Build Scotland Construction Directory
Time and date
CONSTRUCTION DIRECTORY
Share this page
Construction News
25/10/2022

ICO: 'Complacency Greater Risk Than Hackers'

Construction News Image
The Information Commissioner's Office (ICO) has warned that complacency is a bigger risk than hackers as UK construction giant Interserve is issued a fine of £4.4 million following a data breach,

The ICO has warned that companies are leaving themselves open to cyber attack by ignoring crucial measures like updating software and training staff.

Berkshire-based construction company, Interserve Group, was fined for failing to keep personal information of its staff secure – a breach of data protection law.

The ICO found that the company failed to put appropriate security measures in place to prevent a cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details, as well as special category data including ethnic origin, religion, details of any disabilities, sexual orientation, and health information.

John Edwards, UK Information Commissioner, said: "The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company. If your business doesn't regularly monitor for suspicious activity in its systems and fails to act on warnings, or doesn't update software and fails to provide training to staff, you can expect a similar fine from my office.

-- Advertisement --
NorthernAsbestosServicesLtd

"Leaving the door open to cyber attackers is never acceptable, especially when dealing with people's most sensitive information. This data breach had the potential to cause real harm to Interserve's staff, as it left them vulnerable to the possibility of identity theft and financial fraud.

"Cyber attacks are a global concern, and businesses around the world need to take steps to guard against complacency. The ICO and NCSC already work together to offer advice and support to businesses, and this week I will be meeting with regulators from around the world, to work towards consistent international cyber guidance so that people's data is protected wherever a company is based."

• Details of the Interserve data breach

An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the Interserve's system, to another employee who opened it and downloaded its content. This resulted in the installation of malware onto the employee's workstation.

The company's anti-virus quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company's systems.

The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company's anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.

Interserve broke data protection law by failing to put appropriate technical and organisational measures in place to prevent the unauthorised access of people's information.

The ICO issued Interserve with a 'notice of intent' - a legal document that precedes a potential fine. The provisional fine amount was set at £4.4million. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Latest Construction News

22/11/2024

SP Energy Networks has announced a major investment in Britain's electricity grid, selecting 19 preferred partners to deliver a £5.4bn supply chain programme. This significant initiative aims to meet increasing energy demand and facilitate future growth. The selected companies, many of which are ...
22/11/2024

Edinburgh City Council has launched a 12-week public consultation on a new strategy to revitalise Princes Street and the wider Waverley Valley. The vision aims to create a more vibrant and welcoming city centre, attracting investment, supporting businesses, and enhancing the visitor ...
22/11/2024

Ener-G Services Limited, a leading UK electrical engineering company specialising in renewables, marine, and offshore sectors, has expanded its operations in Westhill, Aberdeenshire. The company has leased Unit 6E at Kingshill Commercial Park, a 2,500 sq ft space, on a 5-year lease. This new ...
22/11/2024

A consortium of leading scientists, industry experts, and academic institutions has joined forces to accelerate Scotland's offshore wind sector. The £2.5 million project, led by the University of Edinburgh in collaboration with the University of Dundee and the Forth and Tay Offshore cluster (FTO), ...
22/11/2024

The Port of Aberdeen and Turner & Townsend were highly commended in the 'Engineering, Construction & Infrastructure Project of the Year' category at the APM Project Management Awards 2024. The award recognises excellence in project management and the positive impact on end-users. The £420 million ...
22/11/2024

South Lanarkshire Council's £10 million fire safety improvement programme has reached a significant milestone, with CCG (Scotland) completing installations in over 1,700 high-rise residences across East Kilbride and Cambuslang. The Glasgow-based construction firm has been working closely with the ...
22/11/2024

SSEN Transmission, a key player in the UK's energy transition, is set to further expand its workforce and move into a new, sustainable office space in Glasgow. The company's commitment to net zero and the increasing demand for green energy workers has led to significant growth, with the number of ...
22/11/2024

Scottish Water is investing in the upgrade of its Loch Eck clean water plant in Dunoon. The project involves replacing outdated dry well pumps with new, more reliable pumps capable of operating in both wet and dry conditions. WGM Engineering, an RSK Group company, has been tasked with carrying out ...
22/11/2024

Scottish Land & Estates has expressed serious concerns over the Scottish Government's Land Reform Bill, particularly the provisions that would allow ministers to force landowners to sell large estates in lots. Sarah-Jane Laing, the organisation's chief executive, stated that while the land-based ...
22/11/2024

Clark Contracts employees have once again shown their commitment to community engagement by volunteering at Silverburn Park in Leven. On Thursday, 21st November, 16 members of the team spent their day planting over 400 trees and carrying out other landscaping tasks. This latest volunteering effort ...
Morris & Spottiswood LtdRBT Underfloor LimitedAC Cable Solutions24-7 HealthcareThe Scottish Natural Insulation HubPD ServicesMV CommercialACCON UK LtdToner Damp Proofing SuppliesNo Hydro
Terms and Conditions
2024/11/23 09:18:29