Wednesday, March 10th 2010 11.03pm GMT

Losing the plot

IT COULD have been prevented for £65, but this was a disaster waiting to happen. However shocking and catastrophic the Inland Revenue's security breach may seem to the families left wide open to the threat of identity theft, last week's debacle came as no surprise to the UK's top technology experts.

With the estimated cost of the data disaster standing at more than £200 million and millions of British households now squarely in the sights of international organised crime gangs, the incident has exposed a fundamental flaw in the public sector's approach to IT that many experts have long recognised.

"The most shocking aspect to the loss of 25 million records is that for £65 the data on the two CDs could easily have been stored on an inexpensive and easy-to-use encrypted USB drive. This would have absolutely guaranteed that our most private records would have stayed private, and it beggars belief that a government department could have saved our most personal data on such an insecure medium," said Jim Selby of data storage specialists Kingston Technology.

This, in a nutshell, is the problem with government computing projects. Over the years they have become notorious in the IT sector, frequently taking years to complete, running wildly over budget and often ultimately failing to cope with the basic functions for which they were designed, when simpler and cheaper off-the-shelf products would have done the job.

If there is a bright side to the debacle, many commentators believe it is that the public sector can no longer pretend there is not something fundamentally wrong with its approach to technology.

"I believe this will be the tipping point," said Richard Archdeacon, Symantec's director of technical services. "The government clearly has some major issues to solve within its technology strategy, and can surely not continue without a far-reaching review of its IT policies and procedures."

This viewpoint is hard to counter. Earlier this month around 15,000 Standard Life customers were put at risk of fraud after an HM Revenue and Customs (HMRC) courier lost a computer disc containing personal information, while in October one of the department's employees lost the details of a reported 400 individuals when a work-issued laptop was stolen.

Most would hope that the missing discs will turn out to be lying under somebody's desk, but HMRC will not be the only organisation in the hunt. According to experts in the hacking community, a multitude of professional identity-theft gangs will also be hot on the trail, if one of them doesn't have the discs already.

"A dataset of name, address, national insurance number, birth date and bank account details for 25 million people is worth a lot of money," said Gunter Ollmann, director of security strategy for IBM Internet Security Systems. "I doubt that anyone but the big boys of organised crime could afford to buy all the information in one go. However, a common method of making money off large data sets is to break them down into smaller batches. Batched datasets containing this kind of data get bought and sold for variable amounts, but something like $2 per record in batch sizes of 1000 records is not uncommon."

A $50m haul is there for the taking. And even after the data has been sold, the potential for further criminal gain is enormous. Despite advice to monitor bank statements for suspicious activity, those contained in the lost discs are sitting ducks.

Fraudsters using the missing information will have enough information to open new accounts in their victims' names, and will be willing to wait until the children whose details have also been lost reach 18 so that they can start impersonating them, said Experian's Peter Brooker. "The damage to a victim's credit report and ability to obtain a mortgage, rent a flat, buy a car on credit, open a new bank account and so on will be severe and will last for years."

Even if the data never reaches nefarious hands, the cock-up is likely to precipitate a deluge of related criminal schemes. "It is likely that even now a large email campaign is being planned to prey on the British public. A similar scam campaign in Scandinavia recently led to a bank losing £800,000 when 250 victims fell for an email scam that preyed on their feelings of vulnerability," said Jonathan Armstrong, partner at international law firm Eversheds.

Among IT experts, the broad consensus is that training schemes designed to make civil servants at all levels aware of the issues surrounding data must be immediately introduced. This, combined with a policy of using the latest technology, would provide a strong starting point from which to ensure such disasters never happen again.

"At the end of the day, this isn't the first time this has happened, and it's about time they got their act together. Quite simply, the use of proper encryption should be a basic, everyday computer skill for anyone working with information like this," said David Tomlinson, managing director of security firm Data Encryption Systems.

"I'd hazard a guess that there are IT and security staff at HMRC who understand fully the security issues and exactly what is needed to take care of them. However, this awareness and information has failed to make its way down to the people dealing with the information on a daily basis."

Industry observers are also calling on the government to introduce breach disclosure laws compelling institutions to notify individuals of any breach in privacy. California has already seen the introduction of such legislation hailed as a major success, and the policy is quickly being adopted in other parts of the world.

