IT Systems and Data Protection

13.06.17

Council hit with £100,000 fine for data protection lapse

A council has this week been slapped with a £100,000 fine by the Information Commissioner’s Office (ICO) after a cyber-attack exposed sensitive personal information about its employees to hackers.

Over 30,000 emails were downloaded from mailboxes of people working for Gloucester City Council in July 2014, some containing financial and sensitive information about staff at the local authority.

The ICO also stated that the attack exploited the ‘Heartbleed’ software flaw, a security issue that allows individuals with the right know-how to access information being exchanged between individuals and some websites that were using a certain type of encryption software called OpenSSL.

This is despite the fact that the ICO sent explicit warnings to councils about the risk of ‘Heartbleed’ attacks around three years ago.

However, Gloucester City Council have told PSE that it is “very disappointed” by the decision by the ICO, and is considering its position whether to appeal the fine.

 “This was a serious oversight on the part of Gloucester City Council,” said Sally Anne Poole, group enforcement manager at the ICO.

“The attack happened when the organisation was outsourcing their IT systems,” she added. “A lack of oversight of this outsourcing, along with inadequate security measures on sensitive emails, left them vulnerable to an attack.”

Poole stated that the council should have known that in the wrong hands, this type of sensitive information could cause substantial distress to staff.

“Businesses and organisations must understand they need to do everything they can to keep people’s personal information safe and that includes being extra vigilant during periods of change or uncertainty,” she concluded.

Gloucester City council: fine will have detrimental impact on finances

But Jon McGinty, managing director of Gloucester City Council stated that the council did not agree with the decision, adding that the fine could have a detrimental impact on the authority’s finances.

“The council takes the security of its data very seriously and remains of the view that it did take swift and reasonable steps in 2014 to prevent a data breach as soon as it was alerted to the existence of this hacking vulnerability and the availability of a security patch,” he said.

“The Heartbleed vulnerability was a threat to businesses for some time before a patch was issued by software providers.”

“There is insufficient evidence to show that the hacking event took place after the council became aware of the existence of the potential vulnerability,” McGinty continued.

“The council believes that the penalty issued by the ICO will have a serious and detrimental impact on its finances, and the services that we will be able to provide to the residents of Gloucester in the future.

“The council has invested more than £1million over the past 3 years to further improve its IT security and remains vigilant to the threats that all businesses face on a daily basis.

“The council did account for the risk of this potential fine in its accounts for 2016-17 but nevertheless its payment will only result in money being taken away from the people of Gloucester and given to Treasury.”

Have you got a story to tell? Would you like to become a PSE columnist? If so, click here

Comments

There are no comments. Why not be the first?

Add your comment

public sector executive tv

more videos >

latest public sector news

Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

19/08/2020Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

Leeds City Council have today (August 19) announced that their plans for a Clean Air Zone within the city may not have to go ahead due to lower e... more >
Apprenticeships on the rise across London boroughs

19/08/2020Apprenticeships on the rise across London boroughs

According to recent statistics by London Councils, apprenticeships directly created by London boroughs are up 14% on the previous  year. ... more >
Colleges set to receive £200m in Funding

19/08/2020Colleges set to receive £200m in Funding

Over 180 colleges are set to receive a share of £200m, in order to repair and refurbish buildings and campuses. The funding makes up p... more >

editor's comment

25/10/2017Take a moment to celebrate

Devolution, restructuring and widespread service reform: from a journalist’s perspective, it’s never been a more exciting time to report on the public sector. That’s why I could not be more thrilled to be taking over the reins at PSE at this key juncture. There could not be a feature that more perfectly encapsulates this... read more >

last word

Prevention: Investing for the future

Prevention: Investing for the future

Rob Whiteman, CEO at the Chartered Institute of Public Finance (CIPFA), discusses the benefits of long-term preventative investment. Rising demand, reducing resource – this has been th... more > more last word articles >
Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

19/08/2020Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

Leeds City Council have today (August 19) announced that their plans for a Clean Air Zone within the city may not have to go ahead due to lower emissions during the lockdown period. The coun... more >
Apprenticeships on the rise across London boroughs

19/08/2020Apprenticeships on the rise across London boroughs

According to recent statistics by London Councils, apprenticeships directly created by London boroughs are up 14% on the previous  year. Between April 2019 and March 2020, London boroug... more >

the raven's daily blog

Cleaner, greener, safer media: Increased ROI, decreased carbon

23/06/2020Cleaner, greener, safer media: Increased ROI, decreased carbon

Evolution is crucial in any business and Public Sector Executive is no different. Long before Covid-19 even became a thought in the back of our minds, the team at PSE were looking at innovative ways to deliver its content to our audience in a more dynamic and responsive manner. We’re conscious to take the time to both prot... more >
read more blog posts from 'the raven' >

comment

Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Being on the receiving end of some “thanks” can make communit... more >
How community-led initiatives can help save the housing shortage

19/06/2019How community-led initiatives can help save the housing shortage

Tom Chance, director at the National Community Land Trust Network, argues that community-led initiatives are a productive way of helping to solve... more >
Aberdeen's green transport fleet attracting international attention

19/06/2019Aberdeen's green transport fleet attracting international attention

Aberdeen City Council’s hydrogen spokesperson, councillor Philip Bell, highlights the Granite City’s determination to play a leading ... more >
A fifth of public sector workers have never received a thank you from the people they serve

13/06/2019A fifth of public sector workers have never received a thank you from the people they serve

A fifth of the country’s public sector workers say they have NEVER received a ‘thank you’ for doing their job as Public Service... more >

interviews

Artificial intelligence: the devil is in the data

17/12/2018Artificial intelligence: the devil is in the data

It’s no secret that the public sector and its service providers need to invest in technology to help make better use of their resources. Bu... more >
Digital innovation in the public sector: The future is now

17/12/2018Digital innovation in the public sector: The future is now

One of the public sector’s key technology partners has recently welcomed a new member to its team. Matt Spencer, O2’s head of public ... more >
New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

05/11/2018New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

The new chief executive of one of the new unitary authorities in Dorset has outlined his approach to culture and work with employees, arguing tha... more >
Keeping the momentum of the Northern Powerhouse

15/10/2018Keeping the momentum of the Northern Powerhouse

On 6 September, the biggest decision-makers of the north joined forces to celebrate and debate how to drive innovation and improvement through th... more >

public sector focus

View all News