially true for unstructured data – the largest, fastest growing kind of data that often contains an organisation’s intellectual property, financial records, and other important content.
“As a result, low-level workers can access and make off with highly sensitive information, often without anyone knowing. To make matters worse, outsider attackers often hijack employee or contractor credentials and then have the same free access as insiders. Organisations have to start doing a better job of tracking and analysing how users use data, profiling their roles and behaviours, mapping and reducing unwanted access, discovering sensitive data and locking it down or moving it out of harm’s way.”
Mark Bower, global director for product management at HPE Security:
“This event illustrates that even with a strong network perimeter in place, it just isn’t enough. Perimeter security is similar to a fence around a house. However, what if someone inside the house is the thief? Today it’s imperative that organisations adopt a data-centric security approach that defends the data itself, typically by encryption or tokenisation. This ensures that no matter where the data resides, if a hacker gets it, or in this case, an employee who is granted legitimate access, the data is protected and isn’t useful. This ability to render data useless if lost or stolen is an essential benefit to ensure data remains secure.
“The EU is introducing aggressive new data privacy laws under the General Data Protection Regulation (GDPR) that will force any breached organisation to pay substantial fines that are a percentage of revenues, issue notification within 72 hours and implement modern data security strategies like data-centric security as best practice.
“This major regulatory shift is a result of breaches like this, and the ineffective nature of traditional controls that are unsuited to today’s data workflows, the extended enterprise, insider threats and advanced malware.
“Organisations have to be planning to meet GDPR now, and more critically, significantly reducing access to live data to minimise future threat impact.”
Image source: Shutterstock/Andrea Danti
Author: Sam Pudwell
View the original article here.
Published under license from ITProPortal.com
https://www.universe.com/users/dubai-metro-04BMC3
http://phpbt.online.fr/profile.php?mode=view&uid=12111
https://www.speedrun.com/users/dubaimetro
https://qooh.me/dubaimetro24
https://billionphotos.com/users/dubaimetro
https://simmer.io/@dubaimetro24
https://bikeindex.org/users/dubaimetro24
https://participa.rosario.gob.ar/profiles/dubaimetro/activity?locale=en
https://savee.it/dubaimetro24/
https://storyweaver.org.in/en/users/880158
https://library.zortrax.com/members/david-27/
https://www.cssreel.com/index.php?/userprofile/userdetails/dubaimetro
https://wemakeit.com/users/dubaimetro24
https://www.pledgeme.co.nz/profiles/221560
https://www.chaintalk.tv/user/dubaimetro24/?profiletab=main
https://www.malikmobile.com/dubaimetro24
https://www.zeczec.com/users/dubaimetro24
https://audio.com/dubaimetro
https://kommunity.com/@dubaimetro
https://trumpbookusa.com/dubaimetro24
https://heuristica.participa.cloud/profiles/dubaimetro24/activity
https://www.buymeacoffee.com/dubaimetro24
https://diit.cz/profil/urnmvnp8sr
https://rainplatform.wtelecom.es/user/69185/
https://code.antopie.org/dubaimetro24
https://gitea.ops.luminia.io/dubaimetro24
http://freihe.xobor.de/u3234_dubaimetro.html
https://findtoptenranks.com/author/david01/
https://elovebook.com/dubaimetro24
https://expatguidekorea.com/profile/dubai-metro/