Perhaps most importantly, many experts are also calling for a review of the government's fondness for outsourcing major IT projects. They believe this creates a dislocation between system and service that will always be difficult to overcome and also prevents in-house teams developing the skills required to manage such complex operations.

"If you outsource core skills, you won't have them to hand when it really matters. That is the nub of the HMRC debacle, and its almost certainly the reason that government technology always seems to be several years behind," said John Safa, chief technical officer of IT security company DriveSentry. "It's also worth noting that government IT jobs pay well below the industry average and, while it sounds cruel, if you pay peanuts you get monkeys."

It seems an unavoidable conclusion that something is very wrong at the heart of the government's technology strategy. It represents a fault at the core of the national infrastructure that, unless remedied, could wreak havoc on British public life for decades to come.

"After all the recent debacles involving public-sector computing, this latest disaster only seems to add to the weight of evidence that the public sector is not taking the security of our data seriously enough," said digital security expert Matthew Tyler. "This certainly does not bode well for either the national DNA database, or, more importantly, the potential new identity card scheme."


Comments


Sat, 14/03/2009 - 8:02am — runescape money (not verified):

Here are some power leveling rules to ensure your account security,rights and interests. runescape accounts Inventory Safety We will NOT remove your pre-existing items and gold

when we are on your account to do power leveling. runescape gold We will

NOT respond to incoming tells by fellow players to maintain the confidentiality of your character during power leveling

process.We will just keep the private chat off until the power leveling is done. runescape moneyYou can check the powerleveling status any time via 24/7 live support or check your

account status by highscores .


Tue, 31/03/2009 - 12:23am — ljhha (not verified):

Crysis Softwarecheap wow gold Development Kit toolsworld of warcraft gold will work withbuy wow gold "Far Cry" software buy wow golddevelopment kit dofus kamasbasic instrument kamas dofusrather, players can Final Fantasy XI giluse software toolsffxi gil to use game developmentlotr gold kit with a model map produced Editor flyff penyaMOD, Game players can evenbuy flyff gold change the original code. These Maple Story MesoscharacteristicsMaple Story meso are the production EverQuest 2 goldof Games MOD players easier.eq2 plat I'm not sure Runescape goldwhether the Runescape moneysoftware tools development Runescape Moneykit will be Runescape Power levelinglaunched on time. Runescape GoldThe software toolffxi gil kit has what new dofus kamasfeatures? Will kamas dofuswork with the dofus kamasdevelopment kit kamas dofusbefore what's the difference? dofus kamas This is a difficultkamas dofus one to twodofus kamas sentences with a kamas dofusquestion to answer.


Tue, 31/03/2009 - 12:24am — ljhha (not verified):

If you are familiar hair straightenerswith the map editor before,GHD you will have chi hair straightenersthe same map editorreplica handbags is very familiar wholesale handbagswith. At this replica designer handbagstime our editorreplica watch add some new swiss replica watchesspecialty, such replica rolex watchesas the puma shoesnew graphicalnike shoes interface womens clothesare the playersed hardy clothing can easily replica handbagsget in thereplica watches game andDesigner clothing add the roleDesigner replica handbags of time,Wholesale jewelry set the Replica rolex watchesgame time, or replica handbageven more. Replica HandbagsCan you Replica Watchesgive me somereplica designer handbags games haveCoach Handbags to introduceGucci Handbags the onlineRolex Watches mode Power Struggle?


Tue, 31/03/2009 - 12:26am — LJH (not verified):

After thewow gold prices occupation wow gold hacksof factories wow gold guides(usually by finding cheap wow gold euthe main office or wow gold gamethe resistancemake wow gold to occupationwow gold shop of the enemywow europe gold attack), gamers can wow fishingpurchase a vehicle. But wow gold tradethe war factory wow gold makingproduction tanks, air wow gold onlineunits. Each wow hacksmap is adopted topaladin wow determine gold in wowsome aspects of the very cheap wow goldwin. Playerswow gold seller can choose buy gold for wowthe time and wipewow gold exchange out the cheap gold for wownumber of points.selling wow gold Refers to thewow gold guide annihilationwow gold priceof a few playersbuy cheap wow gold must destroy the enemy'buy guild wars golds high commandsell wow gold to win. Thischeapest wow gold can only be used to realize two types of weapons.


Thu, 02/04/2009 - 10:14am — yuxuan1515 (not verified):

Date? The term wow goldis a little jarringwow goldPopWatch would wow goldNickelodeon Kids' wow goldup the 2009 wow goldlike to thank Miley wow goldCyrus for summing wow gold


Thu, 02/04/2009 - 10:15am — yuxuan1515 (not verified):

Academy Awardsbuy wow goldworld of warcraft goldworld of warcraft goldwow power levelinglast night's fest wow powerlevelingrunescape goldwhole shebang runescape moneymaple Story mesosand screaming maple mesosneon-green slime maplestory mesoof Hollywood Maple Story mesowas mercifully devoid maple Story mesospomposity. The eminently cheap ffxi gilDwayne Johnson ffxi cheap gilhosted and even ffxi gilfinal fantasy 11 cheap gilfinal fantasy 11 gilrocked some final fantasy xi gilto his long list dofus kamasMiley Cyrus dragkamas dofusof achievementsLOTRO GoldWorld Champion LOTR Goldadded Slip n' Slime lord of the ring goldlycra wetsuit,Warhammer gold clad in a skin-Buy Warhammer goldMiley Cyrus dragflyff penyabetter?) Will Ferrellbuy flyff goldvWho wore the hot flyff moneylittle red mini


Thu, 02/04/2009 - 10:15am — yuxuan1515 (not verified):

NEW YORK (Hollywood Warhammer goldReporter) - In "12 warhammer online goldRounds," a forbuy Warhammer goldfortuitous confluence ffxi giland pluck allows Final fantasy xi gillowly New Orleans cheap ffxi gilcop Danny gil ffxiFisher (John Cenaffxi cheap gil to arrest infernally clever Final fantasy xi gilIrish arms buy ffxi gildealer Miles gil ffxiJackson (Aiden ffxi gilGillen), who's dofus kamasbeen leading kamas dofusthe FBI a merry dofus kamaschase for three kamas dofusIt's a shame Miles' buy wow goldin the processcheap wow golddaredevil girlfriend world of warcraft goldbut it was more Miles' ffxi gil

  
Thu, 07/05/2009 - 7:26am — Anonymous (not verified):

hi,guy this site dofus.us it is about online game's web,we offer the news and important cheats,The main we sell dofus kamas,if u want to buy dofus kamas,u need buy dofus kamas from this site,it is cheapest,right,u want buy dofus kamas,cheap dofus kamas,plz click here:dofus kamas,it is cool,isn't it?everyone who play dofus and want buy dofus kamas can get some help from our.we We have mass available stock of dofus kamas on most of the servers, so that we can do a really instant way of dofus kamas delivery. We know what our buyers need so we offer an instant way of cheap dofus kamas,the cheap dofus kamas delivery.lol…


Fri, 12/06/2009 - 10:17pm — fast loans (not verified):

Looks like the author has massive experience in the matter. Thanks you for the information. bad credit personal loan bad credit personal loan bad credit personal loan bad credit personal loan

 
Wed, 01/07/2009 - 5:07pm — Runescape Gold (not verified):

Frogster Runescape Gold announces ????-aion-RMT the Runescape Money expansion Get Box Sets of Buy Runescape Gold free MMORPG Runescape Gold Runes chanel watches of Magic, Buy Runescape Money“The Elven Runescape Money Prophecy”Runescape Gold For Sale or Prophecy of the Elves, which Runescape Power Leveling incorporates an chanel watches increased level ?????2 RMT limit to the Runescape game in Runescape Money For Sale addition to new chanel j12 watches areas, and two new quest.


Thu, 09/07/2009 - 4:07am — Banks (not verified):

These security breaches can affect the entire financial industry, including companies that offer bad credit personal loans, debt consolidation, credit counseling, mortgage loan modification and mortgage modification products. Additional steps need to be taken to ensure that customer data is safe.


Mon, 10/08/2009 - 10:08am — Mortgage loan modification (not verified):

Great info. Thanks for sharing.


Mon, 10/08/2009 - 3:21pm — Loans Modification consultant (not verified):

What a wonderful website. Great information. I will come back often.


Wed, 12/08/2009 - 8:50am — Angol nyelvtanfolyam (not verified):

I wonder why they have not stopped entirely trading with mortgage backed securities. They have created a market which did not exist and swallowed billions of dollars. We should not do the same mistake again:

Mortgage loan modification
Loan modification
Mortgage loan modifications
Loan modification services


Thu, 13/08/2009 - 6:54am — Könyvelés (not verified):

Finishing work on time is a crucial element to long term success when it comes to starting government computing IT projects.

Angol nyelvtanulás

Eredetiségvizsgálat Budapest

Épületgépészet

Online Marketing 101
Diszlexia


Sun, 16/08/2009 - 8:42am — Masszázs (not verified):

If humans could learn from their mistakes there would no be wars anymore.

Hungria pisos Budapest

Real estate Hungary

Inversion inmobiliaria pisos Budapest

Inversion inmobiliaria pisos Budapest


Fri, 21/08/2009 - 11:16am — Anonymous (not verified):

Fri, 28/08/2009 - 12:09am — Anonymous (not verified):
 
Wed, 02/09/2009 - 8:16am — MMC Chip tuning (not verified):

Sat, 05/09/2009 - 12:12pm — Self Esteem 2 you (not verified):

There has been more than 80 banks gone bankrupt so far this year and this number is expected to rise till 200. You have to have a high self esteem to cope with all the stresses of losing money.

Weboldal optimalizálás

Ingatlan Értékbecslés

Ügyvéd és Ügyvédek

Real Estate Hungary

 
Thu, 10/09/2009 - 7:50am — Bmw chiptuning (not verified):

Banks have created this huge mess so they should be cleaning it all up.

német nyelvtanulás anyanyelvi német nyelvtanár


Wed, 16/09/2009 - 11:35am — Anonymous (not verified):

Fri, 25/09/2009 - 6:03pm — Bio takarítás (not verified):

Wonderful comments! Where all are you guys from? Just Bio takarítás, right?

 
Fri, 02/10/2009 - 6:50am — Blogger (not verified):

Identity theft is a very common problem these days, many are a victim of it, all because the Internet was built out of mistakes and trials , many saying we need to create a new internet,a safer one , where people can't use different identities to buy stuff or work online with how sell gold or perform any other operations

 
Fri, 23/10/2009 - 10:14am — Karosszéria javítás Kistarcsa (not verified):

thank you guys for sharing. Karosszéria javítás is a great way to help you repay your mortgage


Fri, 23/10/2009 - 7:57pm — locksmith in london (not verified):

GreaT!!!!!!!!!!!!!!!!just kidding
-----------------------
24 hour locksmith in london


Mon, 26/10/2009 - 6:10pm — host a gold party (not verified):

It may come to a disaster. Thanks for the governments sectors to be smart enough to convert gold funds into money.


Wed, 25/11/2009 - 5:36am — women's sandals (not verified):

If humans could learn from their mistakes there would no be wars anymore.


Tue, 01/12/2009 - 5:08am — ed hardy (not verified):

I like this story.It's good stuff.ed hardy
ed hardy clothing
ralph lauren polo
juicy couture


Sun, 06/12/2009 - 2:35pm — Microsoft Office 2007 (not verified):

Microsoft Office 2007 ,Office professional 2007 and office Ultimate 2007 sales on:http://www.software-hotbuy.com/ and all free shipping worldwide

Enjoy discount on :http://www.software-hotbuy.com/,discount Microsoft Office 2007 ,Office professional 2007 and office Ultimate 2007 all free shipping worldwide

 
Sun, 27/12/2009 - 6:36am — Chiptuner kft (not verified):

Thanks for the sharing, great content!
Chiptuning árak

Chiptuning akció


Thu, 31/12/2009 - 8:43pm — cheap shoes (not verified):

He is one of the best so stop hating


Fri, 01/01/2010 - 3:11am — Anonymous (not verified):

UGG Classic Crochet for women has an amazing fitting property. The foot bed is completely ugg cardy blackmade of fleece and provides a very snug and comfortable fitting.There is a multi layered rubber outsole placeduggs classic tall in these boots. The function of these layers is providing additional comfort, traction and more support. These boots canugg tall black be worn with socks but they are especially designed to be worn bare- foot.


