<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/computer-misuse-act"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Computer-misuse-act ]]></title>
                <link>https://www.itpro.com/uk/tag/computer-misuse-act</link>
        <description><![CDATA[ All the latest computer-misuse-act content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Mon, 11 Jan 2021 12:04:06 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Two sentenced under the Computer Misuse Act for data theft ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> has led the successful prosecution of two individuals for violating the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act (CMA) 1990</a> by stealing personal data to make nuisance calls.</p><p>Kim Doyle, a former RAC employee, was found guilty of transferring personal data to an accident claims management firm without permission, including road traffic accident data such as names, mobile phone numbers and registration numbers.</p><p>An ICO investigation found that Dyle transferred the data she had obtained to William Shaw, the director of TMS, with this data subsequently being used to make nuisance calls. This constituted a breach of the CMA, with Doyle pleading guilty to conspiracy to secure unauthorised access to computer data, and selling unlawfully obtained personal data.</p><p>Both Doyle and Shaw, as a result, have each been handed an eight-month prison sentence, suspended for two years.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/356423/ico-lambasted-for-falling-asleep-at-the-wheel" data-original-url="/policy-legislation/data-protection/356423/ico-lambasted-for-falling-asleep-at-the-wheel">Brave accuses the ICO of ‘falling asleep at the wheel’</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" data-original-url="/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">Computer Misuse Act 'putting critical UK infrastructure at risk'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">UK gov urged to overhaul "unfit for purpose" Computer Misuse Act</a></p></div></div><p>“People’s data is being accessed without consent and businesses are putting resources into tracking down criminals,” said Mike Shaw, who heads up the UK data regulator’s criminal investigations team. </p><p>“Once the data is in the hands of claims management companies, people are subjected to unwanted calls which can in turn lead to fraudulent personal injury claims. Offenders must know that we will use all the tools at our disposal to protect people’s information and prevent it from being used to make nuisance calls.</p><p>“This case shows that we can, and will take action, and that could lead to a prison sentence for those responsible.”</p><p>This is only the latest in a handful of prosecutions made under the CMA, led by the ICO. In June 2020, for instance, a businesswoman was <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356166/businesswoman-sentenced-after-illegally-deleting" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356166/businesswoman-sentenced-after-illegally-deleting">sentenced for illegally accessing a company’s servers and deleting files</a> months after resigning as a director.</p><p>While only a few individuals are prosecuted under the CMA, historical research had found that <a href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">more than a third of IT workers admitted to violating</a> this legislation. The research from 2016 showed that roughly half of employees surveyed admitted to retaining access to their former employer’s network, while 36% admitted to accessing corporate systems after leaving their roles.</p><p>The act itself, however, is widely deemed out-of-date and counterintuitive by many working in the IT sector and in cyber security. </p><p>According to research published last year, the 30-year-old legislation is <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">preventing cyber security professionals from doing their jobs</a>. Many, in particular, are worried about whether may be breaking the law while researching vulnerabilities, or investigating threats. Specifically, 40% of those surveyed said the CMA has acted as a barrier to them or their colleagues and has prevented them from proactively safeguarding against breaches.</p><p>A coalition of businesses, trade bodies, lawyers and cyber security lobby groups also wrote to the prime minister, Boris Johnson, in June 2020 <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">urging his government to reform the CMA</a> for similar reasons. This group included techUK, F-Secure, McAfee and Trend Micro, among other organisations.</p><p>The Criminal Law Reform Now Network (CLRNN) has also reported on the shortcomings of the CMA, claiming in January last year that the legislation is <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">putting critical UK infrastructure at risk</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/computer-misuse-act/358280/two-sentenced-under-the-computer-misuse-act-for-data</link>
                                                                            <description>
                            <![CDATA[ The individuals were accused of siphoning away personal data from RAC to an accident claims management firm ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">stxqxe4GDJxvLpXWWdqBtU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WormwtP3tucmtME5HLuxE5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Jan 2021 12:04:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WormwtP3tucmtME5HLuxE5-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Code on a screen before fingers typing onto a keyboard]]></media:description>                                                            <media:text><![CDATA[Code on a screen before fingers typing onto a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Code on a screen before fingers typing onto a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WormwtP3tucmtME5HLuxE5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> has led the successful prosecution of two individuals for violating the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act (CMA) 1990</a> by stealing personal data to make nuisance calls.</p><p>Kim Doyle, a former RAC employee, was found guilty of transferring personal data to an accident claims management firm without permission, including road traffic accident data such as names, mobile phone numbers and registration numbers.</p><p>An ICO investigation found that Dyle transferred the data she had obtained to William Shaw, the director of TMS, with this data subsequently being used to make nuisance calls. This constituted a breach of the CMA, with Doyle pleading guilty to conspiracy to secure unauthorised access to computer data, and selling unlawfully obtained personal data.</p><p>Both Doyle and Shaw, as a result, have each been handed an eight-month prison sentence, suspended for two years.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/356423/ico-lambasted-for-falling-asleep-at-the-wheel" data-original-url="/policy-legislation/data-protection/356423/ico-lambasted-for-falling-asleep-at-the-wheel">Brave accuses the ICO of ‘falling asleep at the wheel’</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" data-original-url="/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">Computer Misuse Act 'putting critical UK infrastructure at risk'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">UK gov urged to overhaul "unfit for purpose" Computer Misuse Act</a></p></div></div><p>“People’s data is being accessed without consent and businesses are putting resources into tracking down criminals,” said Mike Shaw, who heads up the UK data regulator’s criminal investigations team. </p><p>“Once the data is in the hands of claims management companies, people are subjected to unwanted calls which can in turn lead to fraudulent personal injury claims. Offenders must know that we will use all the tools at our disposal to protect people’s information and prevent it from being used to make nuisance calls.</p><p>“This case shows that we can, and will take action, and that could lead to a prison sentence for those responsible.”</p><p>This is only the latest in a handful of prosecutions made under the CMA, led by the ICO. In June 2020, for instance, a businesswoman was <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356166/businesswoman-sentenced-after-illegally-deleting" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356166/businesswoman-sentenced-after-illegally-deleting">sentenced for illegally accessing a company’s servers and deleting files</a> months after resigning as a director.</p><p>While only a few individuals are prosecuted under the CMA, historical research had found that <a href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">more than a third of IT workers admitted to violating</a> this legislation. The research from 2016 showed that roughly half of employees surveyed admitted to retaining access to their former employer’s network, while 36% admitted to accessing corporate systems after leaving their roles.</p><p>The act itself, however, is widely deemed out-of-date and counterintuitive by many working in the IT sector and in cyber security. </p><p>According to research published last year, the 30-year-old legislation is <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">preventing cyber security professionals from doing their jobs</a>. Many, in particular, are worried about whether may be breaking the law while researching vulnerabilities, or investigating threats. Specifically, 40% of those surveyed said the CMA has acted as a barrier to them or their colleagues and has prevented them from proactively safeguarding against breaches.</p><p>A coalition of businesses, trade bodies, lawyers and cyber security lobby groups also wrote to the prime minister, Boris Johnson, in June 2020 <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">urging his government to reform the CMA</a> for similar reasons. This group included techUK, F-Secure, McAfee and Trend Micro, among other organisations.</p><p>The Criminal Law Reform Now Network (CLRNN) has also reported on the shortcomings of the CMA, claiming in January last year that the legislation is <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">putting critical UK infrastructure at risk</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 80% of cyber professionals say the Computer Misuse Act is working against them ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Four in five UK cyber security professionals are worried about breaking the law due to confusion caused by the ageing <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act#:~:text=The%20Computer%20Misuse%20Act%20(CMA,without%20appropriate%20consent%20or%20permission.">Computer Misuse Act</a> (CMA).</p><p>The 30-year-old legislation is restricting <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pen-testers</a> and white hat hackers with strict and often out-dated definitions, according to a survey commissioned by teckUK and the CyberUp Campaign.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">UK gov urged to overhaul "unfit for purpose" Computer Misuse Act</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a></p></div></div><p>The survey, which was circulated between 46 respondents representing 11 organisations and some 25,120 employees, found that the legislation was stifling security teams in the UK, with 80% of respondents saying they have been <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">worried about breaking the law</a> when researching vulnerabilities or investigating cyber threat actors.</p><p>Around 40% of those surveyed said the CMA has acted as a barrier to them or their colleagues and had even prevented employees from proactively safeguarding against security breaches. Furthermore, 91% of businesses believed that the law puts UK consultancies at a competitive disadvantage with other countries.</p><p>Some of the answers also suggested confusion about what counts as a criminal offence under the CMA. In fact, in only three cyber incident examples - 'web scraping' (74%), 'open source internet scanning' (68%), and 'default credentials in login panels exposed to the internet' (74%) - did respondents reach a reasonable level of consensus.</p><p>The Computer Misuse Act was enshrined in 1990, long before the internet became the essential tool for businesses it is today. Although it has been updated a number of times, both techUK and the CyberUp Campaign are calling for the government to open a consultation within the industry to put the law through "rapid modernisation".</p><p>"I know from my time in this industry that there are now real concerns among the cyber security community that this law is impeding professionals ability to protect the nation from the ever-evolving range of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber threats</a> we face, and preventing the sector from establishing its leadership position on the international stage," Conservative MP Ruth Edwards wrote in the report.</p><p>"If ever there was going to be a time to prioritise the rapid modernisation of our cyber legislation, it is now, when our reliance on safe, reliable and resilient digital technologies has been brought into stark relief by the coronavirus pandemic."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act</link>
                                                                            <description>
                            <![CDATA[ techUK report calls for "rapid modernisation" of the 30-year-old law that's "stifling" penetration testing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bPfvddXULyJizMmc5oCM9C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oQu4SjakrwoKz8VXQfWVJG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Nov 2020 12:13:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oQu4SjakrwoKz8VXQfWVJG-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A young professional showing signs of stress at work]]></media:description>                                                            <media:text><![CDATA[A young professional showing signs of stress at work]]></media:text>
                                <media:title type="plain"><![CDATA[A young professional showing signs of stress at work]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oQu4SjakrwoKz8VXQfWVJG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four in five UK cyber security professionals are worried about breaking the law due to confusion caused by the ageing <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act#:~:text=The%20Computer%20Misuse%20Act%20(CMA,without%20appropriate%20consent%20or%20permission.">Computer Misuse Act</a> (CMA).</p><p>The 30-year-old legislation is restricting <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pen-testers</a> and white hat hackers with strict and often out-dated definitions, according to a survey commissioned by teckUK and the CyberUp Campaign.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">UK gov urged to overhaul "unfit for purpose" Computer Misuse Act</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a></p></div></div><p>The survey, which was circulated between 46 respondents representing 11 organisations and some 25,120 employees, found that the legislation was stifling security teams in the UK, with 80% of respondents saying they have been <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">worried about breaking the law</a> when researching vulnerabilities or investigating cyber threat actors.</p><p>Around 40% of those surveyed said the CMA has acted as a barrier to them or their colleagues and had even prevented employees from proactively safeguarding against security breaches. Furthermore, 91% of businesses believed that the law puts UK consultancies at a competitive disadvantage with other countries.</p><p>Some of the answers also suggested confusion about what counts as a criminal offence under the CMA. In fact, in only three cyber incident examples - 'web scraping' (74%), 'open source internet scanning' (68%), and 'default credentials in login panels exposed to the internet' (74%) - did respondents reach a reasonable level of consensus.</p><p>The Computer Misuse Act was enshrined in 1990, long before the internet became the essential tool for businesses it is today. Although it has been updated a number of times, both techUK and the CyberUp Campaign are calling for the government to open a consultation within the industry to put the law through "rapid modernisation".</p><p>"I know from my time in this industry that there are now real concerns among the cyber security community that this law is impeding professionals ability to protect the nation from the ever-evolving range of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber threats</a> we face, and preventing the sector from establishing its leadership position on the international stage," Conservative MP Ruth Edwards wrote in the report.</p><p>"If ever there was going to be a time to prioritise the rapid modernisation of our cyber legislation, it is now, when our reliance on safe, reliable and resilient digital technologies has been brought into stark relief by the coronavirus pandemic."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Less than 1% of computer hacking offences resulted in prosecution in 2019 ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Of 17,600 reported cases of hacking in the UK only 57 led to prosecution in 2019, according to a new report.</p><p>The numbers signify a 12% drop in convictions compared to 65 successful prosecutions the year before, according to legal firm RPC, which said police forces lack the resources to fully investigate all aspects of <a href="https://www.itpro.com/security/cyber-security/356354/uk-businesses-spent-ps87-billion-in-five-years-tackling-cyber-crime" data-original-url="https://www.itpro.com/security/cyber-security/356354/uk-businesses-spent-ps87-billion-in-five-years-tackling-cyber-crime">cyber crime</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media" data-original-url="/security/phishing/356581/what-are-you-giving-away-on-social-media">What are you giving away on social media?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31723/what-is-shoulder-surfing" data-original-url="/security/31723/what-is-shoulder-surfing">What is shoulder surfing?</a></p></div></div><p>Government resources are instead being focused on large scale cyber attacks that are deemed a threat to national security, the firm suggested. As such, small, more niche hacking cases have proved elusive for the UK's police and judicial system.</p><p>"Tracking down cybercriminals is a very resource-intensive task," said Richard Breavington, partner at RPC. "Hackers know how to cover their tracks, and doing so is relatively straightforward. Cyber criminals view hacking as a low-risk activity, with virtually zero risk of prosecution."</p><p>RPC said that the majority of hacking offences reported in the UK are most likely carried out overseas, making it difficult to identify and pursue attackers who can route attacks through other jurisdictions where co-operation between law enforcement agencies is not always guaranteed.</p><p>The results for prosecutions in 2019 will be a concern for the UK government, particularly as the pandemic has seen a rise in smaller hacking scams, such as relatively unsophisticated <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><p>The RPC report found that only an "extremely small proportion" of the 17,600 cases were able to be tried under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>. The legislation was first enshrined in 1990 and, despite regular updates to keep it in line with rapidly advancing digital technologies, many have argued the act provides a confusing framework with ambiguous terminology.</p><p>In June, an alliance of businesses and trade groups petitioned the government to scrap the law, largely due to a clause that forces cyber security researchers to seek consent from those they investigate before accessing their systems, effectively preventing work against active criminals.</p><p>However, <a href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media" target="_blank" data-original-url="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media">Jake Moore</a>, Eset security specialist and former cyber security advisor for Dorset Police, told <em>IT Pro</em> that more resources for the police and better collaboration with universities and businesses with higher digital skill sets would be a better use of time over ammending legislation.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zjRhSu4diLQpdzCQ4r6qE4" name="zjRhSu4diLQpdzCQ4r6qE4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/zjRhSu4diLQpdzCQ4r6qE4.png" mos="https://cdn.mos.cms.futurecdn.net/zjRhSu4diLQpdzCQ4r6qE4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Simplify cluster security at scale</strong></p><p class="fancy-box__body-text">Centralised secrets management across hybrid, multi-cloud environments</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/357128/simplify-cluster-security-at-scale" data-original-url="/cloud/cloud-security/357128/simplify-cluster-security-at-scale">FREE DOWNLOAD</a></p></div></div><p>"It's all well and good stating what is illegal in a misuse act but criminal hackers tend to be fully aware of the law," Moore said. "It's just they chose to carry on regardless in the knowledge of being capable of evading capture."</p><p>He argues that hackers are fully aware of the techniques to cover their tracks and evade capture, often making offences largely risk free.</p><p>"The labour-intensive nature of a cyber investigation often means that conviction is not possible," he added. "The amount of evidence requested to put criminal hackers behind bars is usually impossible to even locate let alone locating the offender in the first place. This decrease in prosecutions is likely to continue whilst policing remains in its current state."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/357298/less-than-1-percent-hacking-resulted-in-prosecution-2019</link>
                                                                            <description>
                            <![CDATA[ Of the 17,600 offences recorded in the UK, just 57 were able to be tried under the Computer Misuse Act, report finds ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oEBMpQnr6yMxhecjo9efhy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uENNmtrYnjGSXSYAGfgwJW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Oct 2020 10:08:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uENNmtrYnjGSXSYAGfgwJW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man in handcuffs standing in front of computer equipment in a darkened room]]></media:description>                                                            <media:text><![CDATA[A man in handcuffs standing in front of computer equipment in a darkened room]]></media:text>
                                <media:title type="plain"><![CDATA[A man in handcuffs standing in front of computer equipment in a darkened room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uENNmtrYnjGSXSYAGfgwJW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Of 17,600 reported cases of hacking in the UK only 57 led to prosecution in 2019, according to a new report.</p><p>The numbers signify a 12% drop in convictions compared to 65 successful prosecutions the year before, according to legal firm RPC, which said police forces lack the resources to fully investigate all aspects of <a href="https://www.itpro.com/security/cyber-security/356354/uk-businesses-spent-ps87-billion-in-five-years-tackling-cyber-crime" data-original-url="https://www.itpro.com/security/cyber-security/356354/uk-businesses-spent-ps87-billion-in-five-years-tackling-cyber-crime">cyber crime</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media" data-original-url="/security/phishing/356581/what-are-you-giving-away-on-social-media">What are you giving away on social media?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31723/what-is-shoulder-surfing" data-original-url="/security/31723/what-is-shoulder-surfing">What is shoulder surfing?</a></p></div></div><p>Government resources are instead being focused on large scale cyber attacks that are deemed a threat to national security, the firm suggested. As such, small, more niche hacking cases have proved elusive for the UK's police and judicial system.</p><p>"Tracking down cybercriminals is a very resource-intensive task," said Richard Breavington, partner at RPC. "Hackers know how to cover their tracks, and doing so is relatively straightforward. Cyber criminals view hacking as a low-risk activity, with virtually zero risk of prosecution."</p><p>RPC said that the majority of hacking offences reported in the UK are most likely carried out overseas, making it difficult to identify and pursue attackers who can route attacks through other jurisdictions where co-operation between law enforcement agencies is not always guaranteed.</p><p>The results for prosecutions in 2019 will be a concern for the UK government, particularly as the pandemic has seen a rise in smaller hacking scams, such as relatively unsophisticated <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><p>The RPC report found that only an "extremely small proportion" of the 17,600 cases were able to be tried under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>. The legislation was first enshrined in 1990 and, despite regular updates to keep it in line with rapidly advancing digital technologies, many have argued the act provides a confusing framework with ambiguous terminology.</p><p>In June, an alliance of businesses and trade groups petitioned the government to scrap the law, largely due to a clause that forces cyber security researchers to seek consent from those they investigate before accessing their systems, effectively preventing work against active criminals.</p><p>However, <a href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media" target="_blank" data-original-url="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media">Jake Moore</a>, Eset security specialist and former cyber security advisor for Dorset Police, told <em>IT Pro</em> that more resources for the police and better collaboration with universities and businesses with higher digital skill sets would be a better use of time over ammending legislation.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zjRhSu4diLQpdzCQ4r6qE4" name="zjRhSu4diLQpdzCQ4r6qE4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/zjRhSu4diLQpdzCQ4r6qE4.png" mos="https://cdn.mos.cms.futurecdn.net/zjRhSu4diLQpdzCQ4r6qE4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Simplify cluster security at scale</strong></p><p class="fancy-box__body-text">Centralised secrets management across hybrid, multi-cloud environments</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/357128/simplify-cluster-security-at-scale" data-original-url="/cloud/cloud-security/357128/simplify-cluster-security-at-scale">FREE DOWNLOAD</a></p></div></div><p>"It's all well and good stating what is illegal in a misuse act but criminal hackers tend to be fully aware of the law," Moore said. "It's just they chose to carry on regardless in the knowledge of being capable of evading capture."</p><p>He argues that hackers are fully aware of the techniques to cover their tracks and evade capture, often making offences largely risk free.</p><p>"The labour-intensive nature of a cyber investigation often means that conviction is not possible," he added. "The amount of evidence requested to put criminal hackers behind bars is usually impossible to even locate let alone locating the offender in the first place. This decrease in prosecutions is likely to continue whilst policing remains in its current state."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK gov urged to overhaul "unfit for purpose" Computer Misuse Act ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A coalition of businesses, trade bodies, lawyers and cyber security lobby groups has urged the government to reform laws on cyber crime, which they say are "unfit for purpose". </p><p>The alliance has written a letter to the Prime Minister, according to <a href="https://www.scmagazineuk.com/uk-cybersecurity-industry-calls-overhaul-computer-misuse-act/article/1687977" target="_blank"><em>SCUK</em></a>, urging him to bring forward reforms to the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>, which is now <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">30-years-old</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" data-original-url="/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">Computer Misuse Act 'putting critical UK infrastructure at risk'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/26043/british-teen-arrested-for-contravening-computer-misuse-act" data-original-url="/hacking/26043/british-teen-arrested-for-contravening-computer-misuse-act">British teen arrested for contravening Computer Misuse Act</a></p></div></div><p>The legislation first came into effect in 1990 after two men hacked into Prince Philip's Prestel account. At the time, the two couldn't be found guilty as no laws on computer hacking existed, so one was created. However, 30-years-on, the law now affects research into cyber crime.</p><p>The coalition calling for it to be changed includes NCC Group, F-Secure, techUK, McAfee, Trend Micro and many more. In their letter, they state that section 1 of the Act prohibits the unauthorised access to any programme or data held in any computer and has not kept pace with advances in technology.</p><p>"With the advent of modern threat intelligence research, defensive cyber activities often involve the scanning and interrogation of compromised victims and criminals systems to lessen the impact of attacks and prevent future incidents," the letter reads. "In these cases, criminals are obviously very unlikely to explicitly authorise such access."</p><p>The reasoning is that the law hampers research into threats and therefore increases the risk to the UK's critical national infrastructure. Those who signed letter suggest the issue is very urgent, highlighting the nation's resilience on secure digital technologies, especially given the impact of the coronavirus. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5GaDu65xakaBRLvtFcNhGA" name="5GaDu65xakaBRLvtFcNhGA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/5GaDu65xakaBRLvtFcNhGA.jpg" mos="https://cdn.mos.cms.futurecdn.net/5GaDu65xakaBRLvtFcNhGA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cybersecurity crisis-planning checklist</strong></p><p class="fancy-box__body-text">Tips for planning and ensuring business continuity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356047/cybersecurity-crisis-planning-checklist" data-original-url="/security/cyber-security/356047/cybersecurity-crisis-planning-checklist">FREE DOWNLOAD</a></p></div></div><p>The letter cites other examples from countries, such as the US and France, and suggests that the UK has fallen behind with its laws on cyber crime. </p><p>"This creates an advantage for competing cybersecurity sectors, which could see the UK lose out on as many as 4,000 additional high-skilled jobs by 2023 without reform," said the letter.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act</link>
                                                                            <description>
                            <![CDATA[ Cyber security experts say 30-year-old law has not kept pace with advances in technology ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2uXWAw9TBbBevj5RPJ5Ypz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D5SqEJvUh8pV83LKehBQSU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2020 09:03:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D5SqEJvUh8pV83LKehBQSU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Darkened image of a hacker wearing a hoodie using computing equipment]]></media:text>
                                <media:title type="plain"><![CDATA[Darkened image of a hacker wearing a hoodie using computing equipment]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D5SqEJvUh8pV83LKehBQSU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A coalition of businesses, trade bodies, lawyers and cyber security lobby groups has urged the government to reform laws on cyber crime, which they say are "unfit for purpose". </p><p>The alliance has written a letter to the Prime Minister, according to <a href="https://www.scmagazineuk.com/uk-cybersecurity-industry-calls-overhaul-computer-misuse-act/article/1687977" target="_blank"><em>SCUK</em></a>, urging him to bring forward reforms to the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>, which is now <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">30-years-old</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" data-original-url="/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">Computer Misuse Act 'putting critical UK infrastructure at risk'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/26043/british-teen-arrested-for-contravening-computer-misuse-act" data-original-url="/hacking/26043/british-teen-arrested-for-contravening-computer-misuse-act">British teen arrested for contravening Computer Misuse Act</a></p></div></div><p>The legislation first came into effect in 1990 after two men hacked into Prince Philip's Prestel account. At the time, the two couldn't be found guilty as no laws on computer hacking existed, so one was created. However, 30-years-on, the law now affects research into cyber crime.</p><p>The coalition calling for it to be changed includes NCC Group, F-Secure, techUK, McAfee, Trend Micro and many more. In their letter, they state that section 1 of the Act prohibits the unauthorised access to any programme or data held in any computer and has not kept pace with advances in technology.</p><p>"With the advent of modern threat intelligence research, defensive cyber activities often involve the scanning and interrogation of compromised victims and criminals systems to lessen the impact of attacks and prevent future incidents," the letter reads. "In these cases, criminals are obviously very unlikely to explicitly authorise such access."</p><p>The reasoning is that the law hampers research into threats and therefore increases the risk to the UK's critical national infrastructure. Those who signed letter suggest the issue is very urgent, highlighting the nation's resilience on secure digital technologies, especially given the impact of the coronavirus. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5GaDu65xakaBRLvtFcNhGA" name="5GaDu65xakaBRLvtFcNhGA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/5GaDu65xakaBRLvtFcNhGA.jpg" mos="https://cdn.mos.cms.futurecdn.net/5GaDu65xakaBRLvtFcNhGA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cybersecurity crisis-planning checklist</strong></p><p class="fancy-box__body-text">Tips for planning and ensuring business continuity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356047/cybersecurity-crisis-planning-checklist" data-original-url="/security/cyber-security/356047/cybersecurity-crisis-planning-checklist">FREE DOWNLOAD</a></p></div></div><p>The letter cites other examples from countries, such as the US and France, and suggests that the UK has fallen behind with its laws on cyber crime. </p><p>"This creates an advantage for competing cybersecurity sectors, which could see the UK lose out on as many as 4,000 additional high-skilled jobs by 2023 without reform," said the letter.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Businesswoman sentenced for illegally deleting company files ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A woman has been prosecuted under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act (CMA) 1990</a> for deleting thousands of crucial files from the servers of a company that went into liquidation. </p><p>Danielle Bulley, former director of a property marketing firm, was found guilty of gaining unauthorised access to the servers of a new company that was created from its remains and deleting more than 5,000 documents.</p><p>The 58-year-old was charged with computer misuse offences and given an 18-month community order and unpaid work requirement when she appeared for sentence at York Crown Court, according to the <a href="https://northyorkshire.police.uk/news/businesswoman-sentenced" target="_blank">North Yorkshire Police</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" data-original-url="/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">Computer Misuse Act 'putting critical UK infrastructure at risk'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals" data-original-url="/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals">Almost 100 HMRC staff disciplined over computer misuse, FOI reveals</a></p></div></div><p>“During our investigation, it became clear that Bulley had left the original company on a bad note, but the deletion of thousands of files containing vital information was catastrophic for the victim. It dealt the new business a blow from which it never recovered,” said detective constable Steven Harris of the Cyber Crime Unit.</p><p>“Ex-employees can pose a serious risk to a business because they are familiar with the company’s IT infrastructure and procedures. This can make it easier for them to carry out <a href="https://www.itpro.com/security/cyber-security/355185/165-million-britons-experienced-a-cyber-crime-in-the-past-year" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/355185/165-million-britons-experienced-a-cyber-crime-in-the-past-year">cyber crimes</a> against their former organisation.</p><p>“We encourage businesses to ensure they have policies in place for removing user accounts and changing passwords when an employee leaves an organisation.”</p><p>Bulley resigned as a director from the new property marketing business, which was launched using the assets of the old company after it went into liquidation. Several months later she gained access to the new company’s servers and permanently deleted all their data. </p><p>The individual who ran the new firm said her actions caused job losses and financial losses of nearly £100,000. The damage to the company was so extensive, he added, that the company could no longer operate and was forced to go under.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uqwrweTFuwAAm5AfE4fRZH" name="uqwrweTFuwAAm5AfE4fRZH.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/uqwrweTFuwAAm5AfE4fRZH.png" mos="https://cdn.mos.cms.futurecdn.net/uqwrweTFuwAAm5AfE4fRZH.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Putting a spotlight on cyber security</strong></p><p class="fancy-box__body-text">An examination of the current cyber security landscape</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356123/putting-a-spotlight-on-cyber-security" data-original-url="/security/cyber-security/356123/putting-a-spotlight-on-cyber-security">FREE DOWNLOAD</a></p></div></div><p>The North Yorkshire Police was approached and the Cyber Crimes Unit launched an investigation, with digital forensic investigations showing that company data had been remotely accessed by somebody using Bulley’s IP address.</p><p>She was questioned and admitted to deleting the files, which she believe she was entitled to do, though she said she knew so would disrupt the operations of the new company. </p><p>Only a handful of people are charged under the CMA 1990 each year, perhaps a few dozen according to the constabulary, and cases often tend to be isolated and localised. One example, from 2018, involves a <a href="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution" target="_blank" data-original-url="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution">motor industry employee being sentenced to six months in prison</a> for accessing customer records using his colleague’s login details.</p><p>However, an organisation earlier this year <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">branded the legislation as out-of-date and claimed it prevents cyber security professionals</a> from properly doing their jobs. In a report published in January, the Criminal Law Reform Now Network (CLRNN) said the CMA imposed restrictions on journalists and academics investigating cyber threats in the public interest and is in dire need of reform.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/computer-misuse-act/356166/businesswoman-sentenced-after-illegally-deleting</link>
                                                                            <description>
                            <![CDATA[ Danielle Bulley accessed a company’s servers months after resigning as director from a previously linked firm that went into liquidation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wkC3jzXNupMS8xkhYwJwB2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wyRiG6qUGMqWvRX8Sn3viS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2020 09:21:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wyRiG6qUGMqWvRX8Sn3viS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person types on laptop in the dark]]></media:description>                                                            <media:text><![CDATA[Person types on laptop in the dark]]></media:text>
                                <media:title type="plain"><![CDATA[Person types on laptop in the dark]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wyRiG6qUGMqWvRX8Sn3viS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A woman has been prosecuted under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act (CMA) 1990</a> for deleting thousands of crucial files from the servers of a company that went into liquidation. </p><p>Danielle Bulley, former director of a property marketing firm, was found guilty of gaining unauthorised access to the servers of a new company that was created from its remains and deleting more than 5,000 documents.</p><p>The 58-year-old was charged with computer misuse offences and given an 18-month community order and unpaid work requirement when she appeared for sentence at York Crown Court, according to the <a href="https://northyorkshire.police.uk/news/businesswoman-sentenced" target="_blank">North Yorkshire Police</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" data-original-url="/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">Computer Misuse Act 'putting critical UK infrastructure at risk'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals" data-original-url="/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals">Almost 100 HMRC staff disciplined over computer misuse, FOI reveals</a></p></div></div><p>“During our investigation, it became clear that Bulley had left the original company on a bad note, but the deletion of thousands of files containing vital information was catastrophic for the victim. It dealt the new business a blow from which it never recovered,” said detective constable Steven Harris of the Cyber Crime Unit.</p><p>“Ex-employees can pose a serious risk to a business because they are familiar with the company’s IT infrastructure and procedures. This can make it easier for them to carry out <a href="https://www.itpro.com/security/cyber-security/355185/165-million-britons-experienced-a-cyber-crime-in-the-past-year" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/355185/165-million-britons-experienced-a-cyber-crime-in-the-past-year">cyber crimes</a> against their former organisation.</p><p>“We encourage businesses to ensure they have policies in place for removing user accounts and changing passwords when an employee leaves an organisation.”</p><p>Bulley resigned as a director from the new property marketing business, which was launched using the assets of the old company after it went into liquidation. Several months later she gained access to the new company’s servers and permanently deleted all their data. </p><p>The individual who ran the new firm said her actions caused job losses and financial losses of nearly £100,000. The damage to the company was so extensive, he added, that the company could no longer operate and was forced to go under.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uqwrweTFuwAAm5AfE4fRZH" name="uqwrweTFuwAAm5AfE4fRZH.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/uqwrweTFuwAAm5AfE4fRZH.png" mos="https://cdn.mos.cms.futurecdn.net/uqwrweTFuwAAm5AfE4fRZH.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Putting a spotlight on cyber security</strong></p><p class="fancy-box__body-text">An examination of the current cyber security landscape</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356123/putting-a-spotlight-on-cyber-security" data-original-url="/security/cyber-security/356123/putting-a-spotlight-on-cyber-security">FREE DOWNLOAD</a></p></div></div><p>The North Yorkshire Police was approached and the Cyber Crimes Unit launched an investigation, with digital forensic investigations showing that company data had been remotely accessed by somebody using Bulley’s IP address.</p><p>She was questioned and admitted to deleting the files, which she believe she was entitled to do, though she said she knew so would disrupt the operations of the new company. </p><p>Only a handful of people are charged under the CMA 1990 each year, perhaps a few dozen according to the constabulary, and cases often tend to be isolated and localised. One example, from 2018, involves a <a href="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution" target="_blank" data-original-url="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution">motor industry employee being sentenced to six months in prison</a> for accessing customer records using his colleague’s login details.</p><p>However, an organisation earlier this year <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk">branded the legislation as out-of-date and claimed it prevents cyber security professionals</a> from properly doing their jobs. In a report published in January, the Criminal Law Reform Now Network (CLRNN) said the CMA imposed restrictions on journalists and academics investigating cyber threats in the public interest and is in dire need of reform.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Computer Misuse Act 'putting critical UK infrastructure at risk' ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The key piece of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> legislation in the UK is outdated, inadequate and prevents cyber security professionals from doing their jobs.</p><p>With the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act 1990 (CMA)</a> turning 30 years-old this year, a collective of academics, legal practitioners and experts have branded the piece of legislation a danger to the UK’s general cyber resilience.</p><p>The CMA, in particular, is preventing <a href="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security" data-original-url="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security">cyber security professionals</a> from carrying out threat intelligence research against cyber criminals and internationally-based hackers, according to a report by the Criminal Law Reform Now Network (CLRNN).</p><p>The legislation also imposes restrictions on journalists and academics from researching cyber threats that are in the public interest.</p><p>“The Computer Misuse Act is crying out for reform,” said Simon McKay, a barrister specialising in civil liberties and human rights who led the CLRNN research. </p><p>“It needs to be future- and technology-proofed to ensure it can meet the challenges of protecting the embedded internet-based culture we all live in and depend on. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34783/237-police-officers-disciplined-over-computer-misuse" data-original-url="/computer-misuse-act/34783/237-police-officers-disciplined-over-computer-misuse">237 police officers disciplined over computer misuse</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals" data-original-url="/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals">Almost 100 HMRC staff disciplined over computer misuse, FOI reveals</a></p></div></div><p>“This report delivers a blueprint for the government to use and develop to make the law more effective in policing and prosecuting cybercrime.”</p><p>The CMA has been used by law enforcement agencies over the past 30 years to penalise people who attempt to access or modify data on a computer without appropriate authorisation. </p><p>Conventionally, this covers the broad scope of malware infections and cyber attacks, as well hacking into systems to <a href="https://www.itpro.com/data-protection/28020/data-protection-principles" data-original-url="https://www.itpro.com/data-protection/28020/data-protection-principles">obtain information or data</a> for future misuse.</p><p>A recent example of a prosecution under the CMA arose in 2018, when <a href="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution" data-original-url="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution">a motor industry employee was given a six-month prison sentence</a> for accessing thousands of customers’ personal records without permission. </p><p>One of the arguments made by the CLRNN against the CMA in its current form is that it offers a confused legal framework, with outdated and ambiguous terminology, and is too broad in its application. The inappropriate nature of this scope may serve to penalise or deter individuals carrying out cyber research that may benefit the UK’s cyber resilience but could be interpreted as criminal.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kcusE2ieoJMdvaiGWce22Y" name="kcusE2ieoJMdvaiGWce22Y.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/kcusE2ieoJMdvaiGWce22Y.png" mos="https://cdn.mos.cms.futurecdn.net/kcusE2ieoJMdvaiGWce22Y.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Strengthen your defences against cybercrime</strong></p><p class="fancy-box__body-text">Cyber resilience planning for email</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354076/strengthen-your-defences-against-cybercrime" data-original-url="/security/cyber-security/354076/strengthen-your-defences-against-cybercrime">FREE DOWNLOAD</a></p></div></div><p>The CLRNN report has outlined a host of recommendations for lawmakers to take into account. These include introducing a public interest defence that allows cyber security professionals, journalists and academics to carry out work that could potentially prevent future cyber attacks.</p><p>There should also be a set of new targeted guidance for prosecutors, including a laxer sentencing regime for younger offenders, as part of a wider overhaul in the sentencing guidelines.</p><p>“The legal case for reform of the Computer Misuse Act 1990 is overwhelming,” said senior lecturer in criminal law at Birmingham Law School and CLRNN’s co-director, Dr John Child."</p><p>“Experts from academia, legal practice and industry have collaborated to identify the best route to ensure proper penalties are enforced to enable prosecution of hackers and companies who benefit from their activities, whilst permitting responsible cyber security experts to do their job without fear of prosecution.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/computer-misuse-act/354600/computer-misuse-act-putting-critical-uk</link>
                                                                            <description>
                            <![CDATA[ The 30 year-old legislation also prevents cyber security professionals from doing their jobs, it's claimed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fJthYRrkso3NcACLRsX8bM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GLaKy5aL4HeSg5vvGxLU3b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jan 2020 11:27:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GLaKy5aL4HeSg5vvGxLU3b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Prioritise certain types of traffic]]></media:description>                                                            <media:text><![CDATA[Prioritise certain types of traffic]]></media:text>
                                <media:title type="plain"><![CDATA[Prioritise certain types of traffic]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GLaKy5aL4HeSg5vvGxLU3b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The key piece of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> legislation in the UK is outdated, inadequate and prevents cyber security professionals from doing their jobs.</p><p>With the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act 1990 (CMA)</a> turning 30 years-old this year, a collective of academics, legal practitioners and experts have branded the piece of legislation a danger to the UK’s general cyber resilience.</p><p>The CMA, in particular, is preventing <a href="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security" data-original-url="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security">cyber security professionals</a> from carrying out threat intelligence research against cyber criminals and internationally-based hackers, according to a report by the Criminal Law Reform Now Network (CLRNN).</p><p>The legislation also imposes restrictions on journalists and academics from researching cyber threats that are in the public interest.</p><p>“The Computer Misuse Act is crying out for reform,” said Simon McKay, a barrister specialising in civil liberties and human rights who led the CLRNN research. </p><p>“It needs to be future- and technology-proofed to ensure it can meet the challenges of protecting the embedded internet-based culture we all live in and depend on. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34783/237-police-officers-disciplined-over-computer-misuse" data-original-url="/computer-misuse-act/34783/237-police-officers-disciplined-over-computer-misuse">237 police officers disciplined over computer misuse</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals" data-original-url="/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals">Almost 100 HMRC staff disciplined over computer misuse, FOI reveals</a></p></div></div><p>“This report delivers a blueprint for the government to use and develop to make the law more effective in policing and prosecuting cybercrime.”</p><p>The CMA has been used by law enforcement agencies over the past 30 years to penalise people who attempt to access or modify data on a computer without appropriate authorisation. </p><p>Conventionally, this covers the broad scope of malware infections and cyber attacks, as well hacking into systems to <a href="https://www.itpro.com/data-protection/28020/data-protection-principles" data-original-url="https://www.itpro.com/data-protection/28020/data-protection-principles">obtain information or data</a> for future misuse.</p><p>A recent example of a prosecution under the CMA arose in 2018, when <a href="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution" data-original-url="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution">a motor industry employee was given a six-month prison sentence</a> for accessing thousands of customers’ personal records without permission. </p><p>One of the arguments made by the CLRNN against the CMA in its current form is that it offers a confused legal framework, with outdated and ambiguous terminology, and is too broad in its application. The inappropriate nature of this scope may serve to penalise or deter individuals carrying out cyber research that may benefit the UK’s cyber resilience but could be interpreted as criminal.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kcusE2ieoJMdvaiGWce22Y" name="kcusE2ieoJMdvaiGWce22Y.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/kcusE2ieoJMdvaiGWce22Y.png" mos="https://cdn.mos.cms.futurecdn.net/kcusE2ieoJMdvaiGWce22Y.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Strengthen your defences against cybercrime</strong></p><p class="fancy-box__body-text">Cyber resilience planning for email</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354076/strengthen-your-defences-against-cybercrime" data-original-url="/security/cyber-security/354076/strengthen-your-defences-against-cybercrime">FREE DOWNLOAD</a></p></div></div><p>The CLRNN report has outlined a host of recommendations for lawmakers to take into account. These include introducing a public interest defence that allows cyber security professionals, journalists and academics to carry out work that could potentially prevent future cyber attacks.</p><p>There should also be a set of new targeted guidance for prosecutors, including a laxer sentencing regime for younger offenders, as part of a wider overhaul in the sentencing guidelines.</p><p>“The legal case for reform of the Computer Misuse Act 1990 is overwhelming,” said senior lecturer in criminal law at Birmingham Law School and CLRNN’s co-director, Dr John Child."</p><p>“Experts from academia, legal practice and industry have collaborated to identify the best route to ensure proper penalties are enforced to enable prosecution of hackers and companies who benefit from their activities, whilst permitting responsible cyber security experts to do their job without fear of prosecution.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 237 police officers disciplined over computer misuse ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK's police forces have disciplined 237 serving officers and members of staff for computer misuse, according to a <a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request">Freedom of Information</a> (FOI) request.</p><p>Six employees have resigned and 11 have been sacked due to failing basic <a href="https://www.itpro.com/strategy/29244/what-is-the-itil-certification-and-why-do-you-need-it" target="_blank" data-original-url="https://www.itpro.com/strategy/29244/what-is-the-itil-certification-and-why-do-you-need-it">IT best practices</a>.</p><p>23 police forces responded to the FOI request made by think tank Parliament Steet. Of those, the Surrey and London Metropolitan police recorded the most disciplinary action over computer misuse.</p><p>The offences range from using police systems without legitimate purposes to sharing sensitive information over social media, and raise concerns over the privacy and security standards of the UK's law enforcement.</p><p>Over two financial years, the Surrey police force recorded 50 individual cases of IT abuse, with the majority of the incidents relating to misuse of email. The Met recorded 18 disciplinary accounts, with one sacking over the misuse of the Crime Reporting System.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/636331/police-it-a-mess-say-mps" data-original-url="/636331/police-it-a-mess-say-mps">Police IT a 'mess,’ say MPs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/34772/capita-partners-with-what3words-to-improve-999-emergency-locating" data-original-url="/digital-transformation/34772/capita-partners-with-what3words-to-improve-999-emergency-locating">Capita partners with What3Words to improve 999 emergency locating</a></p></div></div><p>The Met also disciplined four members of staff for misusing social media. Two employees from Hertfordshire's constabulary were reprimanded for the same reason, after taking photos of the force's systems and sharing them via social media.</p><p>Three officers each were sacked from both Gwent and Wiltshire forces for using the police databases without lawful access to the information. One member of the Nottinghamshire Police used its system to search for a civil dispute they were involved in.</p><p>"Instilling the highest standards of IT best practice in serving officers and operational staff is critical for maintaining the integrity of our police forces," Sheila Flavell, COO of recruitment service FDM Group.</p><p>"All too often these incidents arise due to a lack of training or understanding about the need for correctly handling sensitive information. With cyber crime on the rise, it's vital that those tasked with keeping us safe are proficient with technology and acutely aware of the importance of <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">data protection</a> rules."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/computer-misuse-act/34783/237-police-officers-disciplined-over-computer-misuse</link>
