PL&B UK E-news, Issue 33
5 November, 2004
© Privacy Laws & Business 2007
- Cahoot security flaw exposes customer accounts
- UK government opposed Data Protection Act amendments
- ICO appoint Chief Operating Officer
- SMEs recognise business benefits of DP compliance
1. Cahoot security flaw exposes customer accounts
Online bank Cahoot was forced to shut down its website for 10 hours yesterday after being alerted to a security flaw enabling Internet users to gain unauthorised access to customer accounts. An investigation by the BBC revealed that the bank‚Äôs password controls could be easily bypassed simply by typing in a customer‚Äôs user ID.
Infosecurity expert, Neil Barratt, told the BBC, ‚ÄúI‚Äôm shocked that it was so easy‚ÄĚ, stressing that most online security breaches are more complex. One Cahoot customer described the breach as ‚Äúdisgraceful‚ÄĚ, adding that she would close her account down.
Tim Sawyer, head of Cahoot bank, a subsidiary of the Abbey National Group, said the flaw occurred as a result of an upgrade to the website 12 days ago. He apologised to customers but attempted to reassure customers by stating that anyone hacking into the Cahoot site would not have been able to transfer funds out of the accounts. Sawyer stressed that the bank does carry out security testing on its systems, including penetration testing and the use of ‚Äėethical hackers‚Äô to search for gaps in security. Nonetheless, he added that the incident had ‚Äúnot been our greatest moment‚ÄĚ and pledged to conduct a review of security procedures.
2. UK government opposed Data Protection Act amendments
According to Out-law.com, the government is against suggestions that employees should be given greater rights to access to their personnel records. Following a ruling by the Court of Appeal last year (in the Durant v Financial Service Authority case), workers‚Äô rights to access paper-based personnel files has been heavily restricted. In response to a Parliamentary question about extending the right of access to unstructured manual files, the Secretary of State for Work and Pensions, Alan Johnson, said, ‚ÄúWe have no plans to extend the application of the 1998 [Data Protection] Act to unstructured manual personnel records.‚ÄĚ
3. ICO appoint Chief Operating Officer
The Information Commissioner has appointed Simon Entwisle to the newly created post of Chief Operating Officer. The role will involve responsibility for operational effectiveness and efficiency across the Information Commissioner‚Äôs Office (ICO), including key areas such as data protection case work, regulatory enforcement, the Data Protection Helpline and the notification department. Commenting on the appointment, Richard Thomas, Information Commissioner, said, ‚ÄúThis appointment further strengthens my office‚Äôs commitment to provide proficient data protection advice and enforce the [Data Protection Act] DPA where necessary.‚ÄĚ
4. SMEs recognise business benefits of DP compliance
73 per cent of small-to-medium-sized companies (SMEs) understand the impact data protection has on their business operations, says a new study published by the Information Commissioner‚Äôs Office this week. The study, carried out by the University of Lincoln, found that 99 per cent of SMEs had heard of the Data Protection Act, with around 75 per cent stating that legal compliance was easy. Over 90 per cent of respondents agreed that privacy and confidentiality are important to their clients and business operations.