MPs propose tougher CEO sanctions over data security breaches

Image

CEOs of companies which fail to prevent problems with data security following cyber attacks face having part of their pay withheld under proposals outlined by a committee of MPs, which has also called for disclosure of data protection strategies in annual reports

The Culture, Media and Sport Select Committee has published a report on its inquiry into cyber security based on investigating breaches at network provider Talk Talk, which recommends a new custodial sentence of up to two years for those convicted of unlawfully obtaining and selling personal data.

It has also said the Information Commissioner's Office (ICO) should have a robust system of escalating fines at its disposal to sanction those who fail to report, prepare for or learn from data breaches.

In addition, the committee says companies must report their cyber security and data protection strategies to the ICO and should also include these in their annual reports, in the same way as the requirement for environmental and social reporting where material in what it describes as ‘quadruple bottom line reporting’.

MPs say it is appropriate for the CEO to lead a crisis response, should a major attack arise, but cyber security should sit with someone able to take full day-to-day responsibility who can be fully sanctioned if the company has not taken sufficient steps to protect itself from a cyber attack.

In order to ensure this issue receives sufficient CEO attention before a crisis strikes, the committee recommends a portion of CEO compensation should be linked to effective cyber security.

Other recommendations include companies making it much easier to verify if communications, whether online or by telephone, are genuine. The ICO’s system of sanctions should include fines for companies that fail to do this, while the committee says it should be easier for victims of a data breach to claim compensation.

The report stresses that it is not enough for companies to say they were not aware, arguing that breaches are common, and all companies need to plan and test for that eventuality. It also calls for organisations to demonstrate they have identified and addressed the weaknesses that have led to any data breaches.

Jesse Norman, chair of the committee, said: ‘Companies must have robust strategies and processes in place, backed by adequate resources and clear lines of accountability, to stay one step ahead in a sophisticated and rapidly evolving environment. Failure to prepare for or learn from cyber attacks, and failure to inform and protect consumers, must draw sanctions serious enough to act as a real incentive and deterrent.

‘As the TalkTalk case shows, the reality is that cyber attacks are a constant, evolving threat. TalkTalk responded quickly and well to this attack, but appear to have been much less effective in the past, failing to learn from repeated breaches of different kinds.

‘They should now publish as much of the PWC investigation as commercially possible without delay, and set out exactly how they will implement any necessary changes. Everyone must take the lessons from the Talk Talk breaches as a wake-up call – both in how they prepare to prevent cyber attacks, and in how they deal with their consumers when those attacks occur.’

The report, Cyber Security: Protection of Personal Data Online, is here.

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe