Defend your business against the biggest cause of data breaches: human error

GDPR has become part of everyday life but as Tom Chartres-Moore an Associate at Stephens Scown and Director of NuBright explains human error is the greatest risk to professional firms of exposure to a data breach. DASLS members Stephens Scown have worked with the BlueGrass Group to provide a training platform that will help firms improve awareness of how breaches occur.

GDPR is now in full swing, enabling the Information Commissioners Office (ICO), to levy large fines for breaches or for failing to take proper care of customer and personal data. The biggest cause of data breaches is close to home. It’s human error.

 

The ICO has said that over 85% of breaches are due to human mistakes and professional services firms both large and small are just as susceptible to a breach of GDPR as any other business. It is imperative that GDPR compliant policies and practices are put in place to reduce risk and ensure that the correct course of action is taken in the event of a breach.

 

Something as simple as email error is, in our experience, one of the most common mistakes made. It could be a case of not blind copying, or it could simply be sending an email to the wrong address. We all know that these things can easily happen, especially when someone is under time pressure or multi-tasking. But if an incident like this leads to the leaking of someone’s personal, sensitive data then the consequences could be serious, however innocent the mistake.

 

One notable case ruled on by the ICO involved Gloucestershire Police. An officer sent an update email about an alleged victim of child abuse and put recipients names in the ‘to’ field instead of blind copying them. This made all recipients’ names and email addresses visible to all. The force was fined £80,000 by the ICO. Professional services firms deal with sensitive and financial information on a daily basis, so the risk of a data breach is real.

 

Other common human error issues include staff simply disclosing too much or inappropriate information. This could happen over the phone – it doesn’t have to be electronically in writing. For example, if someone phones a lawyer claiming to be the client but is using a different telephone number – the natural instinct in a good staff member will be to help them and tell them what they want to know. Most of the time, this will be harmless but it could end badly if someone has negative intentions. Professional services firms should be alive to this risk because of the risk of fraud and finance deception.

 

Other issues straddle the boundaries between human error and systems weaknesses. For example, staff clicking on links in ‘phishing’ emails which then introduce a virus or allow access into systems full of data.

 

This is why it’s vital to ensure that staff have the training they need around cyber security and GDPR / data protection issues. This is especially prevalent in a professional services firm, where additional regulations apply and governing bodies take interest in such matters. Staff are your first line of defence and awareness of the issues is key. At nuBright, a joint venture between Stephens Scown and Bluegrass Group, we offer accessible and straightforward training that can help.

 

Our training courses ‘Data Protection’ and’ Cyber Security’, when purchased together, cost just £12 + VAT per person. The course is interactive, online and can all be completed in less than 30 minutes.

 

When businesses stand back and look at their processes, they often find that it’s not just a compliance issue: there are improvements they can make that create a more efficient business. There are real returns in getting on top of the GDPR, as well as helping keep your business out of a very unwelcome spotlight.

 

To find out more how nuBright can help your company with data protection and cybercrime email ask@nubright.co.uk or call 01392 796280. www.nubright.co.uk

 

Thomas Chartres-Moore, Director at NuBright


Like   Back to Top   Seen 493 times   Liked 0 times
Subscribe to Updates And Join Over 1.2K Subscribers Today!

Subscribe to:
x

Subscribe to Updates

If you enjoyed this, why not subscribe to free email updates and join over 1274 subscribers today!

Subscribe to updates



Subscribe to:

Alternatively, you can subscribe via RSS RSS

‹ Return to

All email subscriptions must be confirmed to comply with GDPR.

I've already subscribed / don't show me this again