Posts Tagged ‘ICO’, pseudonymised data and the ICO

April 6, 2014 Leave a comment

I find the ICO’s response to Dr Neil Bhatia’s request for clarification on and the Data Protection Act (DPA) to be very strange. is the name for NHS England’s program to centralise all GP patient health records together with all hospital visit records in one big data warehouse available to researchers. While originally intended to go live this month, it has been delayed for six months.

Dr Neil Bhatia is a privacy activist opposed to the program. Where a patient objects to his or her data being shared outside of the NHS, the intention is to share ‘pseudonymised’ health data. Dr Bhatia wrote to the ICO for clarification on the Data Protection Act and pseudonymised health records.

The ICO replied that anonymised data is not covered by the DPA. If the subject cannot be identified there can be no privacy loss.

But on pseudonymised data he has no clear response:

Pseudonymised data on its own would not constitute personal data, as it does not enable individuals be identified.

However, it is possible that pseudonymised data may become personal data if it is held by an organisation which holds other information which could be used in conjunction with the pseudonymised data to identify individuals.

As such, whether pseudonymised data would be covered by the DPA would depend on other information which is in the data controller’s possession.
ICO’s letter to Dr Neil Bhatia

There are two problems with the ICO’s statement — both the first and last of these sentences. For the first, there is a growing academic consensus that you simply cannot pseudonymise data so that the individuals concerned cannot be re-identified.

On Friday, Professor Ross Anderson blogged in Light Blue Touchpaper and provided both audio and slides for a talk he gave at the Open Data Institute. The talk is titled ‘Why Anonymity Fails’. In the inference section he notes:

  • If you link episodes into longitudinal records, most patients can be re-identified
  • Add demographic, family data: worse still
  • Active attacks: worse still (Iceland example)
  • Social network stuff: worse still

[The 'Iceland example', incidentally, refers to the occasion in 1998 when DeCODE offered Iceland free IT systems in return for access to medical records. The funding came from the Big Pharma company, Roche.]

Now check the 33 Bits of Entropy blog operated by Arvind Narayanan (a Computer Science/CITP Assistant Professor at Princeton and affiliate scholar at Stanford Law School’s CIS):

The title refers to the fact that there are only 6.6 billion people in the world, so you only need 33 bits (more precisely, 32.6 bits) of information about a person to determine who they are.

…If your hometown has 100,000 people, then knowing your hometown gives me 16 bits of entropy about you, and only 17 bits remain.
About 33 Bits

It is clear that a determined adversary will be able to obtain the 33 necessary bits of entropy from within the pseudonymised data — but the ICO seems to ignore this as if simply labeling a dataset as pseudonymised actually makes it impossible to re-identify the subject.

And this, of course, is without marrying the health data to other easily obtainable databases — such as the edited version of the electoral register which includes details of everyone who hasn’t specifically opted out of being included. There are no restrictions on the use of this data.

The second problem with the ICO’s statement is that he talks about ‘other information’ actually in the data controller’s possession — nothing about the other data that the data controller could subsequently obtain. This means that an unscrupulous operator could easily obtain because he has no ‘other information’ and then later marry it with separately obtained other databases. He would then become subject to the Data Protection Act, but might no longer be within the ICO’s jurisdiction. Having got the data, he would have everything necessary to sell personal information to whoever would buy it.

The simple reality is that it is impossible to protect the anonymity of patient health data while retaining the value that the researchers (big pharma, insurance, credit companies etcetera) demand. With big business and David Cameron both singing from the same hymn sheet, may have been delayed, but it is a long way from being abandoned — particularly when we have an ICO more determined to apply his own interpretation of the law than protect the people.

Categories: All, Politics, Security Issues

If it’s not outright lies, it is downright deceit: the NHS and patient data

March 23, 2014 Leave a comment

I had to visit the hospital the other day. I’m not going to say why, because that’s private, personal and confidential. Suffice it to say that the condition isn’t one that I wouldn’t tell my mother; but it is one that I’d prefer potential employers and insurers know nothing about unless I tell them (it’s probably nothing anyway). I would most certainly not want the pharmaceutical industry to know — the drugs they offer make the (possible) condition much worse, and introduce new ones.

