Skipton acts on ICO warning
The building society has deployed database security technology after an encrypted lost laptop brought it to the Information Commissioner’s attention.


Skipton Building Society has announced a successful deployment on new database security technology for a new mortgage broker application.
The information security of the UK's sixth largest building society came under scrutiny in February this year when the Information Commissioner's Office (ICO) warned it to raise IT security levels after losing an encrypted laptop containing the personal details of 14,000 customers.
At the time, it signed a legal agreement to ensure the security of the personal data it holds in the future, included its encryption and the ability for the ICO to carry out risk assessments.
Now it has taken steps to protect its customer-facing mortgage broker SQL application that contains confidential customer data. Colin McMahon, Skipton technical services infrastructure manager, said it recognised the need for extra security.
"Whilst we have databases based on proprietary technology, the new application used an SQL back-end, which made it far more vulnerable to attack," said McMahon.
"A successful SQL injection attack could have allowed a hacker to make any number of illegitimate requests to the database. We therefore urgently needed a security solution that understood the true intent of all database access requests and one that could identify and block any illegitimate ones."
Skipton, which is also the parent company to 19 subsidiary financial services companies, chose to deploy the Secerno DataWall database activity monitoring and security suite.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
It is enabling the company to set and update access rules and policies around the application more easily, continually monitor traffic and analyse the data from activity reports.
"Secerno's technology now adds to the protective perimeter around the database itself, so we are confident that our application data is well protected. We owe this to our customers."
The society now plans to develop a number of new internal business applications that make greater use of SQL databases.
McMahon added that the new system has proved very effective at highlighting security bugs and flaws in the new application. "By flagging these vulnerabilities, it has helped our developers write tighter code and build more secure applications from the outset, which is far more time and cost effective than remedying problems after an application has gone live," he said.
"It's very reassuring to know that we have done everything possible to mitigate the risk of a data security breach, protecting our own reputation and that of our customers."
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
New Zealand privacy commissioner tipped to become next ICO head
News John Edwards is said to be an 'anti-Facebook' regulator who would fit well in the UK's plans to clamp down on big tech
By Bobby Hellard
-
What is a freedom of information (FOI) request?
In-depth We look at the mechanism citizens can use to hold public bodies to account
By Dale Walker
-
ICO hints at Facebook hypocrisy over data protection goals
News Elizabeth Denham asks Facebook to drop appeal after CEO's call for greater internet regulation
By Bobby Hellard
-
ICO to investigate Google over GDPR violations
News UK Watchdog to liaise with other European regulators over 'forced consent' push by the tech giant
By Bobby Hellard
-
ICO myth-busts on the flow of data post Brexit
News The Information Commissioner explains how data will move between the UK and EU in a no-deal scenario
By Bobby Hellard
-
Leave.EU faces big fine over data law breaches
News Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
By Alan Martin
-
ICO website knocked offline for more than 24 hours
News The outage was caused by an “unprecedented electrical surge” that damaged its host’s circuits
By Keumars Afifi-Sabet
-
Elizabeth Denham appointed ICO boss
News Denham will be tasked with helping the UK leave the EU without any knock-on effects on privacy
By Clare Hopping