BLOG

This is SmallBizPod's blog dedicated to practical advice, news and insight for small business owners, entrepreneurs, and anyone needing help starting a business. You can read all sections of the blog from here or go straight to the topic you prefer by clicking the appropriate channel above.

Sponsors

Freeform Dynamics sponsors SmallBizPod's blog


Are you safe?

I see that our beloved leaders are knocking off tomorrow until January 7th. Slipping under the wire will be Alistair Darling to explain how our data will be safer in future. Sounds like a PR exercise to me, but I’ll be very interested to hear what he says. This is against a backdrop of stopping the police search for the missing HMRC CDs and a £20,000 reward for their safe return. But, apparently, Mr Darling is going to reassure us today.

The problem with this whole saga is that it’s got little to do with the discs and everything to do with the data on them. Unless they’re found down the back of the “junior civil servant”’s desk pedestal, the chances are good that the data has already been copied and created a time bomb for twenty five million people.

This isn’t news but it does give me an excuse to ask me about your own set up. Do you have information in your computer systems that you would not like others to see? We’re talking here principally about competitors and criminals, although feel free to let your imagination roam.

If the answer’s “yes”, are you certain that it could not leave your company? Bear in mind that routes out include CDs and DVDs, memory sticks (and these are often ‘disguised’ as MP3 players, iPods, phones, cameras etc) and email. You absolutely know that there’s no chance of anything being copied?

And, if there is a chance, do you have logging procedures in place, so you know who accessed what data, for what purpose and when? And do you have authority settings which prevent the wrong people getting hold of data they shouldn’t. And do you have enforced encryption of any sensitive data that leaves your own system?

Then we come to the human procedures. Despite HMRC having all manner of written procedures, these were ignored. Telling people what to do really isn’t enough. But at least make people aware of the rules and tell them what the consequences are of ignoring them, both in consequences of the data falling into the wrong hands and in terms of the impact on their employment.

Some American states have implemented a data breach notification law. Companies must notify anyone whose data has been compromised. This lays them open to lawsuits. Without such laws, it’s little wonder that a company’s natural instinct is to keep quiet and pray that nothing horrible will happen. But the EU is looking at similar regulations. Better to assume that they’re coming and plan accordingly.

The HMRC fiasco came about because someone, understandably, didn’t want to pay £5,000 to extract precisely the information the National Audit Office was after. Had they done this, they could have printed it in three inch high letters on a billboard, and no-one would have been compromised. If the CDs do fall into the wrong hands, the damage will run into hundreds of millions. Whoever it was that refused to cough up that £5k will live to rue the day.

Now, are you sure it couldn’t happen to you?

Related Posts

Alibaba.com sponsors SmallBizPod small business podcast

Sponsor SmallBizPod - the podcast for small business and entrepreneurs



4 Comments »

Subscribe to SmallBizPod feedRSS feed for these commments. SmallBizPod trackbackTrackBack address

    £5000 to extract just the required data? I would have thought it would have been a simple query. It might have taken a while to run or running the same report a few times with different criteria. It would have been easier to put a copy of the database in a non live system that whoever needed the data could connect to over a secure network. Suppose we have to be grateful that ID cards aren’t in place yet.

    Comment by Phil Connolly — December 18, 2007 #

    Lemme see now 25 million records, £5000. That would be a penny per 50 records processed. Seems reasonable to me. It’s how the bureaucratic mind is likely to work. And said bureaucrat would regard that as a lot of money without thinking about the risk involved should things go pear-shaped.

    A non-live but secure copy with restricted access to columns makes a lot of sense.

    Frankly, the more of these cock-ups (and the government slipped a few more under the wire yesterday) the better. With a bit of luck their incompetence will kill off an all-encompassing national ID database for good.

    Comment by David Tebbutt — December 18, 2007 #

    Breaches of security / privacy appear to be increasingly common. It’s a very alarming trend - whatever measures are in place to protect personal data don’t appear to be robust enough.

    Comment by Joan Harrison — December 18, 2007 #

    And these breaches are just the ones we hear about…

    Comment by David Tebbutt — December 18, 2007 #

Leave a comment

XHTML: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Alibaba.com sponsors SmallBizPod small business podcast

Podcasts

Listen to small business podcasts on iTunes

Click on one of the blue triangles below on the right to listen to inspirational interviews with entrepreneurs from the SmallBizPod archive.

SmallBizPod #60 - Inspirational business planning

SmallBizPod #60 - Inspirational business planning

Become passionate about your business planning and learn how to do it right with Tim Berry and Alan Gleeson of Palo Alto software.

play small business podcast now
SmallBizPod #64 - British Library, Facebook and Startups

SmallBizPod #64 - British Library, Facebook and Startups

Putting the voices to the faces behind the startups on the British Library Business and IP Centre Facebook group. Includes an interview with the Neil Infield of the British Library on its social media strategy.

play small business podcast now
SmallBizPod #51 - Tuesday 10 July 2007

SmallBizPod #51 - Tuesday 10 July 2007

Nigel Botterill, founder and managing director of theBestOf on business growth, franchising, online business & big ideas.

play small business podcast now
SmallBizPod #29 - Thursday 6 July 2006

SmallBizPod #29 - Thursday 6 July 2006

Steve Leighton, founder of hasbean.co.uk, on the practicalities of importing goods, ethical business and his passion for coffee.

play small business podcast now

Small Business Podcast RSS FeedWhat is this? Small Business Podcast RSS FeedMore business podcasts

Recent

Comments
  • Sherry Borzo: Thanks for the silver lining news and ha, ha, on the blowing bit. Nothing like tooting the horn for...
  • Ron Perrella: Cloud computing is another name for timesharing or “utility computing” — a concept...
  • Martyn: Nice article. We are a company in the target range, circa 50 employees, and we struggle with the on/off line...
  • The Credit Cruncher: It seems to me, the major credit crunch effect on businesses will be the banks hiking up costs...
  • David Tebbutt: Hi Alexander, if mine hadn’t been a birthday present, I’d have gone for the bigger screen...
  • Will - ArenaFlowers.com: Definitely an opportunity for business owners…if they can hold their nerve and run a...
  • Alexander Deliyannis: I’ve been quite impressed myself by these little machines and will probably buy one soon....
  • Benjamin: Lots I’d agree with there. Small businesses need someone to be their technology intermediary - not...
  • Ed Stivala: Will certainly go and read his research, sounds really interesting. For those of us that have been in...
  • Bob: Hi the complete agenda of the Berlin Web Week: http://berlinwebweek.de/

Topics
  • Archives
    Contact

    Other Info

    Check out other information and ways to subscribe for free to this blog

    • Add to Google
    • Subscribe in NewsGator Online
    • Subscribe in Bloglines
    • Add SmallBizPod - small business blog to Newsburst from CNET News.com
    • Small Business Blogs - BlogCatalog Blog Directory

    Small Business Trends review

    Creative Commons License

    © Copyright BizPod Media Ltd, 2005-2008