<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; UK</title>
	<atom:link href="http://www.endpoint-security.info/tag/uk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Thu, 02 Feb 2012 10:58:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>British authorities experienced 1,035 data loss incidents</title>
		<link>http://www.endpoint-security.info/2011/11/24/british-authorities-experienced-1035-data-loss-incidents/</link>
		<comments>http://www.endpoint-security.info/2011/11/24/british-authorities-experienced-1035-data-loss-incidents/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 09:05:24 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[authorities]]></category>
		<category><![CDATA[BIg Brother Watch]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[local council]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=809</guid>
		<description><![CDATA[Only 55 of the data loss breaches have actually been reported If you can&#8217;t stop data breaches, at least cover them up! This seems to be the data security code British authorities go by. Too bad for them there is something called Freedom of Information Act requests&#8230; A new report issued by privacy campaign group [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F24%2Fbritish-authorities-experienced-1035-data-loss-incidents%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F24%2Fbritish-authorities-experienced-1035-data-loss-incidents%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><em><strong>Only 55 of the data loss breaches have actually been reported</strong></em></p>
<p>If you can&#8217;t stop data breaches, at least cover them up! This seems to be the data security code British authorities go by. Too bad for them there is something called Freedom of Information Act requests&#8230; A new report issued by privacy campaign group Big Brother Watch showed that councils across the UK experienced over a thousand data loss cases over a three year period &#8211; August 2008 to August 2011.</p>
<p>To get the information, the group sent 433 FOIs to local authorities and councils across the Great Britain and showed s shocking discrepancy between the reported 50 something incidents and the harsh reality. Not only did BBW uncover the data mishandling cases, they also requested information on what happened to the employees of said councils &#8211; if they had been disciplined, fired or prosecuted over the data breaches -, and inquired about the council&#8217;s response to each incident. <span id="more-809"></span></p>
<p>According to the 395 replies received,</p>
<blockquote><p>&#8220;We have uncovered more than 1,000 incidents across 132 local authorities, including at least 35 councils who have lost information about children and those in care,&#8221; said BBW in a <a href="http://www.bigbrotherwatch.org.uk/home/2011/11/local-authority-data-loss-exposed.html#.Tsy-109jUjw" target="_blank">statement</a> accompanying its <a href="http://bigbrotherwatch.org.uk/la-data-loss.pdf" target="_blank">report (PDF)</a>. &#8221;Highly confidential information has been treated without the proper care and respect it deserves. At least 244 laptops and portable computers were lost, while a minimum of 98 memory sticks and more than 93 mobile devices went missing.&#8221;</p></blockquote>
<p>Only 55 of the incidents were subsequently reported to the Information Commissioner&#8217;s Office, which handles data loss complaints. In only 9 cases, those involved in the data breach were fired.</p>
<blockquote><p>“I welcome this research by Big Brother Watch,&#8221; <a href="http://www.theregister.co.uk/2011/11/23/big_brother_watch_report/" target="_blank">local government minister Grant Shapps told the data protection advocates</a>. &#8221;This reinforces the need for steps to protect the privacy of law-abiding local residents. Civil liberties are under threat from the abuse of town hall surveillance powers, municipal nosy parkers rummaging through household bins and town hall officials losing sensitive personal data on children in care.”</p></blockquote>
<p>For a list of some of the most important data incidents included in the report, read the <a href="http://www.theregister.co.uk/2011/11/23/big_brother_watch_report/" target="_blank">story published by the Register</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/" rel="bookmark" class="crp_title">More data breaches caused by improper use of flash drives and laptops</a></li><li><a href="http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/" rel="bookmark" class="crp_title">US 2008 data breach growth blamed on insiders</a></li><li><a href="http://www.endpoint-security.info/2011/08/16/june-the-month-with-the-most-data-breaches-of-2011-so-far/" rel="bookmark" class="crp_title">June, the month with the most data breaches of 2011 so far</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/24/british-authorities-experienced-1035-data-loss-incidents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK fraud on the rise, losses amount to billions</title>