But I don’t need to worry, do I? At the bottom of the hospital appointment letter, in bold type, is the statement:

All personal information about you is kept confidential at all times and is only shared when necessary to support your care and treatment. If we want to use your information for any other purpose, with the exception of when the law requires us to do so, we will talk with you and obtain your consent. If you have any concerns regarding this, please talk to the person providing your care and treatment.
(see grammatical note at the end of this post)

But that’s a lie. While the government wants to start centralizing our GP records in the autumn, it is already doing so with HES (Hospital Episode Statistics). These are already held by the Health and Social Care Information Centre (HSCIC) which is where all of the records will eventually be held. According to the HSCIC website,

HES is a data warehouse containing details of all admissions, outpatient appointments and A&E attendances at NHS hospitals in England.

This data is collected during a patient’s time at hospital and is submitted to allow hospitals to be paid for the care they deliver. HES data is designed to enable secondary use, that is use for non-clinical purposes, of this administrative data.

It is a records-based system that covers all NHS trusts in England, including acute hospitals, primary care trusts and mental health trusts. HES information is stored as a large collection of separate records – one for each period of care – in a secure data warehouse.

We apply a strict statistical disclosure control in accordance with the HES protocol, to all published HES data. This suppresses small numbers to stop people identifying themselves and others, to ensure that patient confidentiality is maintained.

Compare the two statements. It is perfectly clear that the hospital is lying. But the reality is, so is HSCIC.

Back in 2012, the marketing firm PA Consulting bought a copy of the HES data.

So we bought the data and installed it (with certain security restrictions) on our own hardware… [But querying the data took too long.] The alternative was to upload it to the cloud using tools such as Google Storage and use BigQuery to extract data from it… Within two weeks of starting to use the Google tools we were able to produce interactive maps directly from HES queries in seconds.

(That document seems to have been removed from the PA site, or hidden away. Anyway, I can no longer find it, and have to rely on the copy I have. It seems to have been replaced by a press statement from PA here and another from HSCIC here in a coordinated release. Neither of these should satisfy any patient.)

Ask yourself this: how can maps be produced without location data? What is location data if it is not personal identification information? How can data be transferred to a third-party (Google cloud) and stay within the Data Protection Act. Remember that several different data protection regulators in various parts of Europe, including our own, have challenged Google over its privacy policy — and several have already fined Google the maximum possible for being in breach of European data protection laws.

The HES data sold by the government is pseudonymised — but still includes postcode and age (PA denies that it received DOB or address, but doesn’t specify whether that included ‘age’ and ‘postcode’). In other words, standard HES data specifies very clearly exactly who 98% of the patients actually are and where they live.

And then there’s Beacon Dodsworth, a firm that “provides geographical information system (GIS) mapping software and marketing technology to clients in a wide range of industries” including Estee Lauder, Trinity Mirror Group and Boots. It says

Hospital Episode Statistics (HES) have now been integrated with our P2 People & Places people classification thanks to some hard work from our clever developers.

This means you can now better understand the health needs of local communities and populations and identify trends and patterns in order to target health improvement more effectively.

So we seem to have a system that quite readily sells our hospital records to any marketing company that will pay for them, and then allows those marketing firms to advertise the ability to target us on the basis of our health. And at the same time, the NHS itself tells us something completely different: that the data is only seen by those involved in our treatment.

Now Ross Anderson, chair at the Foundation for Information Policy Research; Phil Booth, coordinator at medConfidential; and Nick Pickles, director at Big Brother Watch, have all filed a complaint with the ICO requesting that the issue be examined in relation to the Data Protection Act.

