27 Nov 2009
Verity Trustees has been made to sign a Formal Undertaking by the Information Commissioner's Office (ICO) after the theft of a laptop containing sensitive data on 110,000 individuals.
Mick Gorill, assistant information commissioner at the ICO, described the incident as a "stark reminder of how easily people's details can be put at risk ".
Of the 110,000 individuals affected, the laptop contained the bank details of 18,000 of them, along with names, addresses, dates of birth and National Insurance numbers.
As well as signing the Formal Undertaking to process personal data in accordance with the Data Protection Act, Verity must ensure that portable and mobile devices used to store and transmit personal data are encrypted.
The data was downloaded for training purposes by Northgate Arinso, the supplier of Verity's computerised pensions systems, and then subsequently stolen from one of its locked server rooms. This was in breach of the firm's policy of using only anonymous data samples of 50 to 100 pension scheme members.
Graham Cluley, senior technology consultant at Sophos, said that organisations which handle personal data should put technology in place that not only encrypts sensitive information, but polices the movement of that data.
"There is a danger that the public are losing trust in the ability of organisations to look after personal information, but it's essential that confidence is maintained," he added.
Gorill said that he was encouraged to see that Verity had "taken remedial steps" since the data loss, including the engagement of a fraud protection service provider to protect the affected individuals.
"I am satisfied that the Trustees will now take appropriate steps to ensure that individuals' details are protected," he said.
Cluley also said it was good that Verity is engaging with a fraud protection service, which "may offer some comfort to concerned customers who may have been affected".
However, the security expert questioned whether other companies will learn from this incident, and put "proper defences in place to ensure that data accidents like this do not happen again".
Latest stories from Management
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
IT Security Specialist Move in2 Solutions /Pre-Sales...
SOFTWARE ENGINEER - BERKS - to £34k plus package WAREHOUSE...
We currently have a position for a Senior Project Manager...
JAVA DEVELOPER TRANSPORT MANAGEMENT SYSTEMS / TMS...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
A Masterclass in how to make news out of nothing.
'...slaps Verity Trustess'? The undertaking is actually a VERY short list of points to consider and improve on. The ICO equivalent of "Move along please, nothing to see here" Hence the need to heavily pad the article with generalisms from an IT security firm that everyone has heard of to make it sound like there is still a story. Why not pop along to www.theregister.co.uk for some real news.
Posted by: Ghost 01 Dec 2009