Security community slams HMRC

Security breach saw 15 million child benefit recipients' details 'lost in the post'

Written by Sara Yirrell

HM Revenue and Customs (HMRC) has been slammed by security experts after being responsible for what has been described as ‘one of the world’s biggest ID protection failures’.

As a result of the government faux pas, which involved the loss of computer discs in the post, thought to contain the confidential details of 15 million child benefit recipients along with over seven million people's bank details, HMRC chairman Paul Gray has resigned.

Earlier today the Chancellor of the Exchequer, Alistair Darling was forced to issue a statement which admitted an investigation is still in progress, after attempts to locate the missing CD’s failed. Darling added that an independent review of HMRC’s security procedures is taking place, with the full results being published in Spring 2008.

However Tom de Jongh, product manager at SafeBoot, said: “Basic policies were ignored. It appears that the fundamental policies upon which the National Audit Office and HMRC operate are flawed and it is no wonder that this breach has occurred. The Chancellor freely admits that NAO and HMRC broke clear procedures, but that will not reassure the millions of families that are praying their financial details don’t get into the wrong hands.”

Brian Spector, general manager for content protection group at Workshare, said: “It is staggering that an organisation responsible for the data of over 25 million child benefit claimants is still copying data onto CDs and not ensuring its full protection through encryption techniques. It has never been acceptable for businesses or government departments to lose data, but in today’s information society, the flagrant disregard for the protection and security of this type of data is not acceptable.

“The money invested in IT by the UK government must now be prioritised on security to ensure that the data of those the government serve – the public - is secure and protected.”

Jamie Cowper, director of European marketing at PGP Corporation, said: “Thes e discs should never have been transported in the first place – information of this type should only be transmitted using the strongest security protocols available such as encrypted batch transfer – but more to the point, these details should not have been stored in this medium.

Discs are easy to lose, but difficult to protect. This type of information should only be stored on formats where the data can be encrypted transparently, so that it remains protected wherever it resides, and whether at rest or in motion."

Further Reading:

Tax man loses 25m people’s records
http://www.channelweb.co.uk/computing/news/2203890/25m-records-lost-tax-man

  • Have your say
  • Send to a friend
  • Share
  • Print

See also:

reader comments

related articles

 

latest news

Lanway launches recruitment drive

VAR to beef up headcount as it waits for result of Buying Solutions framework 09 Feb 2010

Dell bids for fallen Exanet

PC giant on the brink of buying liquidated storage firm for a reported $12m 09 Feb 2010

ScanSource woos Avaya resellers with fast pricing

Distributor launches System Central 24/7 tool in the UK 09 Feb 2010

analysis and reports

Wireless LAN systems for the healthcare industry

The goal of a paperless hospital driven by wireless access that improves patient healthcare, expedites administration and streamlines operations.

A technology solution to align sales and marketing

Presenting best practices around people, processes and technology, this paper will help you produce more valuable customer relationships.

poll

A direct hit?

A direct hit?

Is Oracle right to take Sun's large accounts direct?

View poll results

David Critchley

PROMOTIONAL VIDEO - Accelerate your business with Cisco

Watch this Cisco promotional video to hear how the vendor can boost your business

money

CRN Web Seminar: Convincing Customers to Spend their way out of Recession

Join CRN editor Sara Yirrell and a panel comprised of Tim Black from sponsor Intel, Sam Routledge from VAR Softcat and Antony Young from analyst Demuto to find out how to get customers spending in 2010

events

Expo 2008 entrance

Channel Expo 2010

The only UK exhibition dedicated to the channel is coming to London, Olympia on 12 and 13 May 2010

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Primary Navigation