It will be interesting to see how the ICO can reconcile what to everyone else is a clear but hidden breach of confidential patient data — and the Data Protection Act — with this government’s desire to sell and share everything about us to anyone willing to pay for it, irrespective of our own wishes. Because the one thing we can be very sure about in all of this is that the ICO will do all he can to avoid doing anything at all.

grammatical note
The first sentence is a complete statement. The second sentence is also a complete sentence. There is nothing in the second sentence to indicate that it qualifies the first sentence. There is nothing in these two sentences from which a reasonable patient could infer that it really means, “We will not share your personal data with anyone other than the centralised government database operated by HSCIC, with whom we will always provide all of your details all of the time, and over which we have not the slightest control nor responsibility for your personal data.

Categories: All, Politics, Security Issues

What is the UK government doing in embedding Google Analytics into confidential government websites?

February 4, 2014 Leave a comment

Perhaps the biggest news today is that the NHS has been redirecting its web visitors to a site hosting malware. It’s OK, though, because the NHS hasn’t been hacked – it managed to endanger its users without any outside help from the bad guys.

The problem was a typo. One of its own developers input instead of A bad guy found this before the NHS found it. He registered and simply waited while the NHS thoughtfully sent its visitors along to be infected – and nobody knows how many may have been.

Typo found… problem solved… nothing to see here… move along please…

But it’s not a problem solved; it’s a problem found – and most of the press reports have missed it. Infosecurity Magazine (NHS Website Not Hacked, Just Exploited) did not miss it. The problem is this: what is the NHS doing using at all? The practice is, according to privacy expert Alexander Hanff, illegal under the EU’s ePrivacy directive.

Alex told me more. The law in question is specifically article 5.3 of the ePrivacy directive and the Privacy and Electronic Communications Regulations (PECR) – better known as the ‘cookie law'; and the biggest culprit is the UK’s own privacy regulator, the Information Commissioner’s Office. “The problem is,” Alex told me, “the ICO refuses to enforce PECR on the issue of 5.3 of the ePrivacy Directive (aka, the cookie law), despite the fact that ICO itself stated that the use of third-party analytics does not meet the requirement of strict necessity. This was before it did a complete 180 after Google reached a deal with the Department for Culture, Media & Sport (DCMS).”

Alex set about discovering more, and used the Freedom of Information Act to get to the bottom of why the ICO had changed its standpoint. If your blood pressure will take it, it is worth reading Who Regulates the Regulator? But be warned, you will indeed find that bureaucratic boilerplate:

Having considered all of these factors we have taken the decision that the public interest in withholding the information outweighs the public interest in disclosing it. Therefore in this instance we are unable to provide you with the correspondence in question.

To Alex, this just smacks of corruption. “The perpetual threesome between Big Data, ICO and the UK Government is an orgy of corruption which flies in the face of European Regulation and is one of the most significant illustrations of why the ICO should be disbanded and replaced with a regulator that is truly detached from government and industry.”

This is not actually an extreme position. Last week European justice commissioner Viviane Reding highlighted some of the things she would like to change, including to ‘correct’ the situation in Germany, where the minister of the interior can take disciplinary action against the data protection commissioner. “Is effective supervision really possible under these circumstances?” she asked.

Clearly the actual independence of the UK’s ICO from the UK government can also be questioned – and perhaps we should all hope that the Eye of Reding turns towards the UK. But in the meantime, I repeat my earlier question: What is the UK government doing in embedding Google Analytics into confidential government websites?

Categories: All, Politics, Security Issues

European regulators say Google is breaking European privacy laws

June 22, 2013 Leave a comment

You have to feel sorry for the ICO (Goodle): it’s in an invidious position. The overwhelming view of the Article 29 Working Party (ie, the collective representatives of all EU member states’ data protection regulators) is that Google is breaking European laws with its aggregated privacy policy.

Goodle (that is, the UK’s ICO) is friendly with Google. You can see that in its behaviour over Street View (the collection, inadvertent or otherwise, of personal wifi data while driving round the streets of the world). Germany fined Google over it. Goodle just said stop it, don’t do it again, and get rid of what you’ve got.

When Google didn’t get rid of it, Goodle had to get really tough, and say get rid of it now, because we really, really mean it this time!