		<link>http://www.endpoint-security.info/2011/01/29/uk-fraud-on-the-rise-losses-amount-to-billions/</link>
		<comments>http://www.endpoint-security.info/2011/01/29/uk-fraud-on-the-rise-losses-amount-to-billions/#comments</comments>
		<pubDate>Sat, 29 Jan 2011 09:29:25 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[loss]]></category>
		<category><![CDATA[statistics]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=596</guid>
		<description><![CDATA[The latest annual statistics from the UK&#8217;s National Fraud Authority show that more than £38bn have been lost over the last 12 months due to fraud. This amounts to an increase of more than 25%.The public sector (£21.2bn) reported the biggest part of the loss, while the private sector cost the government only £12bn, with [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F01%2F29%2Fuk-fraud-on-the-rise-losses-amount-to-billions%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F01%2F29%2Fuk-fraud-on-the-rise-losses-amount-to-billions%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The latest<a href="http://www.attorneygeneral.gov.uk/nfa/WhatAreWeSaying/NewsRelease/Pages/fraud-costs-the-UK-over-38billion.aspx"> annual statistics</a> from the UK&#8217;s National Fraud Authority show that more than £38bn have been lost over the last 12 months due to fraud. This amounts to an increase of more than 25%.The public sector (£21.2bn) reported the biggest part of the loss, while the private sector cost the government only £12bn, with another £4bn in losses from fraud against individuals.</p>
<p>According to the NFA the increase was to be expected, at least in part, due to improved reporting procedures. The figures include estimates for procurement (£2.4bn) and grant fraud (£515m) for the first time.<span id="more-596"></span></p>
<p>In the financial services industry £3.6bn in fraudulent losses have been recorded last year. The highest figure in the private sector was £3.8bn and represented a slight decrease from 2009. Losses attributed to plastic card (£440m) and cheque fraud (£30m) have also increased by up to 14%, reaching £60m. Insurance fraud (£2.1bn) and mortgage fraud (£1bn) both remain high.</p>
<p><a href="http://www.theregister.co.uk/2011/01/28/uk_fraud_losses_soar/" target="_blank">According to Gavin Cunningham</a>, director in the specialist forensic fraud investigation firm, BTG Global Risk Partners, fraudulent losses are only likely to rise in the future.</p>
<blockquote><p>&#8220;These figures make grim reading for both private and public sector business leaders alike and reflect the significant financial impact of fraud in the UK,&#8221; Cunningham said. &#8220;With the UK still struggling to recover from the recession and some uncertainty as to what the future may hold, there is unlikely to be a reduction in fraud in the short term; historically, there is evidence that fraud increases as a recession ends, in part because businesses uncover fraudulent actions as the effects start to build up and in part because there is more scrutiny of hidden and unknown costs in tougher times.&#8221;</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/10/us-fraud-decrease-in-2010/" rel="bookmark" class="crp_title">Fraud has decreased in 2010 &#8211; crime does not pay anymore?</a></li><li><a href="http://www.endpoint-security.info/2008/06/30/uk-smes-warned-to-improve-security/" rel="bookmark" class="crp_title">UK SMEs Warned To Improve Security</a></li><li><a href="http://www.endpoint-security.info/2008/05/29/identity-fraud-on-the-rise-in-the-uk/" rel="bookmark" class="crp_title">Identity Fraud on the Rise in the UK</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li><li><a href="http://www.endpoint-security.info/2008/06/24/anti-fraud-collaborative-service-launches-in-the-us/" rel="bookmark" class="crp_title">Anti-Fraud Collaborative Service Launches in the US</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/01/29/uk-fraud-on-the-rise-losses-amount-to-billions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cyber gangs are taking over &#8211; street gangs will become obsolete</title>
		<link>http://www.endpoint-security.info/2010/10/07/cyber-gangs-are-taking-over-street-gangs-will-become-obsolete/</link>
		<comments>http://www.endpoint-security.info/2010/10/07/cyber-gangs-are-taking-over-street-gangs-will-become-obsolete/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 08:24:57 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber crime fighting]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=530</guid>
		<description><![CDATA[Cyber gangs appear to be one step ahead of e-crime experts. UK Metropolitan police commissioner Sir Paul Stephenson, has stated that he believes police officers trained to fight against the growing number of cyber criminals are as vital as uniformed officers in the streets. In a letter to “The Sunday Telegraph” he outlines his beliefs [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F10%2F07%2Fcyber-gangs-are-taking-over-street-gangs-will-become-obsolete%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F10%2F07%2Fcyber-gangs-are-taking-over-street-gangs-will-become-obsolete%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><em><a href="http://www.endpoint-security.info/wp-content/uploads/2010/10/bad_guy_gang.jpg"><img style="float: left; margin-right: 10px;" title="bad_guy_gang" src="http://www.endpoint-security.info/wp-content/uploads/2010/10/bad_guy_gang.jpg" alt="" width="151" height="151" /></a>Cyber gangs appear to be one step  ahead of e-crime experts. </em></p>
<p>UK Metropolitan police commissioner Sir Paul Stephenson, has stated that he believes <a href="http://www.v3.co.uk/v3/news/2270905/met-chief-underlines-importance" target="_blank">police officers trained to fight against  the growing number of cyber criminals are as vital as uniformed officers in the streets</a>. In a letter to “The Sunday Telegraph” he outlines his beliefs that cutting back -office staff in favor of more street officers is wrong.</p>
<blockquote><p>
&#8220;Online fraud generated £52bn worldwide in 2007 – a staggering sum. There is a significant fight back by the financial institutions, working with police. In the Met, we play our part in a &#8216;Virtual Task Force&#8217;,&#8221; he said.<span id="more-530"></span></p></blockquote>
<p>He has also stated that leaving cyber crime to other institutions like banks and retailers is a mistake and that uniforms should not be put before specialists. More uniforms then specialists is not a good way to serve the general public in his opinion.</p>
<p>Sir Stephenson has also explained that cyber crime dedicated law agencies should exist as we face the growth of this crime form. These agencies should work along side the financial institutions that strive to combat this trend.</p>
<blockquote><p>&#8220;It is a ground-breaking venture and would be less effective without the involvement of experienced detectives. The Task Force is working to predict, prevent and respond to cyber threats.&#8221;</p></blockquote>
<p>A few figures stated by Sir Stephenson show that for every £1 that it costs, The Virtual Task Force saves £21, although this is not enough and the task force is still loosing the battle.</p>
<blockquote><p>&#8220;We know that, at any time, the police service is only actively targeting 11 per cent of the 6,000 organised crime groups in England and Wales.&#8221; &#8211; this is another fact stated by Sir Stephenson</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/16/uk-government-gets-tough-on-cyber-crime/" rel="bookmark" class="crp_title">UK government gets tough on cyber crime</a></li><li><a href="http://www.endpoint-security.info/2010/10/06/cyber-criminals-change-targets-small-fish-are-easier-to-catch/" rel="bookmark" class="crp_title">Cyber criminals change targets &#8211; small fish are easier to catch?</a></li><li><a href="http://www.endpoint-security.info/2008/04/09/gains-from-online-fraud-aim-for-the-sky/" rel="bookmark" class="crp_title">Gains from Online Fraud Aim for the Sky</a></li><li><a href="http://www.endpoint-security.info/2010/10/01/stuxnet-and-cyber-warfare/" rel="bookmark" class="crp_title">Stuxnet and cyber warfare &#8211; the future is now</a></li><li><a href="http://www.endpoint-security.info/2010/06/22/cyber-attacks-warfare-without-a-smoking-gun/" rel="bookmark" class="crp_title">Cyber attacks: Warfare without a Smoking Gun</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2010/10/07/cyber-gangs-are-taking-over-street-gangs-will-become-obsolete/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stuxnet and cyber warfare &#8211; the future is now</title>
		<link>http://www.endpoint-security.info/2010/10/01/stuxnet-and-cyber-warfare/</link>
		<comments>http://www.endpoint-security.info/2010/10/01/stuxnet-and-cyber-warfare/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 19:38:38 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Malware Infections]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[Israle]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[US]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=525</guid>
		<description><![CDATA[Back in 2008, assuming that the human factor would eventually fail at some point and people would make the mistake of plugging an unsecured memory stick into a military laptop, several memory sticks were scattered in a US military base in the Middle East that was providing support for the Iraq war. All these memory [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F10%2F01%2Fstuxnet-and-cyber-warfare%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F10%2F01%2Fstuxnet-and-cyber-warfare%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Back in 2008, assuming that the human factor would eventually fail at some point and people would make the mistake of plugging an unsecured memory stick into a military laptop, <a href="http://www.guardian.co.uk/technology/2010/sep/30/stuxnet-worm-new-era-global-cyberwar" target="_blank">several memory sticks were scattered in a US military base in the Middle East</a> that was providing support for the Iraq war. All these memory sticks were deliberately infected with a computer worm.</p>
<p>It resulted in the self-propagation of a computer worm into the computer system of Centcom &#8211; the central command of the US military. The eradication process took 14 months. Apparently this attack, a<a href="http://www.endpoint-security.info/2010/08/26/pentagon-confirms-us-military-breach/" target="_blank">cknowledged by the Pentagon only in august 2010</a>, was very similar to a Stuxnet worm attack which was used in attempts against Iraq’s nuclear facilities and Iran’s nuclear programme.<span id="more-525"></span></p>
<p>The attacks appear to have been highly funded, this bringing forth the possibility of being orchestrated by another country. The Stuxnet worm has infected 30,000 of Iran’s computers and was apparently delivered by intelligence operatives. This tactic appears to be an almost duplicate of the cyber attack against Centcom.</p>
<p>After these attacks, the US gas attempted an exercise called “Cyber Storm III”, an exercise that had as main purpose the countering an all-out cyber war. The exercise that involved government agencies and 60 private organisations in various sectors such as banking, chemical, nuclear enery, IT took place on Thuesday. The results have yet to be disclosed.</p>
<p>James Lewis of the Centre for Strategic and International Studies in Washington stated:</p>
<blockquote><p>&#8220;Cyber war is already here.We are in the same place as we were after the invention of the aeroplane. It was inevitable someone would work out how to use planes to drop bombs. Militaries will now have a cyber-war capability in their arsenals. There are five already that have that capacity, including Russia and China.&#8221;</p></blockquote>
<p>He added  the he believes only 3 countries  have the drive and means capable of launching the Stuxnet attack on Iran: the US, Israel and the UK.</p>
<p>Lewis also believes that a deliberate hacking of an electric generator at the Idaho National Laboratory has previously proven that infrastructure can be persuaded to destroy itself.</p>
<blockquote><p>&#8220;There is growing concern that there has already been hostile reconnaissance of the US electricity grid,&#8221; he said.</p></blockquote>
<p>Due to the fact that Israel has a specialised cyber war unit, called “unit 8200”, some analysts have been led to believe that the Stuxnet attack against Iran was orchestrated by this country.</p>
<p>The fact that a file called Myrthus, a reference to the book of Esther and Jewish pre-emption is present in the worm’s structure can be a proof but also a red-hering.</p>
<blockquote><p>“Reality has quickly caught up” says Dave Clemente, a researcher into conflict and technology at he International Security Programme at Chatham House in London. &#8221;You look at the Stuxnet worm. It is of such complexity it could only be a state behind it,&#8221; Clemente said.</p></blockquote>
<p>He also points out that the US and UK are putting large ammounts of resources ino cyber warfare defense. According to his statements, a centre for cyber security operations in GCGQ and a new office of cyber security in the  Cabinet Office have taken form.</p>
<p>A few steps <a href="http://www.endpoint-security.info/2010/09/28/conficker-stuxnet-cososys-advisory/" target="_blank">against Stuxnet infections can be found here</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/01/03/new-variations-of-the-stuxnet-worm-expected-to-emerge-in-2011/" rel="bookmark" class="crp_title">New variations of the Stuxnet worm expected to emerge in 2011</a></li><li><a href="http://www.endpoint-security.info/2010/09/20/stuxnet-worm-threatening-scada-systems-and-other-industrial-environments/" rel="bookmark" class="crp_title">Stuxnet Worm: New threat targets Scada Systems and other industrial environments</a></li><li><a href="http://www.endpoint-security.info/2010/11/18/new-concerning-clues-in-the-stuxnet-case/" rel="bookmark" class="crp_title">New concerning clues in the &#8220;Stuxnet&#8221; case</a></li><li><a href="http://www.endpoint-security.info/2010/09/28/conficker-stuxnet-cososys-advisory/" rel="bookmark" class="crp_title">How to Stop Conficker/Stuxnet in four easy steps &#8211; Advisory by CoSoSys</a></li><li><a href="http://www.endpoint-security.info/2010/06/22/cyber-attacks-warfare-without-a-smoking-gun/" rel="bookmark" class="crp_title">Cyber attacks: Warfare without a Smoking Gun</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2010/10/01/stuxnet-and-cyber-warfare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK: Information Commissioner&#8217;s Office reports that the NHS has disclosed 305 security losses, as the amount of breaches tops 1,000</title>
		<link>http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/</link>
		<comments>http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/#comments</comments>
		<pubDate>Sat, 29 May 2010 09:40:14 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[security breaches]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=439</guid>
		<description><![CDATA[Over more than 1000 data losses for the NHS. This is a new record. Of which alone 307 were as a result of stolen data or hardware and 233 due to lost data or hardware. The Information Commissioner&#8217;s Office has warned organisations that they need to minimise the risk of mistakes, as the amount of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F05%2F29%2Fuk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F05%2F29%2Fuk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<blockquote><p>Over more than 1000 data losses for the NHS. This is a new record.<br />
Of which alone 307 were as a result of stolen data or hardware and 233 due to lost data or hardware.</p></blockquote>
<p>The Information Commissioner&#8217;s Office has warned organisations that they need to minimise the risk of mistakes, as the amount of losses reported tops 1,000.</p>
<p>The ICO claimed that staff need simple procedures on how to handle personal information with appropriate training to ensure the importance of securing it is fully understood. It also said that it is essential that the protection of people&#8217;s personal information is part of organisations&#8217; culture and DNA.</p>
<p>An ICO report revealed that 254 breaches were as a result of information being disclosed in error, 307 were as a result of stolen data or hardware and 233 due to lost data or hardware.</p>
<p>A further 83 were due to a technical or procedural failure and 59 were lost in transit. A breakdown of companies revealed 305 incidents were recorded by the NHS, 288 in the private sector and 132 by local government. Only 81 incidents were the result of central government.</p>
<p>David Smith, deputy commissioner at the ICO, said: “We all know that mistakes can happen but, the fact is that human error is behind a high proportion of security breaches that have been reported to us. Extra vigilance is required so that people&#8217;s personal information does not end up in the wrong hands.</p>
<p>“Organisations should have clear security and disclosure procedures that staff can understand, properly implement these and ensure that they are being followed by staff. Staff must be adequately trained not just in the value of personal information, but in how to protect it.</p>
<p>“We are keen to work with organisations to prevent breaches happening in the first place and to help ensure that things are put right when they do go wrong.”</p>
<p>Source and full article: <a href="http://www.scmagazineuk.com/ico-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/article/171205/">SC Magazine</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2008/02/25/uk-companies-pay-47-for-every-private-record-lost/" rel="bookmark" class="crp_title">UK Companies Pay £47 for Every Lost Private Record</a></li><li><a href="http://www.endpoint-security.info/2011/01/29/uk-fraud-on-the-rise-losses-amount-to-billions/" rel="bookmark" class="crp_title">UK fraud on the rise, losses amount to billions</a></li><li><a href="http://www.endpoint-security.info/2011/03/22/data-breach-costs-blamed-on-system-failures/" rel="bookmark" class="crp_title">Data breach costs blamed on system failures</a></li><li><a href="http://www.endpoint-security.info/2008/12/01/uk-governement-says-no-to-data-breach-notification-law/" rel="bookmark" class="crp_title">UK Governement says no to data breach notification law</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Defense experiences fourfold rise in data breaches</title>
		<link>http://www.endpoint-security.info/2009/08/18/uk-defense-experiences-fourfold-rise-in-data-breaches/</link>
		<comments>http://www.endpoint-security.info/2009/08/18/uk-defense-experiences-fourfold-rise-in-data-breaches/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 15:40:54 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[MoD]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=279</guid>
		<description><![CDATA[When one thinks of institutions like the British Ministry of Defense, one expects tight security. Tight as in you cross us once, we expect you not to cross us twice. Apparently, things go another way, as the MoD, quoted by V3.co.uk, says the number of data breaches they have been exposed to was 4 times [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F08%2F18%2Fuk-defense-experiences-fourfold-rise-in-data-breaches%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F08%2F18%2Fuk-defense-experiences-fourfold-rise-in-data-breaches%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>When one thinks of institutions like the British Ministry of Defense, one expects tight security. Tight as in you cross us once, we expect you not to cross us twice. Apparently, things go another way, as the MoD, <a title="MoD breaches rocket" href="http://www.v3.co.uk/v3/news/2246723/mod-breaches-rocket" target="_blank">quoted by V3.co.uk,</a> says the number of data breaches they have been exposed to was 4 times higher in the past year.</p>
<p>The Ministry’s  latest <a title="Annual Report and Accounts Volume Two 2008-2009" href="http://www.mod.uk/NR/rdonlyres/77428463-6C55-46F2-AEE4-522FB73D1B98/0/mod_arac0809_vol2.pdf" target="_blank">resource accounts</a> show it suffered eight serious breaches in the 2008 to 2009 period, up from just two in the preceding year.  The most serious case lead to the loss of a portable hard disk from a contractor&#8217;s premises containing the names, passport information and bank account details of about 1.7 million individuals. That’s a big blow!</p>
<blockquote><p>Other incidents included the theft of three USB sticks from &#8220;secure government premises&#8221;, which contained details of all RAF service personnel who served between 2002 to 2008 and some of their next of kin.</p>
<p>And in April last year, an unencrypted laptop was stolen from government premises containing the personal records of 300 people.</p>
<p>The MoD admitted that it had lost electronic equipment, devices or paper documents from outside government premises on 15 occasions, and in six instances they were lost from within government offices.</p></blockquote>
<p>We’d say it’s about time they actually did something to prevent such breaches! A private company would have probably done so 8 breaches sooner&#8230;But then again, it’s public funds, isn’t it?<br />
<a href="http://www.endpointprotector.com/lp/endpoint_protector_general_EN.html" target="_blank"><img title="Endpoint Protector" src="/wp-content/uploads/banners/banner-factory-epp.jpg" border="0" alt="Endpoint Protector" width="500" height="100" align="middle" /></a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/09/06/2008-sky-is-the-limit-for-us-data-breaches/" rel="bookmark" class="crp_title">2008: Sky is the Limit for US Data Breaches</a></li><li><a href="http://www.endpoint-security.info/2009/05/25/1-tb-of-data-on-the-clinton-administration-gone-missing/" rel="bookmark" class="crp_title">1 TB of data on the Clinton Administration gone missing</a></li><li><a href="http://www.endpoint-security.info/2009/05/20/dod-cant-handle-inside-threats/" rel="bookmark" class="crp_title">DoD can&#8217;t handle inside threats</a></li><li><a href="http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/" rel="bookmark" class="crp_title">US 2008 data breach growth blamed on insiders</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/08/18/uk-defense-experiences-fourfold-rise-in-data-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Governement says no to data breach notification law</title>
		<link>http://www.endpoint-security.info/2008/12/01/uk-governement-says-no-to-data-breach-notification-law/</link>
		<comments>http://www.endpoint-security.info/2008/12/01/uk-governement-says-no-to-data-breach-notification-law/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 06:30:41 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Laws & Standards]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=174</guid>
		<description><![CDATA[Although the numbers of data breaches reported in the UK has been significant this year, the UK Government has recently announced it will not implement a compulsory data breach notification law for the private-sector companies. The decision was made after reviewing a recommendation made in July by information commissioner Richard Thomas. On the other hand [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F12%2F01%2Fuk-governement-says-no-to-data-breach-notification-law%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F12%2F01%2Fuk-governement-says-no-to-data-breach-notification-law%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Although the numbers of data breaches reported in the UK has been significant this year, the UK Government has recently announced <a title="ZDNet news" href="http://news.zdnet.co.uk/itmanagement/0,1000000308,39563446,00.htm?r=1">it will not implement a compulsory data breach notification law</a> for the private-sector companies. The decision was made after reviewing a recommendation made in July by information commissioner Richard Thomas.</p>
<p>On the other hand public-sector organizations are obligated to report any <strong>significant</strong> potential or actual data loss. Their private-sector counterparts should report the losses in the spirit of &#8220;good business practice&#8221;. So if your data is exposed by a public-sector institution and only 2 others have been affected, or if a private company looses thousands of private record but does not see reporting the incident as good practice, you will never find out.</p>
