Incident Disclosure is really a No Win Situation
Recently a UK City Council announced a data breach involving tens of thousands of credit cards, I’m not going to name them as I don’t really want to be associated in defending them.
The facts of the security incident and how it was discovered is very different from the press headlines, which basically laid into the Council for having bad security and not being security responsible by putting thousand of it’s users at high risk of credit card fraud by putting these deatils unsecurely online. However after reading through press releases and a bit deeper into some of the news reports, it painted a slightly more responsible picture.
The Council had hired an external Security Expert – no, not me ;) to check and test the security of their systems, this expert found that a data file had accidentally been uploaded to a public website in error by a member of staff. The file held credit card transaction details for thousands of council tax payments and parking fines, however the credit card data was encrypted and the file didn’t include pin numbers and CV2 numbers, so it would be pretty difficult to use it for credit fraud. I understand the names and address were in clear text but I haven’t able to confirm this as yet. It appears the file was downloaded on one occasion from the public web site.
Well I think the Council’s “heart” must have been in the right place to hire an external security expert in the first place, the fact that the credit card data was encrypted and they didn’t have pin/CV2 numbers within the file bodes well, and after all they publicly disclosed the incident within a week of finding out, they said they would of disclosed it earlier but it would of compromised the incident investigation, sure that could be just PR spin, but we’ll give them the benefit of the doubt. As I’m sure a lot of other organisations might have just swept this type of incident under the carpet. I just think the very negative press attack and blatant avoidance of the actual facts within news reports in order to sensitise the story and panic the populous, isn’t exactly going encourage other organisations to voluntary disclosure similar incidents in future. Which is what I would like see, as I would like to bring into the open the scale of general bad security going on within business, punishing organisations that are appearing to be trying their best I don’t think is going to help matters, if anything it could even put off companies from hiring in security experts to test their system security!
Again what was the cause of this incident? You guessed it was a human (on the inside) making a mistake (humans tend to do that). So another example to be chalked up within my security awareness training presentations.
Before anyone comments on my defensive approach to data breach, please don’t as you will be missing my point, I totally agree any data breach is a serious and generally bad thing, especially when it involves public data/credit card data, and its totally right these incidents are aired within the public arena.
Labels: council Incident Disclosure expert security credit card




