Companies hiding data breaches
The latest survey on corporate data breach practices reveals consumer mistrust in the way companies handle sensitive data may be well founded.


A survey released late yesterday has found that less than half (40 per cent) of organisations affected by data breaches actually bother to tell customers what's happened.
Half failed to inform the police or authorities, according to the alarming research findings unveiled by consultancy firm Logica and the e-media group, who surveyed 300 public and private sector organisations.
More than half (57 per cent) of these companies also said they had "no idea" or understanding of the impact of a security breach on their business. And nearly the same percentage believed security was the responsibility of the IT department.
But only 30 per cent of those questioned educated staff in IT security and information handling procedures on a regular basis, while less than a third employ a specific security incident response team.
And, although 63 per cent held personal data subject to European (EU) data handling regulations, only a quarter comply with the ISO27001/2 security standard for storing personal data.
The survey certainly gives weight to other research released yesterday that suggested Brits want data breaches criminalised because of high levels of mistrust over companies handle their data.
But it also strengthens yesterday's call from the Information Commissioner's office that Brits should also exercise their Data Protection rights and proactively manage the personal held on them.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Tim Best, director of enterprise security solutions at Logica, said the survey showed up the inadequate security policies and protocols that UK organisations have in place.
But he went further, adding: "It is time to take action it should be mandatory for all organisations to report significant breaches of confidential personal information to the Information Commissioner or their regulatory body. Only through mandatory reporting will the scale of the problem be understood, which will lead to the correct solutions being applied."
Best also said security should not be the sole responsibility of the IT department. "It is a boardroom issue and the focus must be to protect the trust that clients have in an organisation," he said.
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott Published
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly Published
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly Published
-
TikTok could be hit with £27m fine for failing to protect children's privacy
News Social media firm issued with a notice from the ICO for potential violations of UK data protection laws
By Bobby Hellard Published
-
What is AdTech and why is it at the heart of a regulation storm?
In-depth The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say
By Carly Page Published
-
ICO crackdown on AI recruitment part of three-year vision to save businesses £100 million
News ICO25 outlines a fresh approach that involves releasing learning materials, advice, and a new ICO-moderated discussion forum for businesses
By Connor Jones Published
-
Clearview AI fined £7.5m over improper use of UK data
News Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database
By Bobby Hellard Published
-
UK data watchdog cut IT spending by £1.2 million during pandemic
News The ICO’s IT budget has been slashed by around 23% since 2019
By Sabina Weston Published