<blockquote><p>&#8220;After considering the analysis of the experience of the US in the area of data-breach notification legislation, the government is not intending to implement similar legislation to that in operation in the US,&#8221; states the <a title="Response to the Data Sharing Review Report" href="http://www.justice.gov.uk/docs/response-data-sharing-review.pdf">Response to the Data Sharing Review Report</a>.</p></blockquote>
<p>Private-sector companies are not clear of all consequences, as fines for organizations found in breach of data-protection laws will soon be raised. According to the same report, The Ministry of Justice is working with the Information Commissioner&#8217;s Office to determine the level of the maximum fine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/07/16/data-watchdog-warns-of-poor-data-protection-in-uk-institutions/" rel="bookmark" class="crp_title">Data Watchdog Warns of Poor Data Protection in UK Institutions</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li><li><a href="http://www.endpoint-security.info/2011/01/29/uk-fraud-on-the-rise-losses-amount-to-billions/" rel="bookmark" class="crp_title">UK fraud on the rise, losses amount to billions</a></li><li><a href="http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/" rel="bookmark" class="crp_title">UK: Information Commissioner&#8217;s Office reports that the NHS has disclosed 305 security losses, as the amount of breaches tops 1,000</a></li><li><a href="http://www.endpoint-security.info/2010/04/29/data-breaches-cost-more-in-the-us/" rel="bookmark" class="crp_title">Data breaches cost more in the US</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/12/01/uk-governement-says-no-to-data-breach-notification-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>British party membership list gets posted online</title>
		<link>http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/</link>
		<comments>http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 13:19:51 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[BNP]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[online fraud]]></category>
		<category><![CDATA[party]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=172</guid>
		<description><![CDATA[If you are British and have been plotting to stalk a member of the British National Party (BNP) you might just have missed the opportunity. A list with all the party&#8217;s members, including names, addresses, and email addresses has recently shown up online. Some of those who just got exposed online are also underage (an [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F11%2F21%2Fbritish-party-membership-list-gets-posted-online%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F11%2F21%2Fbritish-party-membership-list-gets-posted-online%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>If you are British and have been plotting to stalk a member of the British National Party (BNP) you might just have missed the opportunity. A list with all the party&#8217;s members, including names, addresses, and email addresses has recently shown up online.  Some of those who just got exposed online are also underage (an extra &#8220;benefit&#8221; of the family plan BNP offers) and others had mentions of other personal details made public, such as job or hobbies.</p>
<p>As <a title="BNP looses list" href="http://www.theregister.co.uk/2008/11/18/bnp_loses_list/" target="_blank">the Register</a> puts it, &#8220;That&#8217;s how we know that that BNP members include receptionists, district nurses, amateur historians, pagans, line dancers and a male witch.&#8221; Members reacted pretty strongly, filing their comments with courses and outrage. As certain professions in the UK are expected to have no political color, they might even lose their job and according to several blog sources, some pretty powerful people in the BNP are to blame for the leak.</p>
<p>BNP spokespersons found out of the leak from the Register, but although completely unaware, they promised to treat whoever is responsible quite harshly!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/12/09/two-arrested-in-bnp-data-breach-case/" rel="bookmark" class="crp_title">Two arrested in BNP data breach case</a></li><li><a href="http://www.endpoint-security.info/2011/09/05/are-hackers-going-to-be-this-year%e2%80%99s-top-news-item/" rel="bookmark" class="crp_title">Are Hackers Going to Be This Year’s Top News Item?</a></li><li><a href="http://www.endpoint-security.info/2009/04/02/dark-side-of-google-payment-card-details-of-19000-brits-found-in-cache/" rel="bookmark" class="crp_title">Dark Side of Google: Payment card details of 19,000 Brits found in cache</a></li><li><a href="http://www.endpoint-security.info/2008/06/24/anti-fraud-collaborative-service-launches-in-the-us/" rel="bookmark" class="crp_title">Anti-Fraud Collaborative Service Launches in the US</a></li><li><a href="http://www.endpoint-security.info/2010/05/17/la-firemens-cu-potential-breach/" rel="bookmark" class="crp_title">LA Firemen&#8217;s Credit Union notifies 28,000 of potential breach</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

