SUBSCRIBE:

One million UK employees admit to losing confidential data

This article is a press release written by a supplier. It is not endorsed by Personnel Today.

HMRC is not alone in failing to protect confidential information. According to a new survey from Navigant Consulting, conducted by YouGov, more than one million employees in Britain (four per cent of all working adults) have lost, or had stolen a laptop computer; personal digital assistant; thumb-drive; CD; or floppy disk containing confidential information about customers, suppliers, staff or financial information, and a further 12 per cent almost three and a half million people claim that this has happened to a work colleague.

Navigant Consulting warns that employees’ work habits and lack of awareness about security are increasingly putting companies and organisations’ confidential information at risk from opportunistic identity thieves. Andrew Durant, managing director in Navigant Consulting’s Fraud Investigations team, urges employers to make sure that basic measures are in place rather than obsess about complicated IT security.

"Our survey shows that 17 per cent of the British work force now uses a company laptop at home that’s nearly five million people and indicates that working from home is an established working practice rather than a trend," says Andrew Durant. "Yet only 25 per cent of these said that their laptops are encrypted to protect the confidential information they contain".

"In addition, more than 11 million employees - 39 per cent of workers and/or their colleagues save data onto a PDA, thumb-drive, CD, or other device, to work from home. It is unrealistic to expect employees to stop using technology to work more flexibly, and frankly reckless for companies not to put measures in place to protect their confidential information in view of this change in working habits.

"Information security is a complex and expensive area, and I can understand why businesses want to bury their heads in the sand. But most frauds perpetrated using stolen confidential information can be prevented by taking some simple, common sense measures," claims Durant.

In the first half of 2007 reported stolen data included:

  • confidential information found in a skip outside a bank
  • computer back-up tapes stolen from a contractor’s van
  • confidential information stolen from an employee’s laptop following a house burglary
  • payroll and pension data from three stolen laptops
  • mortgage details in documents stolen from an employees briefcase in a theft from a car.

"Companies should have a policy regarding what information should and shouldn’t be stored on laptops and other devices and communicate this clearly to staff. Many employees will be unaware that information is confidential or could be used to perpetrate a fraud against the company or individuals connected to it.

"Laptop hard drives should be encrypted so that data is protected if it is stolen or mislaid. This can equally apply to specific files that contain sensitive data stored on a server to prevent them being copied or read by unauthorised people. Companies can also prevent electronic data containing confidential information from being stored locally on an individuals’ PC or laptop, instead forcing them to be stored centrally - this, greatly reduces the threat if a computer were lost or stolen," advises Durant.

Other work practices which are considered risky include employees sending documents containing confidential information to their own or other people’s personal web mail accounts such as Yahoo! or Hotmail for work reasons - 15 per cent of British workers, approximately 4.3 million people admit to doing this; and allowing company laptops to be used by friends and family. As many as 29 per cent of employees who use a company laptop at home are happy to let others use their work laptops more women than men are content to let this happen (37% and 25% respectively).

"Both of these practices illustrate how organizations are losing control of their confidential information as data flows out of the organization and into the hands of individuals who may have no relationship or loyalty to the owner of the information," says Durant.

Basic security is also failing in the work place according to Durant: "Identity fraudsters and organised criminals place bogus employees, and bribe temporary staff or even disillusioned employees to steal information from the inside.

"Yet 23 per cent of British employees know other employees’ computer passwords; 14 per cent claim that colleagues know their password; four per cent write their password down; four per cent all use the same password and five per cent don’t have one at all. It would be child’s play for a fraudster to sit down at a colleagues’ computer and access confidential information if there wasn’t a system of restricted access in place or data encryption that would prevent an unauthorised person from gaining admission to computer files.

"This practice also negates the value of audit logs as it would direct an investigation towards an innocent person."


 
 

COMMENTS

How do you protect your personal data?

As a tech geek and the IT guy of my house I employ these simple, common-sense measures as well to safeguard my data. For instance, my personal notebook never contains mission critical data. That type of info is stored on a desktop PC that stays in my house and is remotely accessed via VNC. VNC is a light-weight and freely available application that allows any computer on a network to display and control a remote computer. In this way, programs such as Quicken reside on my desktop computer and can be managed from my notebook. If my notebook is ever stolen, my data and personal account information is not compromised because it is basically a terminal device.


For passwords, I tend to write them down. There is much debate over this but in my opinion it is better to write down a complicated password then to try to memorize easy ones. If you are an organization freak like myself then do yourself a favor and pick up a password organizer book as well so you don't have loose scraps of paper floating around with all sorts of login information. Check out: http://www.internetpasswordorganizer.com/ for a nice solution.


The Mad Hermit
22 Nov 2007

ALERTS

Alert me when new articles are added which relate to these topics
Business performance
Computer misuse
Corporate social responsibility
Data protection
Knowledge management
Mobile workers
Teleworking
Alert me when new articles are added which relate to these specialism areas
Economics, government & business
Employment law
General HR management
Strategy

RELATED PERSONNEL TODAY PRODUCTS AND SERVICES

Personnel Today's monthly magazine dedicated entirely to employment law for senior HR professionals provides analysis through case law, practical advice and Q&As on legal matters for all UK employers.Arrow IconMore...
This Personnel Today guide gives a practical insight into all areas of employer branding - including understanding the branding process, learning how to create a branding framework and communicating a company’s values effectively.Arrow IconMore...
Human Capital Management offers HR its best chance yet of demonstrating its impact on the bottom line. Written by one of the UK’s leading experts, this Personnel Today guide will rapidly get you up to speed on the next revolution in HR. Arrow IconMore...
Personnel Today’s One-Stop Guide to Absence Management, provides essential information and practical advice on preventing and reducing absenteeism in the workplace. Arrow IconMore...
Effective absence management is now recognised as a key factor in improving productivity levels. Personnel Today's One-Stop Guide to Managing Incapacity give you the information and guidance you need to find a route through the law, the issues and best practiceArrow IconMore...
Many investments in HR information systems, shared services, e-HR or outsourcing do not deliver on what they promise or are outright failures. This Personnel Today guide explains how to redesign your HR function successfully.Arrow IconMore...
Personnel Today's stablemate XpertHR is your one-stop resource for all HR information needs, bringing together the combined expertise of Personnel Today, IRS and Butterworths Tolley into a single online tool. Arrow IconMore...
 
© Reed Business Information 2008