Proceeding contribution from Lord Harris of Haringey (Labour) in the House of Lords on Friday, 10 October 2008. It occurred during Debate on select committee report on Internet: Personal Security (S&T Report).
Internet: Personal Security (S&T Report)
My Lords, I thank the noble Lord, Lord Broers, for the way in which he introduced this debate and for the excellent way in which he steered the inquiry. I learnt a great deal from him, not least about the complexities of web-based navigational aids on ocean-going yachts, a subject to which I had not previously given much, if any, thought. I also want to pay tribute to the work of the committee’s Clerk, Christopher Johnson, who has now been elevated to the position of your Lordships’ Clerk of the Journals. I am not quite sure what the Clerk of the Journals does, but I hope the position makes full use of his excellent talents and skills. I also thank our adviser, Dr Richard Clayton from the University of Cambridge, who, along with the Minister, is a member of the bearded elite. Since our report was published, much has happened. There have been well publicised data losses at HM Revenue and Customs and from other government departments and agencies. Indeed, today we heard of the loss by EDS of an MoD hard drive containing the details of 100,000 service men and women. All this confirms my view that the committee was right to call for a data breach notification law in the UK. I commend the Government for their willingness to come clean and admit problems as they emerge, but that does not alter my view that, with a few exceptions, the maintenance of information security is not a high enough priority in the minds of those in charge of public bodies or private companies. Moreover, recent reports have suggested that a significant number of major private sector losses have been reported to the Information Commissioner. For example, Virgin Media has been ordered to encrypt all portable media that it uses to move data after it lost data on 3,000 would-be customers. In another case, 1 million bank customers’ details turned up on a second-hand PC sold over the online auction website eBay. The data contained information on customers of American Express, NatWest and the Royal Bank of Scotland. It is reported to include mobile phone numbers, bank account numbers, mother’s maiden names and signatures. We have to recognise that it remains unclear whether all such losses have been disclosed, given that it will not be in a company’s commercial interest to do so. A data breach notification law would not solve those problems, but it would certainly concentrate the minds of those responsible. We must alter the mindset. It must be clear that information security is not some optional extra, and that for every business and organisation, information security is just as important as physical security. That is about the culture within organisations. Every employee must understand the importance of maintaining data security and their responsibility for doing so. Perhaps if people recognised the potential value of personal data, they might be less cavalier in its treatment. For many people, a stolen identity will take weeks or months of effort to sort out. The FSA estimates that the cost of identity fraud in the UK—admittedly, using a fairly wide definition—is about £1.7 billion. During the inquiry, we were told by Team Cymru that on a single server in a typical month, there were for sale the data from 32,000 compromised Visa cards and 13,000 MasterCards. The price nearly three years ago was $1 for a US card and, apparently, $2 for a UK card. Associated data were also for sale, including the cardholder’s mother's maiden name. Perhaps if employees were told that each personal record was worth at least £100—it is probably more—they might treat a memory stick or, for that matter, the MoD hard drive containing 100,000 personal records as though it was worth £10 million. They would certainly treat it with substantially more respect. Engendering such a change in culture may require more than a data breach notification law. Perhaps we need something more akin to the framework created by health and safety legislation, where every manager would have to take personal responsibility for delivering information security in their area of responsibility or face prosecution. Perhaps we need an IT equivalent of the US Sarbanes-Oxley requirements to make people at board level take their responsibilities to heart. Nevertheless, as a first step, I ask my noble friend when he replies to reflect on whether the experience of the past few months and weeks has made it all the more urgent that we introduce data breach notification legislation. The need for a shift in the burden of responsibility was also a key theme of the report in terms of those who should be responsible for ensuring personal internet security more generally. The underlying theme of the report was that the internet is a powerful force for good in society, but underpinning the success of the internet has to be the confidence of individual users, as we are all only too well aware at the moment. That matters. Government spending plans are predicated on the growth of e-government, with more citizens transacting with central and local government electronically. Similarly, economic forecasts are based on the continuing growth of e-commerce. If public confidence in the internet falters, the consequences are serious. There is every reason to suppose that such confidence could falter. According to a survey commissioned by Get Safe Online, e-crime is now more feared than mugging, car crime or burglary. I believe that the Department for Business, Enterprise and Regulatory Reform contests that, but there is no question that many people are fearful of conducting transactions electronically. Moreover, as the inquiry concluded—albeit, I must say, with an eye to the soundbite—the internet, "““is now increasingly the playground of criminals””." The government view, certainly as initially expressed to us, was that internet security ultimately rests with the individual. However, our view was that such a stance was no longer realistic and was in danger of compounding the perception that, in another soundbite from the report, the internet is a ““lawless ‘wild west’””. Responsibility for improving internet security should be shared. The committee used the analogy of road transport. Within the road transport system, the safety and security of the individual road user is protected at several levels. There is the network itself, with roads designed and engineered for safety, maintained, lit and signposted. Then there is the equipment that uses the network—in the road safety analogy, cars and other vehicles have safety features built into their design. Individual users are taught how to drive and subjected to testing and monitoring. Finally, the network is policed with a clearly defined legal framework for the use of the network, with those who breach the law risking prosecution. As far as internet security is concerned, the network providers—the ISPs and so on—equipment manufacturers and software producers should all take some responsibility for making the network, the equipment and the programmes more secure. Similarly, businesses must have a role in making their interface with consumers safe and secure and protecting the position of those who transact with them. Finally, each user must be sensible and careful, although the Government can help by taking measures to raise IT literacy and improve understanding of security. The Government must ensure, of course, that the rules set are adequately and effectively policed. The noble Lord, Lord Broers, referred to the value of a kite-marking security system. This is clearly necessary for equipment and software and for service providers. There should be better service advice given automatically on the first use of products. Default security settings should initially be set as high as possible. It should be an explicit decision of users to lower the settings. Security updates should automatically be downloaded, and security messages and warnings should be in clear and simple language. Let us be clear, however, that people are put at risk in a variety of ways: sometimes by their own ignorance, sometimes by the carelessness or ignorance of others, sometimes by deliberate criminal acts and sometimes by technological flaws or poor product design. This is often made worse by products that behave badly or lead people into trouble. Why do so many commercial sites require information that is not necessary for the transaction concerned? The answer, of course, is that it provides them with useful marketing information—all the better to sell you future products. However, how well is that information protected? The impetus to complete the transaction will lead many people to provide more information that may not be strictly necessary but may be difficult not to provide, and to agree, or more likely not to disagree, to its use in all sorts of ways that in any event are probably outlined in a 20-page policy that most users will not bother to read. As my noble friend Lord Mitchell has highlighted, of particular concern is the way in which some of the popular social networking sites encourage people, often teenagers, to reveal all sorts of personal details and information about themselves. This opens them up not only to identity theft but to sexual predators. Young people might also want to reflect on the impact on their future employment prospects when details of their wilder escapades may be readily available to would-be recruiters. The companies that run these sites have an obligation to warn people about these dangers, to enable people simply to remove material that with hindsight they wish they had not posted and to make it easier for users to report abuse and problems. Perhaps my noble friend Lord Brett will tell us in his reply whether the Government are happy to see social networking sites, which are used by so many teenagers and young people, operating so freely and in a way that could be so damaging to their users. Then there is the problem of e-crime. The term is necessarily a loose one; fraud is fraud, whether it is committed using electronic means or any other means, and child abuse is child abuse, whether images of it are transmitted electronically or in any other way. However, to say that you cannot define it meaningfully does not alter the underlying issue that the way in which many crimes are committed or the ways in which they are facilitated have changed dramatically in recent years. It is therefore necessary to ensure that the police and enforcement agencies are equipped to respond effectively to this dramatic change. That is why the creation of the police e-crime unit is so important. I am grateful for the Government’s support for this and for the resources that have been made available. I pay tribute in particular to my honourable friend Vernon Coaker, who worked so hard to bring this about and has now, I am pleased to say, been rewarded by promotion to Minister of State. The creation of a centre of excellence that provides support and policy leadership to police forces around the country is essential given the rapid pace of technological developments and the speed at which criminals exploit these developments. Such a centre cannot be the end of the process. Every police force will need to develop its own capacity in this area, and, increasingly, mainstream resources will have to be devoted to this area to reflect the changing nature and manner of crime. My final point relates to what the report did not cover: the wider question of the national infrastructure and internet security. As a nation, the systems that are essential for our health and well-being rely on computer and communications networks, whether we are talking about the energy utilities, the water and food distribution networks, transportation, the emergency services, telephones, the banking and financial systems, and, indeed, government and public services in general. All of them are vulnerable to serious disruption by cyber-attack, with potentially enormous consequences. The threat could come from teenage hackers with no more motivation than proving that it can be done. Even more seriously, it could come from organised criminals, intent on extortion or fraud, or from cyber-terrorists, intent on bringing about the downfall of our society. We now know that, following the cyber-attacks on Estonia and the cyber-disruption suffered by Georgia earlier this year, the threat may also come from nation states. Moreover, most of the critical national infrastructure is privately owned and operated. It may not be in the commercial interests of those owners and operators even to acknowledge to anyone outside their organisation that they have had a problem. Do I, as an operator, want my other customers to know that my security, and therefore their security, has been breached? I think not. It would certainly not be good for business. In any event, it cannot be necessarily assumed that the commercial need to maintain system security is of the same magnitude as the national interest in that security; nor can we be confident about those parts of the CNI operated in the public sector. We live in a target-driven world, and security constraints are not necessarily adequately addressed in each department’s key performance indicators, certainly when the key drivers of activity are improving the quantum of specific aspects of service delivery. My final question to my noble friend is: are the Government really satisfied that our critical national infrastructure, which is now so dependent on the internet, is genuinely as well defended and secure as it should be? I believe that Personal Internet Security has already had a significant impact on government thinking. However, there is still too much complacency on this issue: information security remains the poor relation of information technology and of physical security. Information security is not an optional extra. If we do not get this right, public confidence in the internet is at risk, and with it business confidence and perhaps, if we consider the reliance of our national infrastructure on electronic systems, even our national security.
Secondary information
- Type
- Proceeding contribution
- Reference
- 704 c459-63
- Session
- 2007-08
- Chamber / Committee
- House of Lords chamber
- Subjects
- Data protection Crime Banks Computers Credit cards Fraud Internet Personal records Police Security Internet service providers
- Link
- View this Proceeding contribution on www.publications.parliament.uk
Librarians' tools
- Timestamp
- 2023-12-16 01:39:51 +0000
- URI
- http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_498734
- In Indexing
- http://indexing.parliament.uk/Content/Edit/1?uri=http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_498734
- In Solr
- https://search.parliament.uk/claw/solr/?id=http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_498734