https://mientrungreview.wixsite.com/mientrungreview/profile/dubaimetro24/profile
https://www.jgctruckdrivingtraining.com/profile/dubaimetro24/profile
https://www.babkis.com/profile/dubaimetro24/profile
https://www.spef.pt/profile/dubaimetro24/profile
https://www.greenpark-fukiware.com/profile/dubaimetro24/profile
https://www.layaspaandyoga.com/members-area/dubaimetro24/profile
https://owntweet.com/go_65cc88c92b162
https://ffm.bio/aoj2j0
https://photozou.jp/user/top/3352832
https://simulationhockey.com/member.php?action=profile&uid=9374
https://www.data.gouv.fr/fr/users/diana-diana-1/
https://mecabricks.com/en/user/Diana01
https://wwwmatthes.in.tum.de/persons/dhgxzv7c646d/Diana
https://kai-you.net/u/Diana01
https://www.wpanet.org/profile/realdoctorsnotes/profile
https://7tdmjpf5yuwu.jobboard.io/profiles/5267830-diana-walker
https://www.sutori.com/en/user/diana-walker-c81a?tab=profile
https://www.blurb.com/user/Dianawalker0?profile_preview=true
https://www.designspiration.com/realdoctorsnotes/saves/
https://www.spoonflower.com/profiles/diana01?sub_action=shop
https://www.worldanvil.com/author/Diana01
https://longbets.org/user/Diana01/
https://data.world/diana01
https://www.4shared.com/u/MQYNNY5s/realdoctorsnotes.html
https://wellfound.com/u/diana-walker-4
https://onlyfans.com/u444941949
https://www.titantalk.com/members/diana.384118/
https://www.openstreetmap.org/user/Dianawalker01
https://stocktwits.com/Dianawalker02
https://www.awwwards.com/diana-walker/
https://www.stylevore.com/user/realdoctorsnotes
https://triberr.com/Diana01
https://www.metooo.io/u/66e94730b6d67d6d17834dbc
https://www.decidim.barcelona/profiles/diana_walker/activity
https://www.atlasobscura.com/users/diana01
https://www.blogtalkradio.com/realdoctorsnotes
https://wefunder.com/dianawalker2
https://gifyu.com/diana01
https://community.hodinkee.com/members/Diana01
https://booklog.jp/users/dianawalker01/profile
https://www.awn.com/users/diana-1
https://participer.ge.ch/profiles/Diana01/activity?locale=en
https://participa.terrassa.cat/profiles/diana_walker/activity
https://appsumo.com/profile/104845205487865849207/
https://entre-vos-mains.alsace.eu/profiles/diana_walker/activity
https://www.aicrowd.com/participants/diana_walker
https://participez.villeurbanne.fr/profiles/diana_walker/activity
https://www.creativelive.com/student/diana-walker-10?via=accounts-freeform_2
https://www.magcloud.com/user/diana01
https://www.pinterest.com/dianaw4864/
https://diit.cz/profil/eddpz4ebqx
https://app.talkshoe.com/user/maclewis01/about
https://audio.com/mac-lewis
https://www.clarinetu.com/profile/mcdmenu/profile
https://www.layaspaandyoga.com/members-area/mcdmenu/profile
https://www.greenpark-fukiware.com/profile/mcdmenu/profile
https://www.spef.pt/profile/mcdmenu/profile
https://www.babkis.com/profile/mcdmenu/profile
https://rozanceenkora.wixstudio.com/vidi/profile/mcdmenu/profile
https://www.soyidec.com/profile/mcdmenu/profile
https://www.hiddenpeakteahouse.com/profile/mcdmenu/profile
https://www.dungeondelights.com/profile/mcdmenu/profile
https://www.fukagawine.tokyo/profile/mcdmenu/profile
https://www.twilightcreationsinc.com/profile/mcdmenu/profile
https://www.ilovecoffeegroup.co.za/profile/mcdmenu/profile
https://www.healthlinkdental.org/profile/mcdmenu/profile
https://www.interacao.espm.br/profile/mcdmenu/profile
https://www.reyaztecarestaurantbar.com/profile/mcdmenu/profile
https://www.woll2woll.com/profile/mcdmenu/profile
https://www.freethewild.org/profile/mcdmenu/profile
https://allmenuz.wixsite.com/menu/post/reloadable-gift-card-balance-check-manage-funds
https://allmenuz.wixsite.com/menu/post/restaurants-with-senior-menus-top-deals-discounts
https://allmenuz.wixsite.com/menu/post/best-shrimp-cooking-methods-tasty-easy-techniques
https://allmenuz.wixsite.com/menu/post/affordable-catering-packages-budget-friendly-options
https://allmenuz.wixsite.com/menu/post/artistic-feather-illustration-creative-drawing-ideas
https://allmenuz.wixsite.com/menu/post/fast-food-fries-comparison-taste-quality-guide
https://allmenuz.wixsite.com/menu/post/classic-bar-drinks-list-must-try-cocktails-more
https://67970103920ed.site123.me/blog/allergy-symptoms-and-treatment-guide
https://678787deea85b.site123.me/blog/flavored-butter-ideas-delicious-combinations-to-try
https://678787deea85b.site123.me/blog/bbq-side-menu-best-dishes-for-your-cookout
https://678787deea85b.site123.me/blog/reverse-sear-ribeye-perfect-steak-every-time
https://678787deea85b.site123.me/blog/phone-number-lookup-find-details-instantly
https://678787deea85b.site123.me/blog/cozy-winter-scene-coloring-fun-pages-to-print
https://healthylife9061.wordpress.com/2025/02/05/postpartum-work-re-entry-tips-and-considerations/
https://allmenuz.blogspot.com/2025/02/free-meals-for-veterans-top-restaurants.html
https://allmenuz.blogspot.com/2025/02/user-friendly-apps-best-easy-to-use.html
https://allmenuz.blogspot.com/2025/02/air-fryer-buffalo-wings-crispy-spicy.html
https://allmenuz.blogspot.com/2025/02/compound-butter-ideas-flavorful-blends.html
https://allmenuz.blogspot.com/2025/02/realistic-hair-drawing-tips-techniques.html
https://allmenuz.blogspot.com/2025/02/classic-double-cheeseburger-recipe.html
https://allmenuz.blogspot.com/2025/02/best-plant-based-dishes-must-try-vegan.html
https://67970103920ed.site123.me/blog/work-time-off-for-health-reasons-key-considerations
https://medium.com/@menuz/global-desserts-sweet-treats-from-around-the-world-89a93d69c84b
https://medium.com/@menuz/calorie-density-smart-eating-for-better-health-511d9b0b65fb
https://medium.com/@menuz/restaurant-coupons-and-deals-save-big-on-dining-07f4483197dc
https://medium.com/@menuz/meal-planning-for-families-easy-healthy-dinners-41447339a74b
https://medium.com/@menuz/fun-winter-activities-coloring-snowy-adventures-for-all-9edc107d86f9
https://healthylife9061.wordpress.com/2025/02/05/dentist-excuse-for-school-missed-valid-reason-explained/
https://allmenuz.wordpress.com/2025/02/11/best-catering-services-top-catering-options-for-any-event/
https://allmenuz.wordpress.com/2025/02/11/successful-fundraising-strategies-effective-ways-to-raise-more-funds/
https://allmenuz.wordpress.com/2025/02/11/best-prime-rib-cuts-top-cuts-for-juicy-prime-rib/
https://allmenuz.wordpress.com/2025/02/11/marinating-tips-for-steak-best-marinades-for-flavorful-steak/
https://allmenuz.wordpress.com/2025/02/11/dove-art-for-beginners-easy-dove-drawing-painting-tips/
https://allmenuz.wordpress.com/2025/02/11/mcdonalds-special-deals-best-mcdonalds-discounts/
https://allmenuz.wordpress.com/2025/02/11/picnic-party-food-ideas-delicious-easy-picnic-foods/
https://medium.com/@menuz/popular-menu-dishes-top-picks-for-a-delicious-meal-5e3a08764445
https://medium.com/@menuz/restaurant-career-opportunities-growth-jobs-in-hospitality-538e32f6da03
https://medium.com/@menuz/award-winning-chili-recipe-the-ultimate-flavor-packed-bowl-b93df16c952a
https://medium.com/@menuz/best-hurricane-margarita-mix-perfect-blend-for-tropical-vibes-91645197aba0
https://medium.com/@menuz/wintertime-cozy-cabin-coloring-page-relax-color-a-snowy-escape-7425258f929e