Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - NAO Report Criticises UK Govt. Data Security
News & Analysis

NAO Report Criticises UK Govt. Data Security

ISBuzz TeamBy ISBuzz TeamSeptember 15, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Majority of Gamers Lack Confidence in Developers
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The National Audit Office has issued a report criticising the UK government’s approach to cyber security. The report says that the GCHQ dealt with 200 “cyber national security incidents” per month in 2015 and that there were 8,995 data breaches in the 17 largest government departments in 2014/15. This news comes just ahead of the UK government launching the National Cyber Security Centre next month.

IT Security Experts from Digital Guardian, WhiteHat Security, Barracuda Networks, Veracode and Ipswitch commented below.

Luke Brown, VP and GM EMEA, India and LatAm at Digital Guardian:

Luke Brown“Public and private organisations alike have a duty of care, not to mention legal obligation, to protect data. It doesn’t matter if the contents of that data are good, bad or ugly. If you store it, you have to look after it. A simple mistake in handling citizen’s private information could have life-altering effects for those caught in the middle.”

.

Ryan O’Leary, VP Threat Research Centre at WhiteHat Security:

Ryan O’Leary

“It is a step in the right direction for the UK government to invest more money in cyber defence by launching the National Cyber Security Centre. In our experience, money is always better spent in the defence of future attacks rather than in trying to find and abolish the culprits. The issue is not the attackers – they are always going to exist – it’s the system that is susceptible to the attack. Fix the issue and your attacker problem goes away.”

Wieland Alge, VP & GM EMEA at Barracuda Networks:

wieland-Alge“It’s interesting that we see many of these damning cyber crime assessments, and yet both the public and private sectors are still not taking the necessary actions to protect themselves and their customers. Many are still ignorant to the fact that everyone has become a target and an astonishing number are surprised that they have been attacked at all.

“That said, modern cyber threats are no longer simple to defend against. The crucial change in recent years has been that cyber criminals are shifting towards more targeted scams and more advanced malware that cannot be detected by traditional scanners. What’s more, the increase in mobility and sheer volume of devices has exponentially increased the potential attack surface. We are in a kind of golden age for digital crime. The business has injected change at accelerating speed into all elements of IT and many organisations are simply trying to keep their security stable. It has become quite easy for attackers to find an unprotected door.”

Paul Farrington, Manager of EMEA Solution Architects at Veracode:

 “Coordination is key to improving the government’s “dysfunctional” approach to data security. One way of doing this in in clarifying the remit of the Chief Security Officer. Government departments are unlikely to want to have their delivery agendas interfered with by a Cyber Czar, who may not be perceived as holding political influence. As such, there probably needs to be a financial incentive in terms of budget release for departments to play ball with any Security Officer. That ultimately means that Key Performance Indicators will need to be established to help drive incremental improvement and coherence across Whitehall.

“It’s unlikely that a single initiative can address all the known security problems highlighted by the report. However, it is clear that Britain continues to be weakened by security breaches: citizens lives are impacted and, in some cases, put at risk, when a breach occurs; government and businesses suffer when valuable secrets are stolen and given to outside interests. It is essential that the execution of the government’s security policy begins to match the political rhetoric. A willingness to change is essential and, while securing government may seem an unsurmountable task for some, engaging with the soon-to-be-opened National Cyber Security Centre will be just one way that government departments will be able to call upon expertise in this area. “

Michael Hack, SVP of EMEA Operations at Ipswitch:

Michael Hack“Whilst rules on data protection, privacy and sharing have been in a state of flux in the last year, that’s absolutely no excuse for poor data security policies, procedure and practice in any organisation. Requirements for new data regulation, the GDPR (set to come in to force in May next year) have been very well documented and publicised. Data breaches will need to be reported without undue delay and within 72 hours of becoming aware of it.

“Public bodies strive to be in the headlines for setting standards and best practice, not for failing in their data security responsibilities.  Many have invested already in bolstering their IT security and data sharing processes. Government now needs to introduce a cohesive risk management exercise that identifies the key processes and assets, and evaluates their vulnerabilities and potential threats. The results will then highlight priorities for the next stage of the process. The exercise should cover all areas of public sector and should also consider technologies and strategies to mitigate the risks identified.

“Public sector organisations must ensure they have the right file transfer technologies, security systems, processes, and most importantly, staff training. By automating, managing and controlling all file transfers from a central point of control, staff are able to easily send and share files using approved secure methods and the IT department gains complete control over activity.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}