<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: skipton]]></title>
    <link>http://securityratty.com/tag/skipton</link>
    <description></description>
    <pubDate>Fri, 04 Jan 2008 19:21:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Skipton Financial Services personal customer data on stolen laptop]]></title>
      <link>http://securityratty.com/article/c0527c011e51afeb9dc52bc4f5239096</link>
      <guid>http://securityratty.com/article/c0527c011e51afeb9dc52bc4f5239096</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/21/07 (backdated from writing of 1/4/08

Organization
Skipton Building Society

Contractor/Consultant/Branch
Skipton Financial Services (SFS
Moore...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sfs.jpg" align="right" height="72" width="153">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>12/21/07 (backdated from writing of 1/4/08)<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.skipton.co.uk/default.aspx" target="_blank"> Skipton Building Society</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.skiptonfs.co.uk/" target="_blank"> Skipton Financial Services (SFS)</a><br><a href="http://www.moorestephens.co.uk/" target="_blank"> Moore Stephens Consulting</a><br><br><span style="font-weight: bold;">Victims:</span><br>Skipton clients with money invested in the Fidelity FundsNetwork<br><br><span style="font-weight: bold;">Number Affected:</span><br>Up to 14,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, dates of birth, National Insurance numbers*, and fund investment details including how much was invested.<br><br><font size="1">*~equivalent to Social Security numbers in US</font><br><br><span style="font-weight: bold;">Breach Description:</span><br>A laptop computer was stolen from a locker being used by a Moore Stevens Consulting employee that contained sensitive personal information belonging to as many as 14,000 Skipton Financial Services (SFS) clients who had invested money in the Fidelity FundsNetwork.&nbsp; Moore Stevens Consulting was on contract with SFS at the time of the theft.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.yorkshirepost.co.uk/news/Computer-theft-puts-14000-at.3611872.jp" target="_blank"> Yorkshire Post Story</a> <br><a href="http://www.theregister.co.uk/2007/12/21/skipton_data_security_breach/" target="_blank"> The Register</a> <br><a href="http://attrition.org/dataloss/2007/12/skipton01.html" target="_blank"> Attrition.org Data Loss Archive</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Rowena Mason, Yorkshire Post via Attrition.org<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Up to 14,000 customers of the financial giant Skipton have been left open to identity fraud, after the company admitted that a laptop containing customers' personal details was stolen<br><br>Investors with money in the Fidelity FundsNetwork were told yesterday that the stolen information includes names, addresses, date of birth, National Insurance numbers, fund investment details – and even how much each person had invested.<br><br>the laptop was taken from a locker being used by a staff member of an information technology (IT) consultancy employed by Skipton Financial Services.<br><br>Moore Stephens Consulting was carrying out work on an IT system for the Yorkshire-based investment company when the theft took place<br><span style="font-style: italic;">[Evan] An IT consultant should know better than to store confidential information on a laptop without encryption.</span><br><br>Last night a Skipton spokesman stressed that the laptop was password-protected and all affected accounts with Skipton Financial Services had been immediately suspended.<br><span style="font-style: italic;">[Evan] Password protection is NOT adequate protection, and suspending the account does nothing to protect victims against identity theft.&nbsp; Does suspending the account provide any protection?</span><br><br>Managing director Simon Holt wrote to all 14,000 customers apologising for the breach of security and assuring them that an investigation had been launched.<br><br>Mr Holt yesterday denied that his company had any responsibility for the loss of the laptop and said every possible step had been taken to reduce risk to clients.<br><span style="font-style: italic;">[Evan] I respectfully disagree with Mr. Holt.&nbsp; Organizations must hold their vendors, consultants, and contractors to the same security standards as those used within the organization.&nbsp; Customers (data owners) gave Skipton the information and Skipton is responsible for it until it is destroyed.&nbsp; No passing the buck allowed.</span><br><br>Skipton Financial Services told their customers about the missing data after advice from the Information Commissioner's Office<br><br>The managing partner of Moore Stephens, Colin Moore, said his firm was doing everything it could to protect data and review security procedures.<br><span style="font-style: italic;">[Evan] Moore Stephens did not do "everything it could to protect data".</span><br><br>A helpline for people whose details might have been taken is open from 8am to 8pm Monday to Friday on 0800 137832.<br><br><span style="font-weight: bold;">Commentary:</span><br>More stolen laptops with confidential information without protection equals more victims.&nbsp; What torques me more about this breach is the fact that an IT consultant was partly to blame.&nbsp; An organization pays a consultant because they believe that the consultant is an expert and knows how to do work at a high-level.<br><br>I am a consultant and look, my laptop is encrypted... <img src="http://breachblog.com/emoticons/wink.png" border="0" /><br><br><img src="http://images.quickblogcast.com/95781-88451/psenc.jpg" border="0" width="509"><br><br>Organizations that employ consultants which access confidential information resources MUST ensure that the consultants follow proper information security policies and procedures.&nbsp; This is accomplished through the creation of a Vendor/Third-Party Security Policy, thorough evaluation before a contract is signed, adding information security language to the contract, and regular reviews of the consultant's information security practices throughout the life of the contract. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/21/sfs.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Fri, 04 Jan 2008 19:21:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skipton">skipton</category>
      <category domain="http://securityratty.com/tag/information includes names">information includes names</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security practices">information security practices</category>
      <category domain="http://securityratty.com/tag/skipton financial services">skipton financial services</category>
      <category domain="http://securityratty.com/tag/financial giant skipton">financial giant skipton</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/skipton spokesman">skipton spokesman</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://breachblog.com/2007/12/21/sfs.aspx">Skipton Financial Services personal customer data on stolen laptop</source>
    </item>
  </channel>
</rss>
