27 Nov 2009
Verity Trustees has been made to sign a Formal Undertaking by the Information Commissioner's Office (ICO) after the theft of a laptop containing sensitive data on 110,000 individuals.
Mick Gorill, assistant information commissioner at the ICO, described the incident as a "stark reminder of how easily people's details can be put at risk ".
Of the 110,000 individuals affected, the laptop contained the bank details of 18,000 of them, along with names, addresses, dates of birth and National Insurance numbers.
As well as signing the Formal Undertaking to process personal data in accordance with the Data Protection Act, Verity must ensure that portable and mobile devices used to store and transmit personal data are encrypted.
The data was downloaded for training purposes by Northgate Arinso, the supplier of Verity's computerised pensions systems, and then subsequently stolen from one of its locked server rooms. This was in breach of the firm's policy of using only anonymous data samples of 50 to 100 pension scheme members.
Graham Cluley, senior technology consultant at Sophos, said that organisations which handle personal data should put technology in place that not only encrypts sensitive information, but polices the movement of that data.
"There is a danger that the public are losing trust in the ability of organisations to look after personal information, but it's essential that confidence is maintained," he added.
Gorill said that he was encouraged to see that Verity had "taken remedial steps" since the data loss, including the engagement of a fraud protection service provider to protect the affected individuals.
"I am satisfied that the Trustees will now take appropriate steps to ensure that individuals' details are protected," he said.
Cluley also said it was good that Verity is engaging with a fraud protection service, which "may offer some comfort to concerned customers who may have been affected".
However, the security expert questioned whether other companies will learn from this incident, and put "proper defences in place to ensure that data accidents like this do not happen again".
Latest stories from Management
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Oracle E-Business Analyst / Functional Consultant - Supply...
SAP consultant Production: SAP MM, IM, PP, APO, Brussels...
Full time DBA with 5-10 years experience will be preffered...
Software Development Manager - Scottish Borders Agile...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
A Masterclass in how to make news out of nothing.
'...slaps Verity Trustess'? The undertaking is actually a VERY short list of points to consider and improve on. The ICO equivalent of "Move along please, nothing to see here" Hence the need to heavily pad the article with generalisms from an IT security firm that everyone has heard of to make it sound like there is still a story. Why not pop along to www.theregister.co.uk for some real news.
Posted by: Ghost 01 Dec 2009