Wednesday, 18 November 2009

More Public Data Lost by the Council TUT TUT

What is the saying? “Trick me once, more fool you. Trick me twice, more fool me.” Something like that, anyway, and it sums up the latest Government-level debacle surrounding their foolhardy, gung-ho approach to safeguarding public information. On this occasion, it was a laptop computer containing personal information (names, addresses, birthdates and worse still, signatures) on 14,673 voters – gone missing from the St. Albans City and District Council Office. The official word is that there are “2 layers” of security inbetween a would-be identity thief and the precious data, but the Council does accept that a security breach would be possible.
When I read this news I almost checked the calendar to ensure it wasn’t April 1st again. I mean, come on. Apparently unencryped public information stored on a laptop? It beggars belief. Do these people not realise that this is totally unnecessary? What about using a thin client setup whereby the laptop logs on to the Terminal Server, via an encrypted VPN (ideally using L2TP for maximum security) to access the information? This way, if the laptop was stolen all that would be lost would be the hardware itself!
If I was the IT Manager in this case I would expect to be sacked. To be caught out in such a basic way as this, when there are technical solutions out there that would avoid them altogether, has to be the IT equivalent of “Murder Most Foul” and the responsible should be punished accordingly. In severe cases like this, they should be made to run Windows Vista for all eternity on a machine with 512MB RAM! Actually, that may be too inhumane a punishment! 
At Nemark, we care about Data Security and offer IT Security Checks on your servers, laptops, webspace and the like. Our staff carry laptops, but we are not like the government, we keep all our data locked away, we don’t even allow client’s into our IT Support Centre’s so they cannot read other client screens!
I think the below picture says it all!

IT, Support, Security, Leeds, Sheffield, Doncaster, Rotherham
Maybe the Government should use this method of data security!

No comments:

Post a Comment