Archive for the ‘Data Breaches’ Category

Quick, cost-effective DPA compliance

February 22nd, 2012 by

There is a standard approach towards achieving DPA compliance:

  • Understand what the DPA is how it affects your business
  • Identify your current level of conformance to the DPA
  • Identify gaps and steps to achieve compliance
  • Document your DPA policies
  • Understand how to react if you suffered a data breach
  • Initiate DPA staff training.

Our Complete Data Protection Toolkit contains everything you need to use this recommended approach.

Complete Data Protection Toolkit Complete Data Protection Toolkit
For quick, cost-effective DPA compliance!

Price: £156
Buy during February and get a free ICT Strategy Toolkit!

Learn more

Buy Now

     

Ensure you organisation avoids fines and brand damage and become DPA Compliant today!

Buy this toolkit before the end of February and get a free ICT Strategy Toolkit!

Would you know if you were hacked?

February 17th, 2012 by

A report by Trustwave has  revealed some startling statistics around data breaches; the most frightening one being that most organisations don’t even know they’ve been hacked.

  • Only 16% of organisations that suffered a data breach last year were able to detect it themselves. This means that 84% only found out they had been hacked when they were told by an external party, such as a regulatory body, law enforcement or by the public
  • Those that were notified by an external party waited an average of 173.5 days before they were told
  • The most popular password for organisations to use is ‘Password1′
  • 89% of organisations were hacked last year because of the value of their customer records 
  • The food and beverage industry is the top target for hackers
  • 8.00 am and 9.00am (Eastern Time, U.S) is the most likely time for an email to be sent with a malicious attachment.

Source: Trustwave

Does any of this ring a bell for you? Do you use ‘Password1′ or a similar phrase? Are you plagued by malicious emails? And most importantly, would you know if you were hacked?

The Complete Data Protection Toolkit will provide you with everything you need to help you comply with the Data Protection Act (DPA), ensuring you become compliant quickly and cost-effectively. This toolkit will help you beat hackers and protect your business from suffering a data breach.

Find out more about the Complete Data Protection Toolkit here >>

 

 

 

Complete DPA and PCI training: Book together and save £200!

February 14th, 2012 by

We are now offering you the chance to book the DPA Foundation Course and the PCI Foundation Course together, saving you £200!

The DPA and PCI Foundation Combination Course offers you the chance to tackle both compliance issues at a reduced price. Both courses (which take place in March 2012) cover the compliance basics and are ideal for those either new to the subject or those that want a refresher course in handling data.

Complete DPA and PCI training: Book together and save £200! >>

DPA and PCI Foundation Combination Course - in London DPA and PCI Foundation Combination Course – in London

RRP: £935.00
Price: £735.00
You Save: £200.00

Learn more

Buy Now

     

Complete DPA and PCI training: Book together and save £200! >>

The DPA Foundation Course and PCI Foundation Course are also sold separately on our website.

Tackle DPA and PCI Compliance once and for all

February 9th, 2012 by

 

In the UK all organisations must comply with the Data Protection Act and every organisation that stores, transmits or processes card holder data must comply with the Payment Card Industry Data Security Standard (PCI DSS), which is enforced by the ‘acquiring bank’ through whom you have your merchant account.

Next month we are holding our best-selling DPA and PCI Foundation Courses to allow organisations, such as yours, to tackle these important compliance issues once and for all. On these courses you will learn everything you need to deal effectively with DPA and/or PCI. Book both together on our Combination Course and save £200!

Book now to save disappointment.

DPA and PCI Foundation Combination Course - in London DPA and PCI Foundation Combination Course – in London

RRP: £935.00
Price: £735.00
You Save: £200.00

Learn more

Buy Now

     

Delivered by expert trainers, this Combination Course is the most cost-effective route to DPA and PCI compliance, enabling you to tackle it once and for all.

Tackle both compliance challenges together, once and for all, on the DPA and PCI Foundation Combination Course >>

Please note: The DPA Foundation Course and PCI Foundation Course are also sold separately.

Latest DPA breach highlights the need for physical and cyber data protection

February 7th, 2012 by

The Information Commissioner’s Office (ICO) announced on Friday that E*Trade, a global financial services company, breached the Data Protection (DPA) Act by losing over 600 customer personals details.

The company discovered files of 608 customers had been lost when asked to retrieve them from a storage facility in which E*Trade were keeping them. Head of enforcement Steve Eckersley commented:
This breach was caused by the company failing to have the necessary security measures in place to keep their clients information secure.

This incident highlights the fact that data protection needs to encompass physical and electronic storage and handling, and that DPA breaches are often the result of human errors.

All organisations need to ensure the protection of their customers and clients data in both the physical and cyber worlds. The only way to do this is by complying with the DPA.

Complete Data Protection Toolkit Complete Data Protection Toolkit


Price: £156

Learn more

Buy Now

  Buy the BS25999 toolkit today and receive the ICT strategy toolkit free >>>  

This complete toolkit provides all the tools and resources you need to carry out your own DPA project and become compliant quickly and cost-effectively.

Until the end of February this toolkit comes with a free ICT strategy toolkit. The ICT toolkit will help you address all of your ICT requirements for the year ahead, and what better time to do this than now, as business budgets are being allocated for the year.

The DPA Toolkit is a proven route to do-it-yourself compliance >>>

Midlothian Council Fined £140,000 for 5 DPA Breaches

January 31st, 2012 by

Yesterday the Information Commissioner announced that he had fined Midlothian Council £140,000 for disclosing sensitive personal information to the wrong recipient on 5 separate occasions. All 5 breaches involved children’s social service reports and occurred between January and June 2011.

 Ken MacDonald, Assistant Commissioner for Scotland commented:

 “The serious upset that these breaches would have caused to the children’s families is obvious and it is extremely concerning that this happened five times in as many months. I hope this penalty acts as a reminder to all organisations across Scotland and the rest of the UK to ensure that the personal information they handle is kept secure.”

The ICO’s investigation found that all five breaches could have been avoided if the council had put adequate data protection policies, training and checks in place.

The ICO has ordered the council to review and update its data protection policy and ensure council staff and those who work with the council are adequately trained in their DPA responsibilities.

The ICO is gaining support for its request to conduct audits of local councils and NHS bodies without request.  There have been numerous public sector bodies caught in breach of the DPA over the last two years, however the actual number who are not meeting data protection compliance levels is thought to be much, much higher.

The cost-effective way to tackle this issue is to ensure you are DPA compliant now. DPA training and compliance is not expensive, especially compared to the potential huge fines that can be levied on an organisation who are found to have breached the DPA.

DPA Foundation Training – Essential for those responsible for personal and sensitive data within an organisation.

SafeXs Sticks – Essential for protecting sensitive data within an organisation. Hardware encrypted and almost bombproof, the SafeXs stick also comes as an enterprise package.


DPA Staff eLearning
– A Cost effective way of delivering essential training to staff.

DPA Toolkit – Essential time saving documentation toolkit to help you create the documents you need to ensure DPA compliance.

You can read more about the Data Protection Act here >>>

29.2% of data breaches could be avoided just by insisting on encrypted USB sticks.

January 31st, 2012 by

Keep a step ahead, and stay out of trouble – deploy easy-to-use encrypted USB sticks today!

Introducing SafeXs – The Next Generation Safestick

SafeXs is a fully hardware encrypted USB flash drive, fully managable by SafeConsole.

Approved to FIPS 197/FIPS140-2 and CESG Government standards, all portable data is 100% safe if the drive is lost. There are NO backdoors.

For management, SafeConsole enforces full, granular control, policy enforcement and auditing over an organisation’s SafeXs devices, and enables a host of productivity and management features.

For a limited time only, we are offering SafeConsole Lite free with a purchase of 25 sticks or more

SafeXs FIPS 197 USB Stick Silver Package SafeXs FIPS 197 USB Stick Silver Package
Get SafeConsole Lite Free!

Learn more

Buy Now

 

Various capacity options available:
FIPS 197 from just £48 and FIPS 140-2 from just £76.50

     

SafeConsole key features include:

  • Remotely KILL lost or stolen sticks
  • Full audit of all SafeXs use
  • Centrally backup / restore of user data
  • Reset forgotten user passwords via challenge / response
  • Push files and applications from a Central location to SafeXs
  • Full protection from malware such as Conficker
  • Create trusted zones of users
  • Restrict files from being transferred in and out of the network
  • Write protect the drives so they can only be read outside of the company network
  • …plus much, much more.

Over 1 million SafeXs USB sticks are now in use in the NHS helping to keep patient data and other confidential data secure!

Buy your SafeXs today!

O2 suffers data leak – but do they care?

January 26th, 2012 by

Mobile giant 02 have suffered a couple of embarrassing gaffs this week. Firstly it was revealed that they had been inadvertently been passing their customers phone numbers on to any site that they visited when using O2’s 3G network on smartphones. With almost half of O2’s customers using smartphones, the data leakage could possibly have affected up to 15 million people.

O2 blamed a ‘technical’ glitch and has since stated the problem has been resolved and apologised to its customers. However a leading consultant at Sophos, Graham Cluley, commented that such issues had “been known about for almost two years at least”.

The Guardian reported yesterday that O2 also ‘regularly hands over subscribers’ phone numbers to sites that offer age-restricted material and premium-rate billing, whether the users realise it or not.’

What?! I hear you cry. The Information Commissioners Office’s is considering investigating the incident however it seems unlikely that that any action will be taken as a mobile phone number, in the eyes of the ICO, on its own, is not considered as a ‘personally identifying information’.

Even though, with your number being passed onto potentially anyone under the sun, you could be the subject of phishing attacks, reverse charge texts and unsolicited marketing.

These incidents further highlight what companies do with our data when we’re surfing the internet; and how little we actually know as consumers. And what can you do as a consumer? Where is the avenue for reproach? We’ll all be politely told that the issue was a ‘technical problem’ and has now been resolved. But when did we sign up for this in the first place? I mean if, when you bought your latest phone, there were questions like: “Would you like us to share your information with every single website you visited?” Or, “Would you like us to pass your details on to sex chat services?” You would tick yes to these?!

Often terms and conditions are deliberately confusing, long winded and impenetrable for consumers; allowing the service provider you’re signing with the legal ambiguity to do with your information as they wish. But in the instances referenced in this article, this wasn’t the case. One was an error and the other – passing customer details onto premium and age-restricted sites – well, no one seems to know. O2 have thus far refused to comment. Are they allowed to do this?

One thing is for sure. Such instances cause huge brand damage and loss of custom. Retaining customer loyalty and brand image is of huge importance to all businesses and organisations. I dare say that if an SME suffered an instance like this that they would have a far more difficult time of it. Protection of customer data is important. The data protection act says so.

But I often wonder, when the brand is so big and they have so much money, as in the instance of Playstation last year, and now someone like O2, are they beyond the pale?

You can read more about data protection and the Data Protection Act here >>>

Charity loses memory stick containing unencrypted patient data

January 23rd, 2012 by

Praxis Care charity  lost a memory stick in August 2011,  containing  confidential data of 160 different people. The data that was held on the unencrypted stick contained personal information such as their mental health and care records.

Since losing the memory stick and coming under the wrath of the ICO for suffering the data breach, Praxis Care is now committed to improving its data protection standards.

Christopher Graham, the information commissioner, said: “Carrying people’s personal information around on an unencrypted memory stick is clearly unacceptable.”

To avoid a situation like the above, companies need to use a secure USB sitck with hardware encryption.

SafeXs is a secure USB stick with AES 256 bit hardware encryption and is FIPS 197-certified. Over 1 million of these sticks are now in use by the NHS, helping to keep patient data and other confidential data secure.

Simply plug in a SafeXs and within minutes you can be up and running. All you need do is set a password and any data placed on the SafeXs is encrypted.

Read more about the popular encrypted USB stick >>

Bring Data Protection to Life

January 16th, 2012 by

“Excellent tutor, great facilities & lovely environment. Made complex subject easy to understand. The best Data Protection course there is!”
Jonathan Pillinger, Senior Associate, Corporate Compliance, Postcomm

With engaging tutors and interesting content, our DPA Foundation Course will bring data protection to life.

This interactive and enjoyable one-day course gives both new and experienced staff and management – those involved with or responsible for personal data – an oversight of what the Data Protection Act means to their business and also to their own rights as an individual.

Here’s what some of our delegates thought about the course:

“Brought data protection act to life’ – engaging tutor”
Louise Gilbert, Project Manager, John Lewis Partnership

“Excellent enjoyable day, made subject very interesting.”
Emma Willoughby, HR Director, The Myton Hospices

DPA Foundation Course - in London DPA Foundation Course – in London

Price: £440.00

Learn more

Buy Now

     

Book on this course today >>

Course delegates will go back to their companies with up-to-date knowledge of the current legal compliance position around personal data, including

  • The 8 Principles of the DPA;
  • Powers of the Information Commissioner;
  • Individuals’ legal rights;
  • The new DPA enforcement regime;
  • Options available for ensuring compliance.

Book on this course today >>

More to explore:

PCI Foundation Training Course
PCI Foundation Training Course

Learn more

Buy Now

ISO27001 Certified ISMS Foundation Training
ISO27001 Certified ISMS Foundation Training

Learn more

Buy Now

Digital Forensics Foundation Training
Digital Forensics Foundation Training

Learn more

Buy Now