                                                                            <description>
                            <![CDATA[ FOI request reveals UK forces failing basic IT best practices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">koGCiQ1t9ufQwdV8RVXtqS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uyNqrc7WXQz39DK5whTTT3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Nov 2019 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uyNqrc7WXQz39DK5whTTT3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Police Sign]]></media:description>                                                            <media:text><![CDATA[Police Sign]]></media:text>
                                <media:title type="plain"><![CDATA[Police Sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uyNqrc7WXQz39DK5whTTT3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's police forces have disciplined 237 serving officers and members of staff for computer misuse, according to a <a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request">Freedom of Information</a> (FOI) request.</p><p>Six employees have resigned and 11 have been sacked due to failing basic <a href="https://www.itpro.com/strategy/29244/what-is-the-itil-certification-and-why-do-you-need-it" target="_blank" data-original-url="https://www.itpro.com/strategy/29244/what-is-the-itil-certification-and-why-do-you-need-it">IT best practices</a>.</p><p>23 police forces responded to the FOI request made by think tank Parliament Steet. Of those, the Surrey and London Metropolitan police recorded the most disciplinary action over computer misuse.</p><p>The offences range from using police systems without legitimate purposes to sharing sensitive information over social media, and raise concerns over the privacy and security standards of the UK's law enforcement.</p><p>Over two financial years, the Surrey police force recorded 50 individual cases of IT abuse, with the majority of the incidents relating to misuse of email. The Met recorded 18 disciplinary accounts, with one sacking over the misuse of the Crime Reporting System.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/636331/police-it-a-mess-say-mps" data-original-url="/636331/police-it-a-mess-say-mps">Police IT a 'mess,’ say MPs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/34772/capita-partners-with-what3words-to-improve-999-emergency-locating" data-original-url="/digital-transformation/34772/capita-partners-with-what3words-to-improve-999-emergency-locating">Capita partners with What3Words to improve 999 emergency locating</a></p></div></div><p>The Met also disciplined four members of staff for misusing social media. Two employees from Hertfordshire's constabulary were reprimanded for the same reason, after taking photos of the force's systems and sharing them via social media.</p><p>Three officers each were sacked from both Gwent and Wiltshire forces for using the police databases without lawful access to the information. One member of the Nottinghamshire Police used its system to search for a civil dispute they were involved in.</p><p>"Instilling the highest standards of IT best practice in serving officers and operational staff is critical for maintaining the integrity of our police forces," Sheila Flavell, COO of recruitment service FDM Group.</p><p>"All too often these incidents arise due to a lack of training or understanding about the need for correctly handling sensitive information. With cyber crime on the rise, it's vital that those tasked with keeping us safe are proficient with technology and acutely aware of the importance of <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">data protection</a> rules."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ex-Yahoo employee admits trawling through user accounts for explicit content ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A former software engineer with Yahoo has pled guilty to hacking into approximately 6,000 user accounts, including those of his friends and colleagues, in order to search for explicit or sexual material.</p><p>Reyes Daniel Ruiz, 34, has been accused of hacking into thousands of Yahoo accounts through his work at the company in an attempt to find sexual images and videos from the account holders.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals" data-original-url="/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals">Almost 100 HMRC staff disciplined over computer misuse, FOI reveals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution" data-original-url="/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution">Six-month sentence handed for data abuse in landmark ICO prosecution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32731/briton-sentenced-for-huge-cyber-attack-on-liberian-telco" data-original-url="/security/32731/briton-sentenced-for-huge-cyber-attack-on-liberian-telco">Briton sentenced for huge cyber attack on Liberian telco</a></p></div></div><p>These were accounts primarily belonging to younger women, according to the <a href="https://www.justice.gov/usao-ndca/pr/former-yahoo-software-engineer-pleads-guilty-using-work-access-hack-yahoo-users" target="_blank">US Attorney's Office for the Northern District of California</a>.</p><p>Ruiz made copies of images and videos he found without permission, and stored the data at his home. He also admitted to taking this a step further and compromising the iCloud, Facebook, Gmail, Dropbox and other online accounts of the victims in order to search for more explicit photos and videos.</p><p>"In pleading guilty, Ruiz, a former Yahoo software engineer, admitted to using his access through his work at the company to hack into about 6,000 Yahoo accounts," the US Attorney's Office said.</p><p>"Ruiz cracked user passwords, and accessed internal Yahoo systems to compromise the Yahoo accounts.</p><p>"After his employer observed the suspicious account activity, Ruiz admitted to destroying the computer and hard drive on which he stored the images."</p><p>Ruiz was indicted on 4 April and charged with one count of Computer Intrusion, and one count of Interception of a Wire Communication, pleading guilty to the latter. The maximum penalty for each count is five years in prison and a fine of $250,000.</p><p>Although these laws apply in the US only, one piece of legislation that serves as the equivalent in the UK is the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act 1990</a>, which is designed to prevent information theft from computer systems.</p><p>Research from 2016 found that <a href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">more than a third of employees were routinely violating this law</a>, although not to the extent of Ruiz's offences.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/34551/ex-yahoo-employee-admits-trawling-through-user-accounts-for-explicit-content</link>
                                                                            <description>
                            <![CDATA[ More than 6,000 users compromised as defendant also accessed iCloud, Facebook and Gmail accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7QaB7bzJadeTeAEzVHqUZL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mFkcFADErQwih7McDfaRYD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Oct 2019 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mFkcFADErQwih7McDfaRYD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Yahoo]]></media:description>                                                            <media:text><![CDATA[Yahoo]]></media:text>
                                <media:title type="plain"><![CDATA[Yahoo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mFkcFADErQwih7McDfaRYD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A former software engineer with Yahoo has pled guilty to hacking into approximately 6,000 user accounts, including those of his friends and colleagues, in order to search for explicit or sexual material.</p><p>Reyes Daniel Ruiz, 34, has been accused of hacking into thousands of Yahoo accounts through his work at the company in an attempt to find sexual images and videos from the account holders.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals" data-original-url="/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals">Almost 100 HMRC staff disciplined over computer misuse, FOI reveals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution" data-original-url="/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution">Six-month sentence handed for data abuse in landmark ICO prosecution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32731/briton-sentenced-for-huge-cyber-attack-on-liberian-telco" data-original-url="/security/32731/briton-sentenced-for-huge-cyber-attack-on-liberian-telco">Briton sentenced for huge cyber attack on Liberian telco</a></p></div></div><p>These were accounts primarily belonging to younger women, according to the <a href="https://www.justice.gov/usao-ndca/pr/former-yahoo-software-engineer-pleads-guilty-using-work-access-hack-yahoo-users" target="_blank">US Attorney's Office for the Northern District of California</a>.</p><p>Ruiz made copies of images and videos he found without permission, and stored the data at his home. He also admitted to taking this a step further and compromising the iCloud, Facebook, Gmail, Dropbox and other online accounts of the victims in order to search for more explicit photos and videos.</p><p>"In pleading guilty, Ruiz, a former Yahoo software engineer, admitted to using his access through his work at the company to hack into about 6,000 Yahoo accounts," the US Attorney's Office said.</p><p>"Ruiz cracked user passwords, and accessed internal Yahoo systems to compromise the Yahoo accounts.</p><p>"After his employer observed the suspicious account activity, Ruiz admitted to destroying the computer and hard drive on which he stored the images."</p><p>Ruiz was indicted on 4 April and charged with one count of Computer Intrusion, and one count of Interception of a Wire Communication, pleading guilty to the latter. The maximum penalty for each count is five years in prison and a fine of $250,000.</p><p>Although these laws apply in the US only, one piece of legislation that serves as the equivalent in the UK is the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act 1990</a>, which is designed to prevent information theft from computer systems.</p><p>Research from 2016 found that <a href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">more than a third of employees were routinely violating this law</a>, although not to the extent of Ruiz's offences.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Almost 100 HMRC staff disciplined over computer misuse, FOI reveals ]]></title>
                                                                                                <dc:content><![CDATA[ <p>HMRC has issued 92 disciplinary notices to members of staff as a result of computer misuse over the last two years, according to data released as part of a Freedom of Information request.</p><p>Covering the years 2017-18 and 2018-19, the results of a Parliament Street think tank <a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request">(FOI) request</a> showed that the number of disciplinary actions had increased with time, with the most common offence being that of "misuse of email".</p><p>Figures specifically detailed the number of first warnings, final warnings and dismissals given to employees relating to misuse of email, computer equipment, telecommunications, social media and other internet services.</p><p>The offence that led to the most dismissals was the misuse of computer equipment, resulting in eight dismissals in 17-18 and between one and five in 18-19.</p><p>Where results amounted to less than five, the exact figure wasn't issued due to fears that the individual may be identified, an eventuality that could breach <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and therefore ommitted under section 40(2) of the Freedom of Information Act 2000.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/privacy/33577/the-ico-compels-hmrc-to-delete-5m-biometric-records" data-original-url="/privacy/33577/the-ico-compels-hmrc-to-delete-5m-biometric-records">The ICO compels HMRC to delete five million biometric records</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents" data-original-url="/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents">Insider threats make up 74% of business cyber security incidents</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a></p></div></div><p>The most common offence committed over the two financial years was 'misuse of email', resulting in 25 written warnings, including both first and final, being issued by the UK's tax collector to its employees.</p><p>There was a sharp rise in <a href="https://www.itpro.com/social-media/33367/developing-your-social-media-voice-and-following" target="_blank" data-original-url="https://www.itpro.com/social-media/33367/developing-your-social-media-voice-and-following">social media</a> offences in 18-19, leading to nine written warnings compared to zero in the previous year.</p><p>What constitutes "misuse" isn't clearly defined in HMRC's reply to the FOI request, nor is it clear what the specific offences were to warrant each type of disciplinary action.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CNxjYtvhLk5uFnMyNhVskH" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/CNxjYtvhLk5uFnMyNhVskH.png" mos="https://cdn.mos.cms.futurecdn.net/CNxjYtvhLk5uFnMyNhVskH.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4hQ5dijAh4LFDuzgeE94k9" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/4hQ5dijAh4LFDuzgeE94k9.png" mos="https://cdn.mos.cms.futurecdn.net/4hQ5dijAh4LFDuzgeE94k9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>What's encouraging is that in nearly all areas, except for social media, the number of disciplined offences appeared to decrease or stay the same which indicates that employees might be becoming more aware of how their actions could lead to damaging data breaches.</p><p>"Tackling employee misuse of IT systems should be a top priority for all public sector organisations, particularly those which handle the financial data of millions of people," said Christy Wyatt, CEO at Absolute Software.</p><p>"This kind of activity often involves individuals abusing access to personal information and in some cases sharing it, leading to a potential data breach. Organisations like HMRC need to adopt an enterprise resilience mindset not only around potential bad employee behaviour, but fortifying their overall security posture and risk management profile."</p><p>It also appears that HMRC doesn't have to issue warnings before ordering the dismissal of staff. Taken from the 17-18 figures, the number of written first warnings given to staff was less than the number of issued dismissals for the same offence in the same year.</p><p>According to <a href="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents" target="_blank" data-original-url="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents">a 2017 report</a>, 74% of enterprise cyber security incidents can be attributed to insider threats such as employees, so having a robust disciplinary framework for public sector IT misuse is in HMRC's best interests.</p><p>The threat of data incidents from rogue employees is still as high today as it was in 2017. A <a href="https://www.itpro.com/data-breaches/33731/more-than-half-of-uk-employees-admit-to-stealing-corporate-data" target="_blank" data-original-url="https://www.itpro.com/data-breaches/33731/more-than-half-of-uk-employees-admit-to-stealing-corporate-data">report from Deep Secure</a> indicated that more than half of UK employees would be willing to steal and sell company data on to third-parties. A quarter of respondents said they could be swayed for as little as 1,000.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/computer-misuse-act/34541/almost-100-hmrc-staff-disciplined-over-computer-misuse-foi-reveals</link>
                                                                            <description>
                            <![CDATA[ Staff dismissed over misuse of emails, computer equipment and social media ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e49dvN66kQopU7BXsHT4v6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZJmoGNzxRRdCxktPaxjAPS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Oct 2019 10:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZJmoGNzxRRdCxktPaxjAPS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[HMRC logo appearing on a smartphone which is nestled in the pocket of someone&amp;#039;s jeans]]></media:description>                                                            <media:text><![CDATA[HMRC logo appearing on a smartphone which is nestled in the pocket of someone&amp;#039;s jeans]]></media:text>
                                <media:title type="plain"><![CDATA[HMRC logo appearing on a smartphone which is nestled in the pocket of someone&amp;#039;s jeans]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZJmoGNzxRRdCxktPaxjAPS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>HMRC has issued 92 disciplinary notices to members of staff as a result of computer misuse over the last two years, according to data released as part of a Freedom of Information request.</p><p>Covering the years 2017-18 and 2018-19, the results of a Parliament Street think tank <a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request">(FOI) request</a> showed that the number of disciplinary actions had increased with time, with the most common offence being that of "misuse of email".</p><p>Figures specifically detailed the number of first warnings, final warnings and dismissals given to employees relating to misuse of email, computer equipment, telecommunications, social media and other internet services.</p><p>The offence that led to the most dismissals was the misuse of computer equipment, resulting in eight dismissals in 17-18 and between one and five in 18-19.</p><p>Where results amounted to less than five, the exact figure wasn't issued due to fears that the individual may be identified, an eventuality that could breach <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and therefore ommitted under section 40(2) of the Freedom of Information Act 2000.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/privacy/33577/the-ico-compels-hmrc-to-delete-5m-biometric-records" data-original-url="/privacy/33577/the-ico-compels-hmrc-to-delete-5m-biometric-records">The ICO compels HMRC to delete five million biometric records</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents" data-original-url="/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents">Insider threats make up 74% of business cyber security incidents</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a></p></div></div><p>The most common offence committed over the two financial years was 'misuse of email', resulting in 25 written warnings, including both first and final, being issued by the UK's tax collector to its employees.</p><p>There was a sharp rise in <a href="https://www.itpro.com/social-media/33367/developing-your-social-media-voice-and-following" target="_blank" data-original-url="https://www.itpro.com/social-media/33367/developing-your-social-media-voice-and-following">social media</a> offences in 18-19, leading to nine written warnings compared to zero in the previous year.</p><p>What constitutes "misuse" isn't clearly defined in HMRC's reply to the FOI request, nor is it clear what the specific offences were to warrant each type of disciplinary action.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CNxjYtvhLk5uFnMyNhVskH" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/CNxjYtvhLk5uFnMyNhVskH.png" mos="https://cdn.mos.cms.futurecdn.net/CNxjYtvhLk5uFnMyNhVskH.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4hQ5dijAh4LFDuzgeE94k9" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/4hQ5dijAh4LFDuzgeE94k9.png" mos="https://cdn.mos.cms.futurecdn.net/4hQ5dijAh4LFDuzgeE94k9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>What's encouraging is that in nearly all areas, except for social media, the number of disciplined offences appeared to decrease or stay the same which indicates that employees might be becoming more aware of how their actions could lead to damaging data breaches.</p><p>"Tackling employee misuse of IT systems should be a top priority for all public sector organisations, particularly those which handle the financial data of millions of people," said Christy Wyatt, CEO at Absolute Software.</p><p>"This kind of activity often involves individuals abusing access to personal information and in some cases sharing it, leading to a potential data breach. Organisations like HMRC need to adopt an enterprise resilience mindset not only around potential bad employee behaviour, but fortifying their overall security posture and risk management profile."</p><p>It also appears that HMRC doesn't have to issue warnings before ordering the dismissal of staff. Taken from the 17-18 figures, the number of written first warnings given to staff was less than the number of issued dismissals for the same offence in the same year.</p><p>According to <a href="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents" target="_blank" data-original-url="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents">a 2017 report</a>, 74% of enterprise cyber security incidents can be attributed to insider threats such as employees, so having a robust disciplinary framework for public sector IT misuse is in HMRC's best interests.</p><p>The threat of data incidents from rogue employees is still as high today as it was in 2017. A <a href="https://www.itpro.com/data-breaches/33731/more-than-half-of-uk-employees-admit-to-stealing-corporate-data" target="_blank" data-original-url="https://www.itpro.com/data-breaches/33731/more-than-half-of-uk-employees-admit-to-stealing-corporate-data">report from Deep Secure</a> indicated that more than half of UK employees would be willing to steal and sell company data on to third-parties. A quarter of respondents said they could be swayed for as little as 1,000.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Six-month sentence handed for data abuse in landmark ICO prosecution  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A motor industry employee has been given a six-month prison sentence for accessing customer records without permission in a landmark prosecution led by the Information Commissioner's Office (ICO).</p><p>Mustafa Kasim pleaded guilty on one charge of securing unauthorised access to personal data between January and October 2016, and was sentenced to six months under the Computer Misuse Act (CMA) 1990.</p><p>Kasim, who worked for accident repair firm Nationwide Accident Repair Services (NARS), accessed the personal data of thousands of customers on the Audatex IT platform using his colleagues' login details.</p><p>This is the first time the ICO has led a prosecution charge in 28 years since the Act came into force, and was motivated by a desire to inflict a tougher punishment on Mustafa Kasim than is conventionally handed for data misuse.</p><p>"People who think it's worth their while to obtain and disclose personal data without permission should think again," said the ICO's group manager of the criminal investigations team <a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/11/six-month-prison-sentence-for-motor-industry-employee-in-first-ico-computer-misuse-act-prosecution" target="_blank">Mike Shaw</a>.</p><p>"Although this was a data protection issue, in this case we were able to prosecute beyond data protection laws resulting in a tougher penalty to reflect the nature of the criminal behaviour.</p><p>"Members of the public and organisations can be assured that we will push the boundaries and use any tool at our disposal to protect their rights."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk" data-original-url="/data-protection/28029/latest-gdpr-news-uk">GDPR news: GDPR turns six months old</a></p></div></div><p>Kasim continued to access customers' personal data when he left NARS and started a new job at a different car repair organisation which used the same software. These details included customers' names, phone numbers, as well as vehicle and accident information.</p><p>NARS approached the ICO upon receiving increased complaints from customers about receiving nuisance calls.</p><p>"Data obtained in these circumstances is a valuable commodity, and there was evidence of customers receiving unwarranted calls from claims management companies causing unnecessary anxiety and distress," Shaw continued.</p><p>"The potential reputational damage to affected companies whose data is stolen in this way can be immeasurable. Both Nationwide Accident Repair Services and Audatex have put appropriate technical and organisational measures in place to ensure that this cannot happen again."</p><p>Cases such as this, concerning data abuse, are normally prosecuted under Data Protection Act (DPA) 1998, or the EU's General Data Protection Regulation (GDPR) which came into force earlier this year.</p><p>However, with the timing of the case rendering GDPR inapplicable, and punishment under the DPA 1998 not deemed severe enough, the ICO opted to prosecute Kasim under different legislation.</p><p>In this case, the ICO chose section one of the CMA 1990, which prohibits the use of a computer to intentionally gain access to programmes or data held. This offence carries a maximum prison sentence of two years.</p><p>The data regulator said "in appropriate cases" it had the remit to prosecute cases via alternative legislation "to reflect the nature and extent" of offences, and so that the court has "a wider range of penalties available".</p><p>"This was an appropriate case to pursue under CMA 1990 because the seriousness of this particular offence, which had a number of aggravating factors, meant that a sentence limited to a fine under the DPA would not have reflected the culpability of the offender," an ICO spokesperson told <em>IT Pro</em>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/computer-misuse-act/32347/six-month-sentence-handed-for-data-abuse-in-landmark-ico-prosecution</link>
                                                                            <description>
                            <![CDATA[ Data regulator hints seeking tougher punishment was an effort to change behaviour in how personal data is held and processed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qqidkSv1RiWjNaqu3pP5tF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/C959qm8qY5aCqWs7zTQ66B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 Nov 2018 10:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/C959qm8qY5aCqWs7zTQ66B-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[gavel and keyboard]]></media:description>                                                            <media:text><![CDATA[gavel and keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[gavel and keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/C959qm8qY5aCqWs7zTQ66B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A motor industry employee has been given a six-month prison sentence for accessing customer records without permission in a landmark prosecution led by the Information Commissioner's Office (ICO).</p><p>Mustafa Kasim pleaded guilty on one charge of securing unauthorised access to personal data between January and October 2016, and was sentenced to six months under the Computer Misuse Act (CMA) 1990.</p><p>Kasim, who worked for accident repair firm Nationwide Accident Repair Services (NARS), accessed the personal data of thousands of customers on the Audatex IT platform using his colleagues' login details.</p><p>This is the first time the ICO has led a prosecution charge in 28 years since the Act came into force, and was motivated by a desire to inflict a tougher punishment on Mustafa Kasim than is conventionally handed for data misuse.</p><p>"People who think it's worth their while to obtain and disclose personal data without permission should think again," said the ICO's group manager of the criminal investigations team <a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/11/six-month-prison-sentence-for-motor-industry-employee-in-first-ico-computer-misuse-act-prosecution" target="_blank">Mike Shaw</a>.</p><p>"Although this was a data protection issue, in this case we were able to prosecute beyond data protection laws resulting in a tougher penalty to reflect the nature of the criminal behaviour.</p><p>"Members of the public and organisations can be assured that we will push the boundaries and use any tool at our disposal to protect their rights."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28029/latest-gdpr-news-uk" data-original-url="/data-protection/28029/latest-gdpr-news-uk">GDPR news: GDPR turns six months old</a></p></div></div><p>Kasim continued to access customers' personal data when he left NARS and started a new job at a different car repair organisation which used the same software. These details included customers' names, phone numbers, as well as vehicle and accident information.</p><p>NARS approached the ICO upon receiving increased complaints from customers about receiving nuisance calls.</p><p>"Data obtained in these circumstances is a valuable commodity, and there was evidence of customers receiving unwarranted calls from claims management companies causing unnecessary anxiety and distress," Shaw continued.</p><p>"The potential reputational damage to affected companies whose data is stolen in this way can be immeasurable. Both Nationwide Accident Repair Services and Audatex have put appropriate technical and organisational measures in place to ensure that this cannot happen again."</p><p>Cases such as this, concerning data abuse, are normally prosecuted under Data Protection Act (DPA) 1998, or the EU's General Data Protection Regulation (GDPR) which came into force earlier this year.</p><p>However, with the timing of the case rendering GDPR inapplicable, and punishment under the DPA 1998 not deemed severe enough, the ICO opted to prosecute Kasim under different legislation.</p><p>In this case, the ICO chose section one of the CMA 1990, which prohibits the use of a computer to intentionally gain access to programmes or data held. This offence carries a maximum prison sentence of two years.</p><p>The data regulator said "in appropriate cases" it had the remit to prosecute cases via alternative legislation "to reflect the nature and extent" of offences, and so that the court has "a wider range of penalties available".</p><p>"This was an appropriate case to pursue under CMA 1990 because the seriousness of this particular offence, which had a number of aggravating factors, meant that a sentence limited to a fine under the DPA would not have reflected the culpability of the offender," an ICO spokesperson told <em>IT Pro</em>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC unveils new cyber attack classification system ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK's national cyber security body has announced a new categorisation system to classify cyber attacks, in an effort to help intelligence operatives and law enforcement prioritise their response to hacks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever" data-original-url="/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever">Scale of cyber risk to UK businesses is "bigger than ever"</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/30462/ncsc-blocks-millions-of-cyber-attacks-launched-against-uk" data-original-url="/national-cyber-security-centre-ncsc/30462/ncsc-blocks-millions-of-cyber-attacks-launched-against-uk">NCSC blocks millions of cyber attacks launched against UK</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/30685/ncsc-cyber-crime-is-a-major-threat-to-uk-charities" data-original-url="/cyber-security/30685/ncsc-cyber-crime-is-a-major-threat-to-uk-charities">NCSC: Cyber crime is a major threat to UK charities</a></p></div></div><p>As part of its inaugural CYBERUK security conference, the National Cyber Security Centre (NCSC) yesterday launched the new framework, which comprises six levels of severity, from a minor individual attack all the way up to a catastrophic attack on the UK's national infrastructure.</p><p>Upon identifying an attack, the NCSC's incident response teams will use the new framework to classify the attack and allocate the appropriate resources to deal with it based on the severity of the incident.</p><p>"This new joint approach, developed in partnership with UK law enforcement, will strengthen the UK's ability to respond to the significant, growing and diverse cyber threats we face," said NCSC director of operations, Paul Chichester. "The new system will offer an improved framework for dealing with incidents, especially as GDPR and the NIS Directive come into force shortly."</p><p>Attack categories range from one to six based on impact and severity, with a category six attack defined as a "localised incident" such as an individual being hacked. This level of attack, according to the NCSC, will typically only warrant a direct response from local police, acting in a support capacity.</p><p>Responses to more severe attacks - such as a category three "significant incident" - will be led by the NCSC directly, who will be on-hand to provide remote analysis, as well as on-site support.</p><p>The highest level of threat is the category one "national cyber emergency". This type of threat - which NCSC head Ciaran Martin has warned the UK <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns" target="_blank" data-original-url="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns">will inevitably face sooner or later</a> - is one which attacks critical infrastructure like power grids, utilities or hospitals and leads to "severe economic or social consequences or to loss of life".</p><p>In the event of a category one attack, a "coordinated cross-government response" will be spearheaded by COBRA, with NCSC and law enforcement working closely with relevant government departments to offer mitigation and analysis.</p><div ><table><tbody><tr><td  ></td><td  ><strong>Category definition</strong></td><td  ><strong>Who responds?</strong></td><td  ><strong>What do they do?</strong></td></tr><tr><td  ><strong>Category 1</strong><strong>National cyber emergency</strong></td><td  >A cyber attack which causes sustained disruption of UK essential services or affects UK national security, leading to severe economic or social consequences or to loss of life.</td><td  >Immediate, rapid and coordinated cross-government response. Strategic leadership from Ministers / Cabinet Office (COBR), tactical cross-government coordination by NCSC, working closely with Law Enforcement.</td><td  >Coordinated on-site presence for evidence gathering, forensic acquisition and support. Collocation of NCSC, Law Enforcement, Lead Government Departments and others where possible for enhanced response.</td></tr><tr><td  ><strong>Category 2</strong><strong>Highly significant incident</strong></td><td  >A cyber attack which has a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.</td><td  >Response typically led by NCSC (escalated to COBR if necessary), working closely with Law Enforcement (typically NCA) as required. Cross-government response coordinated by NCSC.</td><td  >NCSC will often provide on-site response, investigation and analysis, aligned with Law Enforcement criminal investigation activities.</td></tr><tr><td  ><strong>Category 3</strong><strong>Significant incident</strong></td><td  >A cyber attack which has a serious impact on a large organisation or on wider / local government, or which poses a considerable risk to central government or UK essential services.</td><td  >Response typically led by NCSC, working with Law Enforcement (typically NCA) as required.</td><td  >NCSC will provide remote support and analysis, standard guidance; on-site NCSC or NCA support may be provided.</td></tr><tr><td  ><strong>Category 4</strong><strong>Substantial incident</strong></td><td  >A cyber attack which has a serious impact on a medium-sized organisation, or which poses a considerable risk to a large organisation or wider / local government.</td><td  >Response led either by NCSC or by Law Enforcement (NCA or ROCU), dependent on the incident.</td><td  >NCSC or Law Enforcement will provide remote support and standard guidance, or on-site support by exception.</td></tr><tr><td  ><strong>Category 5</strong><strong>Moderate incident</strong></td><td  >A cyber attack on a small organisation, or which poses a considerable risk to a medium-sized organisation, or preliminary indications of cyber activity against a large organisation or the government.</td><td  >Response led by Law Enforcement (likely ROCU or local Police Force), with NCA input as required.</td><td  >Law Enforcement will provide remote support and standard guidance, with on-site response by exception.</td></tr><tr><td  ><strong>Category 6</strong><strong>Localised incident</strong></td><td  >A cyber attack on an individual, or preliminary indications of cyber activity against a small or medium-sized organisation.</td><td  >Automated Protect advice or local response led by Law Enforcement (likely local Police Force).</td><td  >Remote support and provision of standard advice. On-site response by exception.</td></tr></tbody></table></div><p>The announcement has been welcomed by top law enforcement officials.</p><p>National Police Chiefs' council lead for cybercrime, chief constable Peter Goodman, said: "This is a hugely important step forward in joint working between law enforcement and the intelligence agencies.</p><p>"Sharing a common lexicon enables a collaborative understanding of risk and severity that will ensure that we provide an effective, joined-up response. This is good news for the safety of our communities, business and individuals."</p><p>The new category framework will replace the existing three-tiered structure, and will go into effect immediately.</p><p><em>Picture: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/national-cyber-security-centre-ncsc/30926/ncsc-unveils-new-cyber-attack-classification-system</link>
                                                                            <description>
                            <![CDATA[ The framework categorises everything from individual hacks up to national cyber emergencies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sBtoGX89t2sv9riemBw4zN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6JP4nYwoULENLMPR8kYKda-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Apr 2018 09:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6JP4nYwoULENLMPR8kYKda-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker typing on a keyboard]]></media:description>                                                            <media:text><![CDATA[Hacker typing on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker typing on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6JP4nYwoULENLMPR8kYKda-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's national cyber security body has announced a new categorisation system to classify cyber attacks, in an effort to help intelligence operatives and law enforcement prioritise their response to hacks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever" data-original-url="/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever">Scale of cyber risk to UK businesses is "bigger than ever"</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/30462/ncsc-blocks-millions-of-cyber-attacks-launched-against-uk" data-original-url="/national-cyber-security-centre-ncsc/30462/ncsc-blocks-millions-of-cyber-attacks-launched-against-uk">NCSC blocks millions of cyber attacks launched against UK</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/30685/ncsc-cyber-crime-is-a-major-threat-to-uk-charities" data-original-url="/cyber-security/30685/ncsc-cyber-crime-is-a-major-threat-to-uk-charities">NCSC: Cyber crime is a major threat to UK charities</a></p></div></div><p>As part of its inaugural CYBERUK security conference, the National Cyber Security Centre (NCSC) yesterday launched the new framework, which comprises six levels of severity, from a minor individual attack all the way up to a catastrophic attack on the UK's national infrastructure.</p><p>Upon identifying an attack, the NCSC's incident response teams will use the new framework to classify the attack and allocate the appropriate resources to deal with it based on the severity of the incident.</p><p>"This new joint approach, developed in partnership with UK law enforcement, will strengthen the UK's ability to respond to the significant, growing and diverse cyber threats we face," said NCSC director of operations, Paul Chichester. "The new system will offer an improved framework for dealing with incidents, especially as GDPR and the NIS Directive come into force shortly."</p><p>Attack categories range from one to six based on impact and severity, with a category six attack defined as a "localised incident" such as an individual being hacked. This level of attack, according to the NCSC, will typically only warrant a direct response from local police, acting in a support capacity.</p><p>Responses to more severe attacks - such as a category three "significant incident" - will be led by the NCSC directly, who will be on-hand to provide remote analysis, as well as on-site support.</p><p>The highest level of threat is the category one "national cyber emergency". This type of threat - which NCSC head Ciaran Martin has warned the UK <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns" target="_blank" data-original-url="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns">will inevitably face sooner or later</a> - is one which attacks critical infrastructure like power grids, utilities or hospitals and leads to "severe economic or social consequences or to loss of life".