You are here: silicon.com > Comment & Analysis > Editor's Blog

Editor's Blog

Editor's Blog: Disclosing data breaches

Why we need to know…

Tags: security, data

By Tony Hallett

Published: 19 July 2007 15:22 GMT

Tony Hallett

You may have noticed that at the start of this week silicon.com kicked off a major campaign. It’s called Full Disclosure and you can see our opening salvo here. In a word: when an organisation, be it bank, retailer, government department or other, leaks some of your personal data, you should know about it.

It is obviously a bit more complex than that. Some types of data are more important than others. Your National Insurance number is worth more than your star sign, to use an example that springs to mind.

And what are we asking for? Well, ideally we’d like a change in the UK law, so it is in line with what now happens in California every time an e-tailer’s database is cracked or an insurance company employee leaves her laptop in a cab with a list of a million policy holders on it.

The idea is that openness is best.

That way we get to see which organisations take security least seriously and we respect the right response to the occasional blip. As things stand, the types of breaches you read about on these pages are just the tip of the iceberg, we can safely assume. We estimate there is another 90 per cent we don’t - but should - know about.

When an organisation, be it bank, retailer, government department or other, leaks some of your personal data, you should know about it.

We also get to act accordingly. If my internet bank account has been compromised, I’d quite like to move funds or adjust my security settings.

What have we learned so far? For one, there is an appetite for this change, an appetite even greater than we have sensed over recent months.

A raft of people and organisations are lining up their support. Some, though not all, are from the IT sector. We will doubtless receive criticism along the lines of 'They would say that, they have something to gain' – though that is not universally true. Some suppliers will also have some answering to do if a particular technology or approach based on a technology lets a user organisation down.

We have also already heard from those saying this shows just how infrequently communications and databases are encrypted. We agree. Encryption should be used more often.

And then there is the view that alerting thousands of customers – and potentially the thieves themselves – as to what has been stolen equates to giving the crooks a tip-off. A laptop that would be sold on for a barely three-figure sum all of a sudden becomes worth many thousands to the thief who only after the act realises what he might have purloined... perhaps thanks to a report in the media.

We will address these and several other issues over the coming weeks and months. We welcome your views on the subject which can be emailed to us at editorial@silicon.com. Or post a Reader Comment below.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
HELPDESK SUPPORT ANALYST / FIRST LINE / IT SUPPORT EXEC – PORTSMOUTH

Guru are an employment business renowned for delivering careers networking to the IT sector and in this instance are managing the advertising and ...

Business Development Manager - Financial Software Sales

Their fully-integrated investment management solutions serve various markets including: Institutional Asset Management, Wealth Management/Trusts, ...

Chief Architect (UK wide)

Provide pre and post sales technical / solution assurance and sign-off. Responsibilities will include: * Act as the technical authority, overseeing ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: