Introduction
The loss of a laptop containing medical records for 5,000 people was just one of a drip-feed of data privacy breach news stories in the past year. Public sector incidents alone led to over 37 million UK citizens having their personal data lost or stolen.
The leakage of 25 million child benefit records at HMRC last November was the world's 5th largest reported data loss incident. With incidents at the DVLA, the MoD, NHS and US Government agencies, it seemed the issue of lax data security was a public sector problem.
But private enterprise also grabbed headlines in 2007, dubbed "The worst ever year for data protection" by website The Register. TK Maxx lost 5 million UK credit card records, Monster.com had details of 3 million customers taken, at loans.co.uk 250,000 private customer records were stolen & sold and Leeds Building Society lost data on its entire workforce.
Commercial Concerns
Loss of customer data is not the only worry in the private sector. A rising tide in Merger & Acquisitions and intensely competitive market has flagged the protection of commercially sensitive data as an equally strong concern.
Company directors and senior public officials are now taking steps to review policies, implement sensitive data procedures and assess the risks of their organisations losing private or commercially sensitive data. Sectors at high risk include Retail, Financial Services, Utilities and Professional Services.
Legislation & Standards
Protecting customers' data privacy and that of the company not only makes sound business sense but is also becoming the subject of industry, government & EU regulation. According to security consultancy Vigitrust, laws such as the European Union Data Protection Directive and equivalent U.S. regulations have resulted in information security becoming a board level action item.
It would be a mistake for UK & European organisations to ignore U.S. legislation in this area as it may also be binding on companies trading with US consumers. Regulations such as California Senate Bill 1386 apply to "any person or business that conducts business in California" even if they are located outside the U.S.
Many organisations are pursuing ISO 27001 accreditation, the Information Security Standard (formerly BS7799). Larger retailers are striving to meet the Payments Card Industry (PCI) standard pioneered by Visa & MasterCard to address identity theft.
The public sector responded to its 'annus horibilis' by mandating data encryption on all laptops, but also by disseminating Information Governance standards on data privacy to all public bodies and practical assistance such as the 'Information Governance Toolkits'.
Risk mitigation software vendor The Irish company, best known for detecting & reporting on illicit image abuse, has been conducting 'Discovery Audits' to detect unprotected sensitive data on company networks since 2007; its auditors found such unprotected data in over 36% of all IT resources scanned, including 46% of PCs, 32% of e-mail accounts and 30% of file servers. In each case, it required at least 20 instances of suspected privacy data to be detected in a document before being logged as 'suspect'.
Risk assessment - Where to start?
Best practice begins with a risk assessment to detect actual data breaches or the existence of 'data at risk'. In order to help corporations gain visibility of this risk, The Irish company offers a complimentary 'Discovery Audit' to detect and report on the presence of sensitive data at rest.
The Irish company Privacy Auditor software will scan for sensitive data such as Credit Card, Bank Account or National Insurance numbers, encryption keys etc. held in plain text on e-mail, desktop PCs, laptops and file servers. The Irish company Privacy Auditor can, on request, remove or encrypt such data for the client.
During this engagement, the organisation may nominate specific sensitive data or documents to be detected on its network, such as commercially sensitive financial data. A comprehensive report is delivered, together with suitable recommendations.
With the public focus on risk & compliance in the treatment of sensitive data, an early risk assessment is now considered the essential starting point to protecting the best interests of taxpayers, customers, companies and ordinary citizens alike.
- Related Videos
- Related Articles
- Ask / Related Q&A




Is ExpertAntivirus a Trusted Security Program?
By: Carl Haugen | 01/12/2009ExpertAntivirus is a rogue security program that claims to remove infections from your PC, but is a parasite itself. This application uses aggressive and misleading tactics to scare the user. The makers of this product want you to believe that threats are on your computer, and that their product will remove these threats. It is all a hoax; don't waste your money!
Choosing a Guillotine Style Paper Cutter
By: Jeff McRitchie | 01/12/2009An important piece of equipment to have in your copy room or work area is a guillotine paper cutter. Guillotine paper cutters can help you quickly trim large stacks of paper. For that reason they are a must-have item if you company produces a lot of documents. But how do...
Restaurant Surveillance with IP Cameras
By: Wes Fernley | 01/12/2009If you're thinking of using an IP camera (also known as a network camera or internet camera) within a restaurant, there are a few unique issues that need to be considered.
Yesterday, Today and Tomorrow
By: Felicia luo | 01/12/2009Today I would like to take the LED projector as an example to exactly explain its life, that is to say, I will briefly discuss its yesterday, today and tomorrow.
NTLDR is missing windows xp - How to fix NTLDR missing
By: zerobyte007 | 01/12/2009Here's the simple step by step how to fix NTLDR Missing issue in windows xp in a minute
The Magic Flash Drive - Fix Your Computer Anytime or Anywhere
By: Copeac | 01/12/2009What is The Magic Flash Drive? Magic Drive is first and foremost a full year membership to our signature service called Remote Restore where we fix your computer for you online in real time. You get unlimited usage of Remote Restore, unlimited phone support, online data back up (up to 12 gig). The Magic Flash Drive also has a toolbox full of utilities pre-loaded so that in the event you cannot access the Internet, the Magic Flash Drive can still repair your computer for you with our help.
The Google Power Meter: Letting You See What You Really Need to See
By: Ezra Drissman | 30/11/2009From the ninety-eight year old refrigerator (give or take a decade) to the four computers that are currently running without a user in front of them, to the television that is one for the apparent amusement of the golden retriever, you know that a lot of electricity is not only being used, but being wasted as well.
Interactive flash map made easy for everyone -- including non programmers
By: Ko Fai Godfrey Ko | 30/11/2009Clickable, interactive flash maps have become an integral part of many websites for companies who want to display location and geographic-related information to their visitors. Map making is easy now and users can choose from a range of web services or software available in the market.
The Irish Company Monitor FAQ
By: Colm Doherty | 31/03/2009 | ManagementWhat does The Irish company Monitor do? The Irish company Monitor is designed to monitor images being viewed on a PC or Laptop and provides multisource image detection and analysis. The Irish company Monitor is deployed as an agent from a central administration console to the Desktop environment within an organisation...
SafeScreen FAQ
By: Colm Doherty | 31/03/2009 | ComputersWhat does SafeScreen do? SafeScreen is designed to monitor images being viewed on a PC or Laptop and provides multi-source image detection, analysis and prevention. SafeScreen runs on computer start-up monitors and report on the images being viewed, and depending upon the product configuration, will prevent inappropriate and illicit images being...
An Irish Company Human Resources
By: Colm Doherty | 31/03/2009 | ManagementDept FAQ What if I have an AUP policy regarding illegal images should I still communicate the introduction of auditing and monitoring software? While such software products are tools for detecting the presence of obscene or illegal images, their long term value lies in their potential as a preventative mechanism deterring...
False Positives. Targeting Accurate Illicit Images Detection
By: Colm Doherty | 30/03/2009 | ManagementWhen discussing inappropriate image detection, the most common question posed is "What about false positives?". In this article, an Irish company explains the issue of false positives in simple terms. What is a false positive? One definition of a False Positive is: "A positive test result in a subject that does not...
No Nudes is Good News
By: Colm Doherty | 30/03/2009 | ManagementRecent statistics collated during 60 corporate audits undertaken by an Irish company between June and September 2006, found that 31.2% of the 5,000 PCs scanned contained digital pornography or other inappropriate images, 8% of the 5,000 email server accounts and 4.5% of 10,000 file server shares scanned were similarly affected....
Data Loss and Privacy Risk - A Top Priority in 2008
By: Colm Doherty | 30/03/2009 | ComputersIntroduction The loss of a laptop containing medical records for 5,000 people was just one of a drip-feed of data privacy breach news stories in the past year. Public sector incidents alone led to over 37 million UK citizens having their personal data lost or stolen. The leakage of 25 million child...
Porn Images and the Public Sector
By: Colm Doherty | 30/03/2009 | ManagementAn Audit Commission report published in June this year highlighted a huge increase in the viewing of computer pornography by public sector workers. The report called for public sector organisations from councils and government departments to the NHS, police and fire-fighters to invest in technology to prevent inappropriate or illegal...
Assessing The Risks Caused By Illicit Images In The Workplace
By: Colm Doherty | 29/03/2009 | ManagementControlling the abuse of illegal and inappropriate images in the workplace is an increasingly important part of managing risk for an organisation. Private use of company computer resources for pornography can lead to a whole host of problems, from lost productivity, wasted computer resources and e-viral infections through to serious...