When and why you need to make a Will – Q&A with James Chittenden
Written by James Chittenden Why do I need to make a Will? To ensure control…
MoreThe ICO has fined the outsourcing giant, Interserve Group LTD, £4.4 million after a catastrophic cyber-attack which allowed hackers access to the personal data of 113,000 employees.
A cyber-attack took place in May 2020 when an Interserve employee, who was working from home, received a phishing email which they then forwarded to another employee who opened it and downloaded the contents.
This caused installation of malware on an employee’s workstation which was initially quarantined by Interserve’s anti-virus software. An alert was sent which Interserve failed to fully investigate leaving the malware in the system.
The malware allowed the hackers to uninstall Interserve’s anti-virus software resulting in the compromise of 283 systems and 16 accounts. Hackers gained access to the personal data of 113,000 employees including bank account details, email addresses, NI numbers and sexual orientation. The personal data was encrypted so that Interserve was no longer able to access the data.
The ICO found that Interserve were in breach of the GDPR regulations, which requires a data controller to ensure the security of personal data. In particular, the ICO found that Interserve had:
The ICO issued a notice of intent for a fine of £4.4 million, the fourth largest fine ever imposed by the ICO. Interserve were praised by the ICO for their cooperation with the investigation and their pro-active remediation efforts however, after consideration of these mitigating factors the ICO did not make a reduction to the fine.
What can businesses learn from the findings of the ICO?
John Edwards, UK Information Commissioner, warned that “the biggest cyber-risk businesses face is not from hackers outside of their company but from complacency within their company”.
Businesses should ensure that staff at all levels of the business receive data protection and cyber security training. The National Cyber Security Centre advises that training should be ongoing and backed up with further assurance testing, such as penetration testing.
Business must take a proactive approach to cyber security. Commenting on the fine, the Information Commissioner stated, “if your business doesn’t regularly monitor for suspicious activity in its systems and fails to act on warnings, or doesn’t update software and fails to provide training to staff, you can expect a similar fine from my office.”
The ICO advised that it is not enough to simply create and maintain cyber security policies if these are not continually reviewed, updated and implemented. Carrying out regular and effective risk assessments can reduce the risk of future attacks occurring and can minimise the impact they have on systems.
If you have any questions regarding data protection obligations for your business, or any other issue raised in this article, then please contact Martin Varley (m.varley@hklaw.uk).
Written by James Chittenden Why do I need to make a Will? To ensure control…
MoreWritten by Charlotte Parsons Why do people leave charitable gifts in their Wills? In the…
MoreProbate and avoiding problems with chattels While financial assets can be divided relatively easily when…
More