Norwich Union fined £1.26m after ID theft

FSA throws book at insurer for security failures

Written by Guy Dixon

Norwich Union Life has been fined £1.26m by the Financial Services Authority (FSA) for exposing customers to the risk of fraud.

The FSA fined the insurer for not having effective systems and controls in place to protect confidential customer information, and failure to manage its financial crime risks.

Norwich Union Life's failings allowed fraudsters to use publicly available information including names and dates of birth to impersonate customers and obtain sensitive details from the firm's call centres.

In some cases fraudsters were able to ask for confidential customer records to be altered, including addresses and bank account details, successfully requesting the surrender of 74 customers' policies totalling £3.3m in 2006.

The FSA ruled that Norwich Union Life had failed properly to assess the risks posed to its business by financial crime, including fraudsters looking to obtain confidential customer information.

"Norwich Union Life let down its customers by not taking reasonable steps to keep their personal and financial information safe and secure," said Margaret Cole, director of enforcement at the FSA.

"It is vital that firms have robust systems and controls in place to make sure that customer details do not fall into the wrong hands. Firms must also frequently review their controls to tackle the growing threat of identity theft.

"This fine is a clear message that the FSA takes information security seriously and requires that firms do so too."

Tags:

Further reading

Experts warns of Banker Trojan peril

Primary threat to online shoppers this Christmas   More...

Cyber-crooks gear up for ID bonanza

'Tis the season to be careful   More...

ICO calls for privacy impact assessments

Necessary to restore public confidence in data collection   More...

Security experts slam Soca job cuts

Greatly increased threat to UK business   More...

Related articles

Data breach bosses 'should go to jail'

It's the only way they'll listen to us, say security experts   More...

Security experts slam Soca job cuts

Greatly increased threat to UK business   More...

MoD launches inquiry into laptop theft

Parliamentary meeting reveals catalogue of errors   More...

Web scams trick one in five US surfers

Victims admit to compromising their own security   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement