{"id":32159,"date":"2017-06-16T01:40:46","date_gmt":"2017-06-16T05:40:46","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/data-protection-fine-shows-security-risks-from-using-open-source-out-law-com.php"},"modified":"2017-06-16T01:40:46","modified_gmt":"2017-06-16T05:40:46","slug":"data-protection-fine-shows-security-risks-from-using-open-source-out-law-com","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/open-source-software\/data-protection-fine-shows-security-risks-from-using-open-source-out-law-com.php","title":{"rendered":"Data protection fine shows security risks from using open source &#8230; &#8211; Out-Law.com"},"content":{"rendered":"<p><p>    Tom Hadden of Pinsent Masons, the law firm behind Out-Law.com,    said the need to manage those risks will become even greater    once     the General Data Protection Regulation (GDPR) begins to    apply. Businesses face fines of up to 4% of their annual global    turnover, or 20 million, whichever is the greatest, under the    new Regulation, which will apply from 25 May 2018.  <\/p>\n<p>    Hadden was commenting after the UK's Information Commissioner's    Office (ICO) imposed a 100,000 fine on Gloucester City Council    over its failure to fix a weakness in the security of its    website. The vulnerability was exploited by a hacker who was    able to access sensitive personal data relating to between 30    and 40 current and former employees of the council.  <\/p>\n<p>    The ICO said Gloucester City Council was responsible for a    serious breach of the Data Protection Act.  <\/p>\n<p>    According to the ICO, Gloucester City Council failed to ensure    software it was using was updated to fix a vulnerability in    coding known as     the 'Heartbleed' bug, which was identified in April 2014 as    existing in some versions of encryption software developed by    via the open source 'OpenSSL Project'.  <\/p>\n<p>    Although IT staff at the council flagged the need to update the    software, a patch issued for the software was never applied,    according to     the monetary penalty notice (17-page \/ 3.02MB PDF) issued    by the ICO. The patching was \"overlooked\" at a time when the    council was outsourcing its IT to a third party supplier, it    said.  <\/p>\n<p>    In a statement, the ICO said that Gloucester City Council \"did    not have sufficient processes in place to ensure its systems    had been updated while changes to suppliers were made\". Sally    Anne Poole, group enforcement manager at the ICO, described    this as \"a serious oversight\" on the part of the authority.  <\/p>\n<p>    \"A lack of oversight of this outsourcing, along with inadequate    security measures on sensitive emails, left them vulnerable to    an attack,\" Poole said. \"The council should have known that in    the wrong hands, this type of sensitive information could cause    substantial distress to staff. Businesses and organisations    must understand they need to do everything they can to keep    peoples personal information safe and that includes being    extra vigilant during periods of change or uncertainty.\"  <\/p>\n<p>    Hadden of Pinsent Masons said: \"This is a classic cautionary    tale for businesses about the importance of keeping their    software and systems properly up to date, and exercising    constant awareness regarding patches that address security    vulnerabilities.\"  <\/p>\n<p>    \"The Heartbleed bug is probably the most well publicised    security vulnerability in the history of open source software    because of its wide reaching impact. However, the patch to fix    the vulnerability was readily available in April of 2014 and,    as the ICO said, the patch was widely publicised,\" he said.  <\/p>\n<p>    \"Given the hefty fines regime that will be installed by the    GDPR when it comes into force in the UK on 25 May 2018, it is    of greater importance than ever that companies take the steps    necessary to keep their software up to date and ensure that    their data, particularly sensitive personal data, remains    secure,\" Hadden said.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See the rest here:<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.out-law.com\/en\/articles\/2017\/june\/data-protection-fine-shows-security-risks-from-using-open-source-software-cannot-be-ignored-says-expert\/\" title=\"Data protection fine shows security risks from using open source ... - Out-Law.com\">Data protection fine shows security risks from using open source ... - Out-Law.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Tom Hadden of Pinsent Masons, the law firm behind Out-Law.com, said the need to manage those risks will become even greater once the General Data Protection Regulation (GDPR) begins to apply. Businesses face fines of up to 4% of their annual global turnover, or 20 million, whichever is the greatest, under the new Regulation, which will apply from 25 May 2018. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-32159","post","type-post","status-publish","format-standard","hentry","category-open-source-software"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32159"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=32159"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32159\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=32159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=32159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=32159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}