Latest Blog Posts

Focus on 2012: 5 key areas in Enterprise IT

(19 December 2011)

From in-house to consultancy: moving to the ‘dark side’

(01 December 2011)

Brace for the feared double dip: IT planning can maximise mergers and acquisitions

(27 October 2011)

The tricky business of justifying IT expenditure

(19 October 2011)

IT consultants should drop the ITIL clichés to win clients over

(19 October 2011)

Steps to a successful Service Transition – new white paper by Plan-Net

(26 September 2011)

‘Cloud Consultancy’ – Experience On Demand

(26 September 2011)

ITIL 2011: Continual Service Improvement or just the result of V3 being rushed?

(03 August 2011)

The GLOCAL IT Service Desk

(26 June 2011)

Oh no… Not another Service Management initiative!

(20 June 2011)

5 reasons to employ an IT consultant

(22 May 2011)

Financial firms’ IP is safe with VDI

(11 May 2011)

IT Support: grow-your-own or buy organic?

(11 May 2011)

Where is that ‘cultural change’ which makes ITSM Best Practice effective?

(19 April 2011)

Executive exceptions: Best Practice killers or just business as usual?

(10 April 2011)

Desktop Virtualisation: Still not a perfect View

(23 March 2011)

What is the impact of the Cloud on the existing IT environment?

(10 March 2011)

Private vs. public sector IT security: more dedicated staff, yet less awareness

(03 March 2011)

Surviving IT spending cuts in the public sector

(15 February 2011)

10 things we learnt in 2010 that can help make 2011 better

(23 December 2010)

IT workforce continuity

(17 December 2010)

Minimising IT downtime for finance professionals

(30 November 2010)

ITIL V3 – should you bother?

(24 November 2010)

Taking the third option

(25 October 2010)

The peculiarities of Metro Bank’s IT outsourcing model

(19 October 2010)

Saving ITIL – how to protect the reputation of Best Practice frameworks

(11 October 2010)

5 tips for moving Disaster Recovery to the Cloud

(04 October 2010)

Does the future of business mobile computing lie in hybrid tablet devices?

(27 September 2010)

How many police officers does it take to email 10,000 criminal records to a journalist by accident?

(15 September 2010)

The perils of commoditising IT Support

(01 September 2010)

Life after ITIL – creating a culture of Continual Service Improvement

(02 August 2010)

10 reasons to migrate to Exchange 2010

(27 July 2010)

Are you Off-Sure about your IT Service Desk?

(14 July 2010)

Mind the skill gap

(11 July 2010)

Microsoft should fear not – is Apple even in the same league?

(24 June 2010)

Is your IT Service Desk future proof?

(22 June 2010)

The quest for a portable office - are all mobile devices safe for work?

(21 June 2010)

Will Tablets rule the future?

(16 June 2010)

Getting back to work - but with a service provider.

(15 June 2010)

Cloud computing: how to minimise lock-in risks

(09 June 2010)

Public sector, private data - is outsourcing the Service Desk too risky?

(02 June 2010)

Doing more with less: an opportunity to learn

(06 May 2010)

Sharing the IT Service Desk: sharing cost, sharing quality

(03 May 2010)

So, Microsoft outsources IT support – What’s all the fuss about?

(27 April 2010)

Survey reveals 1/3 of UK organisations put off Windows 7 roll-out, but are they wise to wait?

(13 April 2010)

Is information safe enough at NHS trusts?

(31 March 2010)

Best Practice and Virtualisation: essential tools in Business Resilience and Continuity planning

(25 March 2010)

What to look for when bringing offshore work back home

(22 March 2010)

5 thoughts on the IT Service Desk that need re-thinking

(10 March 2010)

Microsoft System Center Service Manager 2010: a credible challenger in the Service Management software market?

(17 February 2010)

Do you really want to lose (inter)face?

(15 February 2010)

A new lease of IT life

(11 February 2010)

From ITIL v2 to v3 – where to start?