Fri, 01/01/2010 - 3:19am — Anonymous (not verified):

Placed in these boots ugg ultra saleis a multi layered rubber outsole. These layers are provided simply uggs ultra tallto create additional comfort, traction and more support. They are especially designed to be worn bare-foot, althoughuggs ultra short, wearing socks is not prohibited.


Fri, 01/01/2010 - 3:29am — Anonymous (not verified):

range also change. classic tall uggsThe price range from a hundred and fifteen dollars to hundred anduggs classic tall thirty dollars is for a black or a gray boot. But to any other uncommon colors like the pink boots, you will have ugg sundance 2to add.


Fri, 01/01/2010 - 3:45am — Anonymous (not verified):

As we know that all ages boots timberlandcan enjoy the quality and comfort of Timberland boots in the most cheap timberland bootspopular design. For juniors ages nine to 13, cheap Timberland boots include the original classic wheat Nubuck, priced well under $85. The classic design is a favorite among youth culture heroes and can be seen on CD covers and music timberland work bootsvideos all over You Tube and My Space.


Fri, 01/01/2010 - 3:57am — Anonymous (not verified):

These classic Timberland boots are made with premium, full-grain leather. They toddler timberland bootsare waterproof, and sport a rubber lug sole for great traction on slippery sidewalkstimberlands for women outside school or slushy patches on the playground. In addition to those series of cheap Timberlandtimberland women shoes boots, large quantities of other Timberland footwear also come in black. Just take your time and catch this opportunity!


Fri, 01/01/2010 - 4:07am — Anonymous (not verified):

Perhaps the main reason for uggs becoming so popular is the fact that they are so black kids timberlandcomfortable and practical. You don't even need to wear socks when you wear uggs. In fact, it is best to keep the socks off when wearingblue men timberland these boots. That way, the sheepskin with its natural odor protection, water resistance and insulating capabilities blue women roll-top bootscan help keep your feet warm and dry.


Fri, 01/01/2010 - 4:59am — Anonymous (not verified):

The anti-shoe,discount mbt masai footwearlouboutin shoes, also known as MBT shoes,louboutin mbt shoes chapacl24, are not your normal kind of footwear. It's a relatively new concept inmbt chapa white shoe design developed to be both physiologically and anatomically correct?discount mbt shoes


Fri, 01/01/2010 - 5:10am — Anonymous (not verified):

The concept was developed while studying the tribes of Africa and how they walked. It was discovered that

this nomadic group walk extremely long distances mbt masai footwearon a daily basis, with a most amazing realization that theymbt shoes chapa had

perfect posture and a low amount of back pain even though they were on their feet for long durations. It

was found that they walk barefoot and on uneven ground and is attributed to thembt chapa healthy

conditions. buy mbt shoes cheap


Fri, 01/01/2010 - 5:23am — Anonymous (not verified):

just dear them although, they are a good investments. a great positive, when you already mbt m walk shoes

go of such injuries. a trivial margin stimulated mbt chapa chili
is bigger blood circulation as a health anxiety employee mbt anti shoes , wearing is by far the gentle

cradling of your knee and hip joints while walking, mbt chapa azuloperation or barefoot shoes. pressure is the easiest way to in sculpt, tone

and keep mbt shoes reviews the spine, hips andmbt chapa black knees all over again.



Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <b> <address> <blockquote> <br> <caption> <center> <code> <dd> <del> <div> <dl> <dt> <em> <font> <h2> <h3> <h4> <h5> <h6> <hr> <i> <img> <li> <ol> <p> <br clear=all> <strong> <sub> <sup> <table> <tbody> <td> <tfoot> <th> <thead> <tr> <u> <ul> <tr>
  • Lines and paragraphs break automatically.

More information about formatting options

Captcha
This question is used to make sure you are a human visitor and to prevent spam submissions.
Copy the characters (respecting upper/lower case) from the image.