Picture of bank vault
Most people think the board would be responsbile for security breaches

IT professionals see need for data breach legislation

Companies should be obliged to report breaches, according to survey

Written by Tom Young

Legislation such as the California Breach Law in the US should be implemented to curb the leaking of data and ensure greater transparency in the advent of an information breach, research claims.

Some 79 per cent of respondents to a survey by security vendor WebSense believe new laws are a good idea, while 64 per cent think the board would be held ultimately responsible if an information leak occurs.

'This survey illustrates that companies are still so busy fire-fighting external security threats that when it comes to information leakage they are failing to address the larger problem,' said Ross Paul, international product manager at WebSense.

'A proactive approach, ensuring the enforcement of well-defined policies to protect sensitive information, is a must from stopping it getting into the wrong hands.'

Internal threats such as data leakage through malicious intent or by accident, continued are the greatest concern to respondents, topping the poll at 59 per cent, a 15 per cent increase on the same survey conducted last year.

Just 10 per cent of respondents think companies are taking proactive action to tackle the problem, while 26 per cent think information leaks could cost an organisation as much as two to five per cent of its annual revenue.

If a medium UK company with a turnover of approx £5.6m experienced an information breach, it could cost them up to approximately £280,000.

Fifteen per cent believe most companies have experienced some form of data leak in the past 12 months.

'When data breaches do occur, there is a consensus amongst respondents that legislation should support the need for disclosure,' said Paul. 'With only five per cent surveyed believing that all companies are aware of information leakage incidents, it’s time for companies to actively take responsibility in detecting and protecting against this invisible threat.'

Further reading

Identity breach risk accelerates

Flaws in identity management have huge impact   More...

Indian data breach hits HSBC

Insider fraud at HSBC’s Indian site underscores the need for security that extends to offshore locations   More...

Nationwide under fire for customer data loss

£75 spent on encryption software could have averted the blunder   More...

Related articles

Public demands data breach legislation

Overwhelming majority would want to know if their details were lost or stolen   More...

Data breach bosses 'should go to jail'

It's the only way they'll listen to us, say security experts   More...

Marketing firms routinely losing customer data

Security firms slam cavalier attitude   More...

IT directors call for mandatory data breach disclosure

Insider threats taken to the top of security agendas   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement