Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Local Authorities Are Understaffed And Putting Information At Risk
Articles

Local Authorities Are Understaffed And Putting Information At Risk

ISBuzz TeamBy ISBuzz TeamDecember 20, 2016Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Local authorities face the challenging task of managing ever-growing volumes of records, covering anything from council taxes to confidential information about local schools. Furthermore, they must manage this data securely while dealing with the pressures of cutting costs and improving the overall efficiency of the services they provide to the public. If the protection of this information is not prioritised and is somehow compromised, severe financial penalties and reputational damage will soon follow.

In the UK, the 1998 Data Protection Act requires controllers of personal data to take appropriate measures to prevent data being “accidentally or deliberately compromised”. Some of these measures include having robust policies and procedures in place, and reliable, well-trained staff. If a local authority fails to comply with these measures and a serious data breach occurs, the organisation can face fines up to £500,000.

Despite the obvious risks and reputational damage caused by a breach, local authorities are simply struggling to find the time to manage and protect information properly. A recent study by Iron Mountain, The challenge of sharing information management in UK local authorities in 2016 and beyond highlights the challenges faced by records and information managers.

The study found that 57% of records and information managers have just a few seconds to handle every record they are responsible for and do not have enough staff to deal with day-to-day information management demands. Complicating the issue further is how leaders in other areas view the scale of the problem. According to our study, 50% of records and information managers believe the number of cases involving poor information management has gone up, while only 35% of leaders in other departments agree. There is also a lack of faith within local authorities about their organisation’s ability to manage large volumes of information securely and in accordance with data protection legislation. Approaching half (42%) of records and information managers and leaders in other departments don’t trust their colleagues to adhere to data protection legislation and/or don’t trust them to manage information securely (45%).

In the face of these problems, it is difficult to see what steps local authorities can take to get a better grip on information management. But there are steps they can take. Below are some recommendations on how our local authorities might address the complex information challenges they face.

Overcome cultural and communication barriers

Different working practices and styles mean that teams do not always share or store information across departments in a consistent way. Lowering cultural and cross-departmental barriers within a local authority could go a long way towards helping councils manage information more effectively.

Setting up steering committees can be a useful way to keep communication channels open and align different teams on problems and policies. Once established, steering committees can enable senior leaders and internal stakeholders to communicate regularly with one another about processes, discussing what works well and how to make future improvements.

 Educating staff on the latest data regulations

New data protection regulations are constantly on the horizon. One such is the GDPR, which is set to come into play in 2018 if Brexit does not disrupt current plans. It’s vital that everyone in the local authority is prepared and trained on how to meet data protection requirements. Educate staff so that they are up to date on the latest information management processes, correct procedures and best practice, as well as the potential consequences of mis-managing sensitive information. Every member of staff needs to acknowledge and own their role in helping to keep sensitive information secure, regardless of the time pressures they may be under.

 Balancing organisational pressures with data security

Outsourcing to a trusted third party can help free up time and resource. Secure storage and destruction are areas for consideration. A third party should be able to advise on retention schedules and have high-level security to help safeguard sensitive records, leaving information managers with less to worry about. This will allow them to focus on strategic operations that will deliver better services and value to the public, without compromising the integrity of the information for which they are responsible.

 Conclusion

 Avoiding data breaches is vital if local authorities are to inspire trust amongst the communities they serve. The good news is that there are actions information managers, senior leaders, and stakeholders within local authorities can take to help establish best practice that others can then follow.

Closer collaboration and better education in particular will help solve some of the complexities of information management within the organisation. Putting these measures in place will help everyone work towards one common goal – treating sensitive data with care, while using it to deliver a higher level of service to the local community.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}