But back to Article 29. Problematically, Goodle, it is one of six EU member states chosen to take enforcement action against Google. CNIL, the French regulator, has already completed its task. It has instructed Google in exactly what it must do to come into conformance with French laws. Google has three months to comply before CNIL levies a fine.

Spain is likely to be next. The Spanish regulator announced on Thursday that it has “found evidence of five serious privacy law breaches — each punishable with fines of up to 300,000 euros ($395,000).” (AFP) An enforcement notice with threats will likely follow shortly.

Germany is hardly likely to take a softer line – generally speaking it is tougher than most other EU nations on matters of personal privacy (some can remember Nazi Germany, and most can remember Stasi Germany).

Then we have Italy, the Netherlands, and of course Goodle. My bet is that Italy and the Netherlands do the same as France and Spain. But what then? What about the UK? What’s a good Goodle to do if all the other nations slap Google as hard as they can? It’s a difficult position for a loyal Google Poodle.

Categories: All, Politics, Security Issues

What does the ICO think about PRISM and the GDPR?

June 15, 2013 Leave a comment

I’ve never been convinced on the value of the UK’s data protection regulator, the ICO. There are numerous reasons for this. Firstly, the Data Protection Act is a law. Upholding the law is a job for the police and courts, not a government-controlled quango. Secondly, to uphold the law you need a grounding in the law: the ICO should be a lawyer not a marketer. And thirdly, the whole premise of the Data Protection Act is absurd. The way it is established means that proof of compliance is not getting hacked, while proof of non-compliance is getting hacked. And getting hacked is a lottery that has little relationship to security spend.

But I think I lost all respect when the ICO published an ‘independent’ report on the GDPR last month. It was undertaken by London Economics and is reliant on statistics (a survey of 506 data protection professionals working in UK companies). Statistics always reflect the bias of the author, so they’re always pretty meaningless. But that’s not the issue. It was what the ICO said about it:

Today’s report is the latest contribution from the ICO to this debate. We’d urge the European Commission to take on board what it says, and to refocus on the importance of developing legislation that delivers real protections for consumers without damaging business or hobbling regulators.

This is gobbledygook. ‘Without damaging business or hobbling regulators’ is rather confused since it is protecting business that hobbles regulators. He claims to want ‘real protections for consumers’ when what he is advocating limits the genuinely real protections for consumers proposed by the EC.

But above all, what is the Information Commissioner doing in advocating for business rights? His mission, in his own words, “is to uphold information rights in the public interest.” Yet here he is trying to uphold business rights to the detriment of the public interest. Lobbying against the GDPR on behalf of business is none of his concern, and a betrayal of the people he is supposed to protect.

He is, however, toeing the UK government line; which in turn is toeing the US government and US corporate line. PRISM shows us that the US government cannot be trusted with our personal data. GCHQ’s involvement with PRISM and the MPs’ call to get the Snoopers’ Charter back on course show that UK politicians cannot be trusted with our personal data.

And where is the ICO on PRISM? God knows. He has published no statement, and posted no blog on the subject. Instead, he is lobbying on behalf of business to make the transfer of our personal data (via Google, Facebook, Microsoft et al) to the NSA all the easier.

It’s time for the ICO to be abolished and replaced by something more meaningful, and someone more willing to fight for the people rather than lobby for business at the behest of government.

Categories: All, Politics, Security Issues

EU compliance – why bother?

February 12, 2013 1 comment

Compliance – at least European regulatory compliance – bothers me. Whenever I speak to a security expert, those concerns are allayed for just so long as we talk; and then they come back again.

The problem is that Europe passes principle-based legislation (the US is more likely to pass rule-based legislation). The former tells you what must be achieved (the principle), while the latter tells you how it must be done (the rules).

The European Data Protection Directive is a perfect example of principle-based legislation. It says that personal information must be held securely; but it doesn’t tell you how it should be done.

Here’s my problem. Data that hasn’t been lost or stolen has, de facto, been held securely and the company is in compliance – even if it spends nothing on compliance. Data that has been lost or stolen has not, de jure, been held securely and the company fails compliance even if it has spent many ££millions on compliance. The existence or lack of infosecurity defences is irrelevant: if you lose that data, then you are in breach of the act; if you do not lose the data then you are not in breach of the act.

I’m not interested in claims that proof you spent money on security will make the ICO (a marketing man, mark you – not a lawyer) go easy on you. That’s just marketing dross to hide the underlying contradiction.

What I want to know is quite simple. How can it possibly be right to frame a law that states someone who tries to comply can fail compliance, while someone who ignores compliance can be compliant? The result is that there is no logical reason to spend money on securing personal data – just hope you don’t get hacked. This is aggravated by the common and growing perception that if you get targeted, you will get breached. So if you get targeted, you will have failed compliance whether you try to comply or not. Why bother?

Categories: All, Politics, Security Issues

The ICO, Google and the need for a new pit bull approach to privacy

July 29, 2012 1 comment

Have I mentioned that the ICO is a waste of both space and money? Well, if you ever doubted me, doubt no more. It has been treated with utter contempt by Google, and there’s not a damn thing it can do.

Do you remember Spy-Fi, when Google engaged in its very own version of drive-by downloading? Well the ICO said, “No! Stop it. Don’t do it again. And delete what you’ve got.” And Google said, ever-so politely, yes sir – we will. Only it didn’t. “Google has recently confirmed that it still has in its possession a small portion of payload data collected by our Street View vehicles in the UK.” It says it was an error and will work with the ICO to remedy the situation.

But how does the ICO know? How does the ICO know what Google has done with that payload data, what it may do with that payload data, or how many copies of that payload exist in what parts of Google’s vast and nebulous cloud? It wrote back, even more politely, asking for Google to store the data securely for examination before being told what to do with it.

But how does the ICO know, and what can it do? Nothing, except take the word of big business.

Nick Pickles, director of privacy and civil liberties group Big Brother Watch, has no doubt on what should happen:

The Information Commissioner is hampered by a woeful lack of powers and is forced to trust organisations to tell the truth. Given Google’s behaviour has called into question if that really is a proper way to protect our personal data, it must be right to now demand a proper regulator with the powers and punishments to fully protect British people’s privacy.

It’s time to get rid of the self-congratulatory lap dog and replace it with an angry pit bull.

Categories: All, Politics, Security Issues

The ICO contemplates his navel and likes what he sees

July 8, 2012 1 comment

Anyone who heard Christopher Graham launching the ICO’s annual report last week must wonder just how many planets there are in this solar system. In his own words:

…the ICO is well up to the task.

…the ICO has bared its teeth…

It’s a case of ‘wake up and smell the CMP!’

…the regulator is getting results.

This reads like a marketing department bigging-up a poor product. The simple fact is, based on irrefutable empirical evidence, the ICO is failing: corporate and government loss of personal data is certainly not diminishing. Graham is wrong.

But there are two things in his speech that I particularly wish to consider. At one point he says:

The ICO has received precious little credit for having been the first to blow the whistle on Fleet Street practices in our 2006 publications ‘What Price Privacy?’ and ‘What Price Privacy Now?’… Meanwhile, we have been facilitating ‘fast track’ subject access from the so-called Motorman Files for any concerned citizen…

Compare this view of the ICO with that of its own Motorman investigator at the time, Alexander Owens:

“Despite our protests we were told this was the decision of Richard Thomas [then IC] and that he would deal with the press involvement by way of the Press Complaints Council. It was at this moment we knew no journalist could or ever would be prosecuted in relation to our investigation.”
Something rotten in the state of the Information Commissioner’s Office – will Leveson act?

The reason the ICO got precious little credit is because it deserves none whatsoever – in fact, on the basis of this testimony, it was effectively complicit in what amounts to a cover-up.

My second concern is over the Information Commissioner’s closing comments. Specifically, he said:

Well, the ICO can expect to remain in the news as we engage with two further Government initiatives on the information rights agenda – the Draft Communications Data Bill and the drive for Open Data. We are working to ensure necessary limitations and safeguards for personal information and we want to enable appropriate data sharing and encourage openness provided it complies with the law.

Could somebody please tell me what this means? I want to ‘safeguard’ personal information provided it complies with the law? I want to ‘enable appropriate data sharing’ that complies with the law? The law is whatever the government makes the law. The government is in the process of making a new communications law that will give them huge volumes of our personal data. But that’s alright because our privacy protector will make sure that government complies with the law that it makes.

What a waste of time. What a waste of space. What a waste of taxpayers’ money.

Categories: All, Politics

Tango down the Ministry of Justice – ICO next?

June 5, 2012 Leave a comment

It was bank holiday Monday yesterday, so I didn’t spend all day in front of the computer. But I got a file from the Ministry of Lulz – it was the TangoDown graphic.

When and why, I asked; and was pointed at Saturday’s Anonymous message of support for Julian Assange.

I also received a copy of legal counsel concerning the Information Commissioner – so I started work on an article.

But it was bank holiday Monday; so I didn’t rush – and got overtaken by events. In the early evening I got another message from the Ministry of Lulz: ‘ is down for last 2 hours’.

So in some senses my draft story became irrelevant – but I’m pasting it below anyway. Now, however, it is an explanation for downing the Ministry of Justice – and perhaps a warning for the Information Commissioner. Here it is…

The voice behind The Ministry of Lulz is Winston Smith (named after the hero of Orwell’s 1984). The problem with this association is that the fictional Winston Smith was lured into joining a secret organization determined to bring down the Big Brother government. That secret organization clearly translates to Anonymous. But the fictional recruiter (O’Brien in the novel) turns out to be a government agent (Fed) – and Smith is betrayed. In real life, Smith was ‘recruited’ into Anonymous by ‘XX’. Smith must hope that life doesn’t mirror fiction too closely.

The Ministry of Lulz would appear to have two immediate targets in the UK: the Ministry of Justice and the Information Commissioner. Smith sent me a ‘TangoDown’ graphic. It names ‘’. Asked why, he pointed to the Anonymous video that was posted to YouTube on Saturday. It’s a message of solidarity with Julian Assange following the failure of his High Court plea to prevent extradition to Sweden – from where, suggests Anonymous, there is little doubt that he will rapidly be extradited to the USA.

This second extradition would seem particularly likely following the recent publication of Parmy Olson’s new book, ‘We are Anonymous’. A small section of this book is reproduced on John Young’s Cryptome site (it seems to be the subject of a takedown notice from the DtecNet Anti-Piracy Team but was still available at the time of writing this). In this book, Olson (the London bureau chief for Forbes) states very clearly that “Assange and q appeared to want LulzSec to try to grab the e-mail service of government sites, then look for evidence of corruption or at least evidence that the government was targeting WikiLeaks.” While proof of nothing, especially since FBI-informant Sabu was involved, the suggestion of involvement in a conspiracy to attack government sites merely makes the probability of extradition from Sweden to the USA more likely.

With the tango down graphic I also received copy of a legal opinion on the ICO. The UK’s Information Commissioner’s Office is likely to be targeted for what the Ministry of Lulz considers to be corruption. The legal opinion related to a case where personal medical records were passed to the subject’s (now ex) wife’s solicitors without his permission. The subject also claimed they were incorrect. He complained to the GMC, who ruled that his GP’s action had ‘fallen below the standards expected from a medical practitioner in processing and disclosing information.’ He then complained to the Information Commissioner who rejected his complaint, ruling amongst other things that the accuracy of personal information is not an issue if he (the IC) considers it to be lawfully disclosed. Consider that for a moment: if disclosure is allowed, you can spread lies without hinderance from the ICO.

The subject then took legal counsel (which is what was sent to me). Counsel concludes that “there is a 60-65% prospect of success in an application for permission to apply for judicial review against the IC…” It goes on to say that “the IC is interpreting the justification provisions in the [DPA] 1998 very widely and in a way which is not compatible with guidance and codes from professional organisations such as the GMC and also not in tune with comments from the courts,” and that “issues of wider public interest are raised by the case, namely the correct scope of the justifications in s35 DPA 1998 and the schedules to the Act, especially when seen in the light of the right to respect for private life in Art 8 ECHR.”

