Interserve Group has been fined £4,400,000 due to their failure to implement adequate cyber security measures to protect their staff’s data.

The fine has also led the UK Information Commissioner to release a warning that companies are leaving themselves open to cyber attacks by ignoring crucial measures like updating software and adequately training staff.

Interserve Group’s complacency

Interserve is a British construction and support services business based in Reading, Berkshire. At the time of the attack, the company was designated as a “strategic supplier to the government with clients including the Ministry of Defence”.

The company recently suffered a cyber attack when one of its employees forwarded a phishing email, which had not been quarantined or blocked by Interserve’s IT system, to another employee who opened and unintentionally downloaded the email’s content.

Phishing emails are malicious emails sent by cybercriminals that either contain malware disguised as an innocent file, or encourage users to click a link, which will then install malware or prompt the user to provide their personal information.

In Interserve’s case, the phishing email contained malware, which was installed on the employee’s workstation.

The company’s anti-virus quarantined the malware and sent an alert to Interserve, but their in-house IT staff failed to thoroughly investigate the suspicious activity. If they had effectively investigated the malware, they would have realised that the attacker still had access to their systems.

As a result of this oversight, the attacker went on to compromise 283 systems and 16 user accounts, as well as uninstalling the company’s anti-virus solution.

In total, the personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

The compromised data includes information such as contact details, national insurance numbers, and even bank account details. Personal information, such as ethnic origin, religion, disabilities, sexual orientation and health information was compromised as well.

Interserve went on to inform the ICO and the NCSC of their cyber attack and looked to restore their damaged systems.

ICO Investigation and findings

The ICO investigation found that Interserve failed to follow up on its original alert of suspicious activity, used outdated software systems and protocols, had insufficient risk assessments, and had a complete lack of adequate staff training.

Interserve was also found to have broken data protection law by failing to put appropriate technical and organisational measures in place to prevent unauthorised access to people’s information.

This violation of data protection legislation, combined with their outdated software and organisational practices, resulted in the ICO issuing Interserve with a provisional fine amount set at £4.4 million, which was later reviewed, with no reductions being made to the final fine amount.

“The biggest cyber risk is complacency, not hackers”

Following this attack and fine, the current UK Information Commissioner, John Edwards, has released a statement warning other firms about the risks cyber complacency brings:

The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company. If your business doesn’t regularly monitor for suspicious activity in its systems and fails to act on warnings, or doesn’t update software and fails to provide training to staff, you can expect a similar fine from my office”.

Leaving the door open to cyber attackers is never acceptable, especially when dealing with people’s most sensitive information. This data breach had the potential to cause real harm to Interserve’s staff, it left them vulnerable to the possibility of identity theft and financial fraud”.

Cyber attacks are a global concern, and businesses around the world need to take steps to guard against complacency”.

 

TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
Such certifications are one of the ways we help ensure incidents such as those reported here do not happen to us or our clients.
They show our stakeholders that our cyber security practices are impeccable and allow us to protect against all common cyber attacks.
We are currently offering a free service that will help to identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the current best methods of identifying phishing emails:

https://www.tecsec.co.uk/free-training-phishing-simulation/