+44 (0)203 88 020 88

Menu

Search

Cyber Security News & Articles

 

Cyber Security
News & Articles

Trusted Cyber Security Experts
25+ Years Industry Experience
Ethical, Professional & Pragmatic

BA record £183m fine for data breach

The record fine of £183,000,000 for a UK data breach signals a new era for the economics of information security.

The first fine issued by the UK’s Information Commissioners Office (ICO) under the GDPR regime is 367 times higher than the previous maximum fine levied against Facebook in the aftermath of the Cambridge Analytica scandal.

The fine relates to a breach of the British Airways website and mobile app which saw the payment card and personal details of over 380,000 people stolen during a 15 day period starting August 21st2018.

While BA has remained tight-lipped about how the breach happened, security research firm RiskIQ has published a detailed analysis which points the finger at the Magecart criminal gang.  According to the researchers, the criminals were able to insert a modified version of a standard Javascript library containing just 22 additional lines of code which then skimmed the payment card details in a formjacking  attack and sent the payment card and personal data to a server controlled by the criminals.

Alex Cruz, the chairman and CEO of British Airways, said he was “surprised and disappointed in this initial finding from the ICO. British Airways responded quickly to a criminal act to steal customers’ data.”

The response from BA’s CEO is revealing – his focus was not that a breach happened, but that he says the firm handled the management of the data breach well.

In contrast, Information Commissioner Elizabeth Denham said:

“…the law is clear – when you are entrusted with personal data, you must look after it. Those that don’t will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights.”

For many business leaders, it often looks cheaper to write a response plan to handle a data breach that they believe is unlikely to ever happen than it is to definitely spend a lot of money on equipment and staff to ensure a breach does not happen in the first place. The ICO’s comments make it clear that in the world of GDPR that cynical logic no longer holds true.  With the scale of fines available under GDPR being up to 4% of global turnover, regulators appear keen to send a message to businesses that it is going to be much more economical to prevent a data breach than it is to clean up after one happens and face huge fines.

The half million pound fine issued to Facebook after the Cambridge Analytica scandal was seen by many as being so low as to not affect corporate behaviour in any way – it was merely a cost of doing business. In the wake of the BA fine, it is now becoming clear that for many businesses it will make much more commercial sense to invest in their information security and be able to clearly demonstrate that they did all they could to prevent a data breach.

Many Information Security managers may well find it easier to gain boardroom support for their request for budget as the implications of the new regulatory regime sink in.

 

 

Subscribe to our monthly newsletter today

If you’d like to stay up-to-date with the latest cyber security news and articles from our technical team, you can sign up to our monthly newsletter. 

We hate spam as much as you do, so we promise not to bombard you with emails. We’ll send you a single, curated email each month that contains all of our cyber security news and articles for that month.

Why Choose SecureTeam?

CREST
CCS
ISO9001
ISO27001
CE-PLUS

Customer Testimonials

“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”

Aim Ltd Chief Technology Officer (CTO)

"Within a very tight timescale, SecureTeam managed to deliver a highly professional service efficiently. The team helped the process with regular updates and escalation where necessary. Would highly recommend"

IoT Solutions Group Limited Chief Technology Officer (CTO) & Founder

“First class service as ever. We learn something new each year! Thank you to all your team.”

Royal Haskoning DHV Service Delivery Manager

“We’ve worked with SecureTeam for a few years to conduct our testing. The team make it easy to deal with them; they are attentive and explain detailed reports in a jargon-free way that allows the less technical people to understand. I wouldn’t work with anyone else for our cyber security.”

Capital Asset Management Head of Operations

“SecureTeam provided Derbyshire's Education Data Hub with an approachable and professional service to ensure our schools were able to successfully certify for Cyber Essentials. The team provided a smooth end-to-end service and were always on hand to offer advice when necessary.”

Derbyshire County Council Team Manager Education Data Hub

“A very efficient, professional, and friendly delivery of our testing and the results. You delivered exactly what we asked for in the timeframe we needed it, while maintaining quality and integrity. A great job, done well.”

AMX Solutions IT Project Officer

“We were very pleased with the work and report provided. It was easy to translate the provided details into some actionable tasks on our end so that was great. We always appreciate the ongoing support.”

Innovez Ltd Support Officer

Get in touch today

If you’d like to see how SecureTeam can take your cybersecurity posture to the next level, we’d love to hear from you, learn about your requirements and then send you a free quotation for our services.

Our customers love our fast-turnaround, “no-nonsense” quotations – not to mention that we hate high-pressure sales tactics as much as you do.

We know that every organisation is unique, so our detailed scoping process ensures that we provide you with an accurate quotation for our services, which we trust you’ll find highly competitive.

Get in touch with us today and a member of our team will be in touch to provide you with a quotation. 

0

No products in the basket.

No products in the basket.