Human cost of PSNI data breach laid bare in official review The Register

An official review of the Police Service of Northern Ireland's August data breach has revealed the full extent of the impact on staff.
The review lays bare the broad impact on staff in Northern Ireland, detailing how various officers have been forced to relocate out of fear for their safety.
Staff safety was one of the primary concerns when the breach was first disclosed, given that the identities of every serving PSNI officer were leaked online for more than two hours.
The Northern Irish police force considers itself particularly vulnerable to disclosure issues, and usually identities of its police officers are closely guarded due to the ethno-nationalist conflict that has raged on the island of Ireland for decades.
At the time of the data breach disclosure, the PSNI said no staff members were being relocated, but the review revealed that one officer decided to relocate themselves and their family out of concern for their safety.
The following months saw an undisclosed number of officers also decide to relocate for the same reason.
Staff well-being services are currently stretched with the number of officers seeking support as a result of a force-wide decline in mental health.
A number of officers also reportedly sought PSNI support with name changes but were told this was an unnecessary step.
A single resignation was issued in relation to the breach, though it's not understood if this references the resignation of former police chief Simon Byrne or another officer.
The review highlighted that despite the significant impact the incident has had on the force, staff responses to it were varied.
More than 4,000 staff members contacted the threat assessment group assembled by the PSNI for support and information.
A similar number are thought to be part of a complaint issued to the Information Commissioner's Office and a civil case against the force.
Operational impact on the PSNI is also thought to be significant, with costs expected to be in the region of £24-37 million - a sum the PSNI could not afford due to other financial constraints.
The review highlighted a litany of issues surrounding the force's approach to data protection and the Northern Ireland Police Board's role in holding the PSNI's chief constable to account for the delivery of its services.
A number of audits have been ordered to investigate information security and data protection controls, but some have been delayed or canceled, and the scope of the audits has been limited.
Those that have taken place have found adequate assurances in these areas, though the ICO's audit, carried out separately, suggested there was a lack of oversight within the organization as regards data protection.
Another UK public sector data blab, this time info of pregnant women, cancer patients Home of the world's longest pleasure pier joins public sector leak club Irish cops data debacle exposes half a million motorist records Northern Ireland's top cop quits after security breach, disciplinary controversy.
DPIAs were highlighted by the ICO as an area in need of attention, especially given the police's arsenal of intrusive tools, such as automatic number plate recognition, bulk and sensitive information sharing, facial recognition, internet search tools, and algorithmic risk assessment tools.
Among the various recommendations made to the PSNI to improve its data protection, the embedding of DPIAs within projects was highlighted as a key measure that must be taken.
The Data Protection Act 2018 also mandated the creation of a data protection officer within organizations, but the establishment of this role within the PSNI has been delayed through periods of having an interim DPO and no DPO at all.


This Cyber News was published on go.theregister.com. Publication date: Tue, 12 Dec 2023 14:13:10 +0000


Cyber News related to Human cost of PSNI data breach laid bare in official review The Register

