You are here: silicon.com > Software > Security Strategy

Security Strategy

UK consumers demand data breach disclosure

Ready to vote with their feet - and credit cards

Tags: data loss, data breach

By Jo Best

Published: 17 April 2007 16:47 GMT

UK consumers are demanding companies that suffer data security breaches must let their customers know.

The majority of respondents to a survey carried out by Ipsos MORI for database security company Secerno felt institutions that have suffered a breach should inform customers automatically, with more than 82 per cent expecting to be informed of any data loss.

Consumers also believe time is of the essence when reporting data breaches, with 82 per cent expecting the institution suffering the breach to notify them immediately.

There's been a steady sensitisation of people's attitude to this sort of thing.

-- Paul Davie, CEO, Secerno

However, there remains a powerful disincentive for retailers and financial services companies to be more vocal: shoppers are also prepared to vote with their feet. Of the more than 1,200 adults questioned, 53 per cent said they would stop using the services of a company that admitted a breach.

Paul Davie, CEO of Secerno, told silicon.com: "Basically there's been a steady sensitisation of people's attitude to this sort of thing."

The survey comes in the wake of the world's largest data loss incident, which saw customers of TJX retail group - which owns the TK Maxx chain - warned to check their credit card statements to spot any unauthorised transactions.

The UK has also had its fair share of data breaches, including the theft of a laptop from Nationwide building society which contained some customer details.

Under UK law, retailers and other institutions that suffer data loss do not have to disclose the breach to customers, even those directly affected by the breach.

It's a very different picture in the US, where a piece of legislation called SB 1386 forces any company that has lost customers' data to make the loss public. Security experts have called for the UK to embrace a similar system.

Davie said: "The government has to become involved in the way it has in the US in requiring there is disclosure. If the senior management of companies know there are legal sanctions if they try to sweep breaches under the carpet, that will address their thinking and give them a better incentive to take the right security measures to make sure they don't appear on the morning news."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Product Manager

Huntress does not discriminate on the grounds of age, race, gender, disability, creed or sexual orientation and complies with all relevant UK ...

General Manager (Leeds)

Responsible for keeping up-to-date with the latest employment legislation as advised by our employment lawyer Ownership of employee staff manual, ...

Java (Server Side) Developer, London

My client is one of the most successful financial institutions in the world. Huntress does not discriminate on the grounds of age, race, gender, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: