prison
R E L A T E D   C O N T E N T
ADVERTISEMENT

Board should be liable for breaches, say security profesionals

Websense survey finds IT is not to blame

Rosalie Marshall, IT Week 08 Apr 2008
ADVERTISEMENT

Chief executives of firms that expose customers' confidential data should be put under arrest and jailed, according to a survey conducted by web security firm Websense.

The survey of over one hundred global security professionals was conducted at the annual e-Crime Congress in London.

Over a quarter of respondents said that a jail sentence is the appropriate punishment for a serious data breach, while only three per cent said they did not believe any legally enforced punishment was necessary.

In the 2007 survey, only 74 per cent of the security professionals believed the Board should be responsible for data breaches, but this year the figure increased to 95 per cent. However, less respondents blame IT - only 5 per cent said the IT department should be responsible for breaches, in comparison to last year’s 21 per cent.

This change of opinion could stem from the large number of data breaches that have occurred since last November’s HM revenue and customs loss of 25 million data records which were stored on two discs.

Carrie Hartnell, transformational business programme manager at trade body Intellect, agreed that losses are the outcome of human error rather than because of a failure in technology.

Hartnell argued for a shift in societal and cultural attitudes in how people treat personal data.

“Intellect believes that organisations and government departments should have a co-ordinated approach to data security that recognises the need to educate and train its staff around the handling and use of personal data as well as the appropriate technical security measures,” she added. “They need to ensure that their employees know when they are accessing confidential data and that they understand the policies and procedures for protecting it."

See also:

vaultDetails of over 350,000 customers go missing in the post  07 Apr 2008
Security based on people and process - not technology  03 Apr 2008
vaultProtect Crypto to be bundled with the firm's Protect Premium client  31 Mar 2008
houses of parliamentJoint Committee on Human Rights criticises "lax standards"  14 Mar 2008

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
London, United Kingdom | MI5
Business Intelligence Specialists - Competitive Salary + Excellent Benefits - London   Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
Milton Keynes, Buckinghamshire, United Kingdom | EDS
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >
United Kingdom | Sussex HIS via Acertus Ltd
Business Development and Partnership Director - £62,337 to £77,179 plus benefits Any Sussex HIS location by agreement  The Sussex HIS was formed in mid 2004 through the merging of all IT services from all Trusts ... more >
More job opportunities