Human cost of PSNI data breach laid bare in official review The Register - An official review of the Police Service of Northern Ireland's August data breach has revealed the full extent of the impact on staff. The review lays bare the broad impact on staff in Northern Ireland, detailing how various officers have been forced ...
6 months ago Go.theregister.com
Human cost of PSNI data breach laid bare in official review The Register - An official review of the Police Service of Northern Ireland's August data breach has revealed the full extent of the impact on staff. The review lays bare the broad impact on staff in Northern Ireland, detailing how various officers have been forced ...
6 months ago Packetstormsecurity.com
Widespread Security Flaws Blamed for PSNI Data Breach - In August 2023, the Police Service of Northern Ireland suffered from a cyber incident that resulted in 9483 police officers and civilian staff having their personal data exposed. The breach occurred following the accidental release of data within an ...
6 months ago Infosecurity-magazine.com
Tech Security Year in Review - In this Tech Security Year in Review for 2023, let's look into the top data breaches of the past year. Each factor contributes to the growing threatscape, demanding a proactive and adaptable cybersecurity approach to safeguard your organization ...
6 months ago Securityboulevard.com
The Kubernetes Cost Features You Need in 2024 - In the rapidly evolving Kubernetes ecosystem, managing costs effectively is as critical as ensuring operational efficiency. To make the most of your shift to cloud native technologies in 2024, you need a roadmap to Kubernetes cost optimization, ...
5 months ago Securityboulevard.com
Data Breach Response: A Step-by-Step Guide - In today's interconnected world, organizations must be prepared to respond swiftly and effectively in the face of a data breach. To navigate these challenges, a well-defined and comprehensive data breach response plan is essential. Let's explore the ...
4 months ago Securityzap.com
Goto Customers Backup Data Breach: Protect Your Business and Handle Data Breach Risks - A data breach at Goto customers exposed their backup data to malicious actors, leading to a data breach that impacted those customers. Businesses need to be aware of the risks associated with data breaches and how to protect their organisations from ...
1 year ago Securityaffairs.com
Welltok data breach exposes data of 8.5 million US patients - Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. Welltok works with health service ...
7 months ago Bleepingcomputer.com
How Can Data Breach Be A Trouble For Your Industry? - To navigate an era of cyber risks, this unsettling reality necessitates a renewed focus on data integrity protection and digital asset protection. In this blog, we will discuss a data breach in the Hospitality industry. Some of the companies like MGM ...
5 months ago Securityboulevard.com
CVE-2013-0135 - Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) ...
6 years ago
WebTPA data breach impacts 2.4 million insurance policyholders - The WebTPA Employer Services data breach disclosed earlier this month is impacting close to 2.5 million individuals, the U.S. Department of Health and Human Services notes. Some of the impacted people are customers at large insurance companies such ...
1 month ago Bleepingcomputer.com
23andMe failed to detect mega-breach attackers for 5 months The Register - Biotech and DNA-collection biz 23andMe, the one that blamed its own customers for the October mega-breach, just admitted it failed to detect any malicious activity for the entire five months attackers were breaking into user accounts. In a collection ...
5 months ago Go.theregister.com
Dakota Eye Institute Files Notice of Data Breach Affecting More Than 107k Individuals - On October 23, 2023, the Dakota Eye Institute filed a notice of data breach with the U.S. Department of Health and Human Services Office for Civil Rights after discovering that patients' personal information was compromised following a cyberattack. ...
7 months ago Jdsupra.com
9 Best DDoS Protection Service Providers for 2024 - eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More. One of the most powerful defenses an organization can employ against distributed ...
6 months ago Esecurityplanet.com
AvidXchange Notifies Consumers of Data Breach Following Period of Unauthorized Access - On October 13, 2023, AvidXchange, Inc. filed a notice of data breach with the Attorney General of Massachusetts after discovering that a recent cybersecurity event resulted in an unauthorized party being able to access the company's IT network. In ...
7 months ago Jdsupra.com
Welltok Data Breach: 8.5M US Patients' Information Exposed - In a recent cybersecurity incident, Welltok, a leading healthcare Software as a Service provider, reported unauthorized access to its MOVEit Transfer server, affecting the personal information of approximately 8.5 million patients in the United ...
6 months ago Securityboulevard.com
Decoding the data dilemma: Strategies for effective data deletion in the age of AI - Businesses today have a tremendous opportunity to use data in new ways, but they must also look at what data they keep and how they use it to avoid potential legal issues. Forrester predicts a doubling of unstructured data in 2024, driven in part by ...
3 months ago Venturebeat.com
Fellowship Village Files Notice of Data Breach with the Federal Government - On October 8, 2023, Fellowship Village filed a notice of data breach with the U.S. Department of Health and Human Services Office for Civil Rights after discovering that there was unauthorized access to the company's computer network. In this notice, ...
7 months ago Jdsupra.com
CVE-2017-17713 - Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp ...
6 years ago
CVE-2017-17714 - Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, ...
6 years ago
Akumin Files Notice of Data Breach with the Securities and Exchange Commission - On October 16, 2023, Akumin Inc. filed a notice of data breach with the Securities and Exchange Commission after discovering that it had been the recent victim of a ransomware attack. In this notice, Akumin explains that the incident resulted in an ...
7 months ago Jdsupra.com
Infosys McCamish Systems data breach impacted over 6M people - MUST READ. Infosys McCamish Systems data breach impacted over 6 million people. Keytronic confirms data breach after ransomware attack. City of Cleveland still working to fully restore systems impacted by a cyber attack. ABN Amro discloses data ...
3 days ago Securityaffairs.com
Forward Bank Notifies 46,019 Customers of Recent Data Breach - On November 17, 2023, Forward Bank filed a notice of data breach with the Attorney General of Maine after discovering that an unauthorized party was able to access certain files on the company's computer network. In this notice, Forward Bank explains ...
7 months ago Jdsupra.com
Delta Dental says data breach exposed info of 7 million people - Delta Dental of California is warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. Delta Dental is a dental insurance provider that covers 85 million people ...
6 months ago Bleepingcomputer.com
Prestige Care Announces Data Breach Affecting an Unknown Number of Residents and Employees - On November 6, 2023, Prestige Care Inc. filed a notice of data breach with the U.S. Department of Health and Human Services Office for Civil Rights after discovering that an unauthorized party accessed the company's computer network. In this notice, ...
7 months ago Jdsupra.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)