That, perhaps, is what you get when you put a marketing man rather than a legal man in charge of the ICO. But given the experience of the Ministry of Justice yesterday, he should look to his defences for the future.

Categories: All, Politics, Security Issues

Keynote sessions from Infosecurity Europe 2012 – and a few other stories

April 29, 2012 Leave a comment

Infosecurity Europe is over for another year. If you weren’t there, well I just suggest you make sure you get there next year. Meantime, here’s my take on a couple of the announcements and almost all of the keynote sessions:

Infosecurity Europe 2012: Minister of State for Universities and Science introduces the 2012 security breaches survey
The challenge, says the Rt Hon David Willetts, is that in order to get the economic and social benefits that the internet offers, we need to first tackle cyber security.
24 April 2012

PwC and Infosecurity Europe release the latest Information Security Breaches Survey
Significant attacks more than double, but one-in five companies still spend less than one percent of their IT budget on security, and more than half of small organizations do no security training at all.
24 April 2012

Russian cybercrime: what Russia is doing, and what it should be doing
Russian security company Group-IB says Russian cybercriminals made £2.3b in 2011; Russian-speaking cybercriminals made more than $4b; and worldwide, cybercriminals made more than $12.5b.
24 April 2012

Trustworthy Internet Movement Launches Pulse Tracker
The problem, says Pulse, is that we are telling users that this site has SSL, so it’s secure. That’s not necessarily true. We are promulgating a false sense of security, and we need to fix that.
25 April 2012

Infosecurity Europe 2012: defining risk management in the context of information security
The three companies represented on the keynote panel (G4S Secure Solutions, Steria UK, and Skipton Building Society) are very different; and their CISOs have very different views on the functioning of risk management within infosec.
25 April 2012

Infosecurity Europe 2012: the rising role of the CISO
Chaired by Quocirca’s Bob Tarzey, Network Rail’s CISO Peter Gibbons and Yell’s CISO Phil Cracknell led a lively discussion on the current and future role of the CISO.
25 April 2012

Ipswitch survey reveals the extent to which IT is losing control over data
IT needs governance; but users are choosing simplicity. In choosing and using their own non-sanctioned methods for data transfer, users are causing IT to lose control over its own data.
25 April 2012

Infosecurity Europe 2012: AET & APT – Is this the next-generation attack?
Advanced persistent threats (APT) and advanced evasive techniques (AET): what are they, who’s doing them, and what can we do about them?
26 April 2012

Has the time come to dump anti-virus?
Bit-9 asks the question that dare not be spoken: is anti-virus beyond its sell-by date? And is BYOD the final straw?
26 April 2012

Infosecurity Europe 2012: The ICO on better regulation and better infosec
Christopher Graham, the UK Information Commissioner, talks about his role as an information regulator and facilitator at Infosecurity Europe in London
26 April 2012

Infosecurity Europe 2012: Are we smart enough to secure smartphones?
Three heads of security from three very different organizations came together to discuss their practical and very different experiences in introducing a company BYOD strategy.
26 April 2012

Infosecurity Europe 2012: The insider threat – is it real?
While the primary security stance faces outwards and is designed to keep hackers and malware outside of the system, organizations are increasingly aware that their own staff are also a potential – and in some cases an active – threat.
27 April 2012

Infosecurity Europe 2012: The cloud – do you really know what you’re getting in to?
The cloud is new; but it’s been around for years. It’s insecure; but more secure than we fear. Two practitioners discussed the cloud of FUD.
27 April 2012

It’s the lack of understanding of virtualization that makes security an issue
A new study from Kaspersky Lab confirms an earlier one from Crossbeam Systems: it’s a lack of knowledge about virtualization that leads to fear for its security.
26 April 2012

Categories: All, Security News

Get every new post delivered to your Inbox.

Join 138 other followers