(08 February 2010)

Can you afford not to invest in Best Practice?

(02 February 2010)

Experiential Learning explained through Confucius

(02 February 2010)

Quick win, quick fall if you fail to plan ahead

(11 January 2010)

Cloud computing – Help your IT out of the Tetris effect

(08 January 2010)

One of you may be fired

(17 December 2009)

Hot or not. ..Says who?

(15 December 2009)

2012: avoiding the IT Apocalypse

(03 December 2009)

Punishment alone does not work

(03 August 2009)

HSBC Data Loss

(26 July 2009)

ITIL for ITILs sake

(02 June 2009)

VDI and Windows 7

(06 May 2009)

The art of deception

(05 May 2009)

VDI - the revolution begins...

(04 May 2009)

Wake up and tackle the real VDI issues!

(24 March 2009)

ITIL Version 3

(18 February 2009)

Virtualisation - making the headlines

(18 February 2009)

Batten down the Hatches!

(18 February 2009)

Overcome the Freeze

(10 January 2007)

HSBC Data Loss

Posted in Information Security on 26 July 2009 by

Most will know what has befallen HSBC in recent weeks, for those who don't, the bank's seemingly wanton data loss culminated in a £3.2 million fine, along with a well deserved hammering in the press.

Of course, it could have been a lot worse. The fine itself was reduced from £4.5 million by the FSA as HSBC did not contest the ruling and in all honesty, either amount is small change to an organisation of the size of HSBC. In fact, for HSBC a data loss like this is not quite the catastrophe the media might be making it out to be. Talk of their customer base deserting them in droves is unlikely to become a reality and the furore over the loss will probably die down relatively quickly, what with the crumbling economy generating new tales of woe on an almost daily basis. However HSBC are by no means a typical example. Smaller or less financially powerful organisations would, and indeed are, brought to their knees by mistakes of this nature.

So is yet another high-profile case of data loss really going to change anything? Well for HSBC the answer is yes. This is too big an incident for management to ignore and they will have to act, and act decisively. The media spotlight means their actions will have to be more than just token gestures designed to appease their customer base. However for other companies looking in, history shows us lessons will not be learned and this latest loss will not result in a wholesale improvement in security practices across the board.

This latest piece of evidence that a head-in-the-sand approach does not work will in all likelihood join a list including TK Maxx, Nationwide, nine different NHS trusts and Manchester City Council in becoming examples of data loss that just 'happen to someone else'. The frustration for those among us that do recognise the risk is just how easy it would be for organisations to protect themselves.

So what are the first steps? When a big story like this breaks the media historically  wheels out security experts who peddle the latest technological innovation in locking your information down from the threat of attack, but this direction is looking increasingly impotent in the face of the changing nature of the problem. The reality is that the greatest threat to security lies not from an evil outside entity but from within your organisation. Potentially the most costly problem, as HSBC has shown, is a lack of process, knowledge, education and awareness from the top down.

Rather than looking for the next great technical innovation, Information Security should look to the Health and Safety Executive for inspiration. The way in which organisations protect themselves from liability in this area stands as an example of how, with proper process, an obsessive attention to detail bordering on the ridiculous and staff awareness to the point of saturation, Information Security will start to command the importance it deserves within the organisation.

David Cowan,
Head of Infrastructure, Plan-Net plc

Plan-Net Said,
@ 30 Jul 2009 11:21
Hi Steven, In general, implementing good Information Security practice within a company requires a top down approach where Information Security is part of the organisation’s make up and there is clear support for ensuring the security of information at the highest level in the business. To obtain this management commitment, a good staring point would be presenting a business case for improving the existing Information Security Management System which could then lead into either Executive Awareness sessions or an Information Security review to identify the business risks. If you are interested in progressing this further, please contact our Infrastructure and Security team.
Steven Farmer Said,
@ 27 Jul 2009 11:04
That makes sense, unfortunately many organisations don't know where to start. What would your suggestions be?
Post your Comments

(required)

(required, never displayed)