</p><p>In the event of a category one attack, a "coordinated cross-government response" will be spearheaded by COBRA, with NCSC and law enforcement working closely with relevant government departments to offer mitigation and analysis.</p><div ><table><tbody><tr><td  ></td><td  ><strong>Category definition</strong></td><td  ><strong>Who responds?</strong></td><td  ><strong>What do they do?</strong></td></tr><tr><td  ><strong>Category 1</strong><strong>National cyber emergency</strong></td><td  >A cyber attack which causes sustained disruption of UK essential services or affects UK national security, leading to severe economic or social consequences or to loss of life.</td><td  >Immediate, rapid and coordinated cross-government response. Strategic leadership from Ministers / Cabinet Office (COBR), tactical cross-government coordination by NCSC, working closely with Law Enforcement.</td><td  >Coordinated on-site presence for evidence gathering, forensic acquisition and support. Collocation of NCSC, Law Enforcement, Lead Government Departments and others where possible for enhanced response.</td></tr><tr><td  ><strong>Category 2</strong><strong>Highly significant incident</strong></td><td  >A cyber attack which has a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.</td><td  >Response typically led by NCSC (escalated to COBR if necessary), working closely with Law Enforcement (typically NCA) as required. Cross-government response coordinated by NCSC.</td><td  >NCSC will often provide on-site response, investigation and analysis, aligned with Law Enforcement criminal investigation activities.</td></tr><tr><td  ><strong>Category 3</strong><strong>Significant incident</strong></td><td  >A cyber attack which has a serious impact on a large organisation or on wider / local government, or which poses a considerable risk to central government or UK essential services.</td><td  >Response typically led by NCSC, working with Law Enforcement (typically NCA) as required.</td><td  >NCSC will provide remote support and analysis, standard guidance; on-site NCSC or NCA support may be provided.</td></tr><tr><td  ><strong>Category 4</strong><strong>Substantial incident</strong></td><td  >A cyber attack which has a serious impact on a medium-sized organisation, or which poses a considerable risk to a large organisation or wider / local government.</td><td  >Response led either by NCSC or by Law Enforcement (NCA or ROCU), dependent on the incident.</td><td  >NCSC or Law Enforcement will provide remote support and standard guidance, or on-site support by exception.</td></tr><tr><td  ><strong>Category 5</strong><strong>Moderate incident</strong></td><td  >A cyber attack on a small organisation, or which poses a considerable risk to a medium-sized organisation, or preliminary indications of cyber activity against a large organisation or the government.</td><td  >Response led by Law Enforcement (likely ROCU or local Police Force), with NCA input as required.</td><td  >Law Enforcement will provide remote support and standard guidance, with on-site response by exception.</td></tr><tr><td  ><strong>Category 6</strong><strong>Localised incident</strong></td><td  >A cyber attack on an individual, or preliminary indications of cyber activity against a small or medium-sized organisation.</td><td  >Automated Protect advice or local response led by Law Enforcement (likely local Police Force).</td><td  >Remote support and provision of standard advice. On-site response by exception.</td></tr></tbody></table></div><p>The announcement has been welcomed by top law enforcement officials.</p><p>National Police Chiefs' council lead for cybercrime, chief constable Peter Goodman, said: "This is a hugely important step forward in joint working between law enforcement and the intelligence agencies.</p><p>"Sharing a common lexicon enables a collaborative understanding of risk and severity that will ensure that we provide an effective, joined-up response. This is good news for the safety of our communities, business and individuals."</p><p>The new category framework will replace the existing three-tiered structure, and will go into effect immediately.</p><p><em>Picture: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ British 'hacker' Lauri Love wins High Court appeal against US extradition ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Alleged computer hacker Lauri Love today <a href="https://www.judiciary.gov.uk/wp-content/uploads/2018/02/lauri-love-v-usa.pdf" target="_blank">won his High Court appeal</a> against extradition to the US to answer to charges of hacking into the computer systems of the FBI, the US Central Bank and NASA, among others.</p><p>Royal Courts of Justice judges ruled this morning that extraditing Love to the US, where he would face three separate trials, would be "oppressive" owing to the 32-year-old's likely determination to commit suicide in a US prison, considering any measures to prevent him from doing so further detrimental to his mental and physical health, with the resulting stress worsening a severe eczema condition he has, which would then impact depression he suffers from.</p><p>Instead Lord Chief Justice Lord Burnett and Justice Ouseley permitted his appeal against his extradition, stating it would "not be oppressive" to "prosecute Love in England for the offences".</p><p>"The support of his family, in particular, would mean that he would be at far lower a risk of suicide in consequence," they stated. "On the evidence we have seen, his mental and physical condition would survive imprisonment without such significant deterioration, though it would undoubtedly be more problematic for him than for many prisoners." </p><p>Love is accused of committing the alleged offences between 2012 and 2013, hacking into and stealing vast amounts of data from the US organisations.</p><p>Speaking <a href="http://www.bbc.co.uk/news/uk-england-42946540" target="_blank">to the</a> <em><a href="http://www.bbc.co.uk/news/uk-england-42946540" target="_blank">BBC</a></em> outside the court after the hearing, Love said he was "very thankful for all the support" he had received and hoped he had set a "precedent so this will not happen to people in the future".</p><p>The decision comes only <a href="https://www.itpro.com/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case">three months after more than 70 MPs called</a> on the prime minister to intervene in Love's extradition, writing to the UK attorney general to warn of "potentially fatal consequences" if he stands trial there.</p><p>The cross-party group of parliamentarians, including digital minister Matt Hancock, Love's constituency MP, called for the 32-year-old to face trial in the UK.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order" data-original-url="/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order">Lauri Love wins right to appeal extradition order</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case" data-original-url="/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case">MPs call on PM to intervene in Lauri Love extradition case</a></p></div></div><p>A Westminster magistrate <a href="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order" target="_blank" data-original-url="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order">approved his extradition in September 2016</a>, but Love appealed against it after home secretary Amber Rudd subsequently ordered his extradition last November.</p><p>Love, who has Asperger Syndrome, also suffers from severe eczema that is resistant to antibiotics, and has major depression. His parents have constantly stated that they are the only people with whom Love could live, and that they have prevented him from killing himself.</p><p>Naomi Colvin, Love's case director at the Courage Foundation, which is providing Love with legal support, said: "This is the result Lauri and his family have spent four years waiting for. This ruling is a massive victory for free expression online, for the fair treatment of neurodiverse people and for those of us who have drawn attention to the dire treatment of hackers and information activists in the United States. This ruling will be taken as a comment on the growing international isolation of the US under the Trump administration, and rightly so.</p><p>"I am absolutely thrilled for Lauri, his family, friends, his legal team and all the supporters who have worked so hard to bring us to this point. As we demonstrated at appeal, Lauri was only ever in this position because he had been marked out for unfair, discriminatory and vindictive treatment. With any luck, today's ruling will mean that prosecuting authorities finally start respecting the clear will of the British public: we do not extradite our geeks to face medieval punishment in the United States."</p><p>The Crown Prosecution Service is now expected to attempt to prosecute Love in the UK for the alleged offences, and the court said it expected US authorities to provide assistance.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cyber-crime/30464/british-hacker-lauri-love-wins-high-court-appeal-against-us-extradition</link>
                                                                            <description>
                            <![CDATA[ Love is now expected to stand trial in the UK on charges of US hacking ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dh7FmL18aCoJL19bck8sG4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/59rNNZsEXMd3UipDsS98k9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Feb 2018 13:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lee Bell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/59rNNZsEXMd3UipDsS98k9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The CMA has made an application to obtain an Order]]></media:description>                                                            <media:text><![CDATA[The CMA has made an application to obtain an Order]]></media:text>
                                <media:title type="plain"><![CDATA[The CMA has made an application to obtain an Order]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/59rNNZsEXMd3UipDsS98k9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Alleged computer hacker Lauri Love today <a href="https://www.judiciary.gov.uk/wp-content/uploads/2018/02/lauri-love-v-usa.pdf" target="_blank">won his High Court appeal</a> against extradition to the US to answer to charges of hacking into the computer systems of the FBI, the US Central Bank and NASA, among others.</p><p>Royal Courts of Justice judges ruled this morning that extraditing Love to the US, where he would face three separate trials, would be "oppressive" owing to the 32-year-old's likely determination to commit suicide in a US prison, considering any measures to prevent him from doing so further detrimental to his mental and physical health, with the resulting stress worsening a severe eczema condition he has, which would then impact depression he suffers from.</p><p>Instead Lord Chief Justice Lord Burnett and Justice Ouseley permitted his appeal against his extradition, stating it would "not be oppressive" to "prosecute Love in England for the offences".</p><p>"The support of his family, in particular, would mean that he would be at far lower a risk of suicide in consequence," they stated. "On the evidence we have seen, his mental and physical condition would survive imprisonment without such significant deterioration, though it would undoubtedly be more problematic for him than for many prisoners." </p><p>Love is accused of committing the alleged offences between 2012 and 2013, hacking into and stealing vast amounts of data from the US organisations.</p><p>Speaking <a href="http://www.bbc.co.uk/news/uk-england-42946540" target="_blank">to the</a> <em><a href="http://www.bbc.co.uk/news/uk-england-42946540" target="_blank">BBC</a></em> outside the court after the hearing, Love said he was "very thankful for all the support" he had received and hoped he had set a "precedent so this will not happen to people in the future".</p><p>The decision comes only <a href="https://www.itpro.com/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case">three months after more than 70 MPs called</a> on the prime minister to intervene in Love's extradition, writing to the UK attorney general to warn of "potentially fatal consequences" if he stands trial there.</p><p>The cross-party group of parliamentarians, including digital minister Matt Hancock, Love's constituency MP, called for the 32-year-old to face trial in the UK.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order" data-original-url="/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order">Lauri Love wins right to appeal extradition order</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case" data-original-url="/policy-legislation/30000/mps-call-on-pm-to-intervene-in-lauri-love-extradition-case">MPs call on PM to intervene in Lauri Love extradition case</a></p></div></div><p>A Westminster magistrate <a href="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order" target="_blank" data-original-url="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order">approved his extradition in September 2016</a>, but Love appealed against it after home secretary Amber Rudd subsequently ordered his extradition last November.</p><p>Love, who has Asperger Syndrome, also suffers from severe eczema that is resistant to antibiotics, and has major depression. His parents have constantly stated that they are the only people with whom Love could live, and that they have prevented him from killing himself.</p><p>Naomi Colvin, Love's case director at the Courage Foundation, which is providing Love with legal support, said: "This is the result Lauri and his family have spent four years waiting for. This ruling is a massive victory for free expression online, for the fair treatment of neurodiverse people and for those of us who have drawn attention to the dire treatment of hackers and information activists in the United States. This ruling will be taken as a comment on the growing international isolation of the US under the Trump administration, and rightly so.</p><p>"I am absolutely thrilled for Lauri, his family, friends, his legal team and all the supporters who have worked so hard to bring us to this point. As we demonstrated at appeal, Lauri was only ever in this position because he had been marked out for unfair, discriminatory and vindictive treatment. With any luck, today's ruling will mean that prosecuting authorities finally start respecting the clear will of the British public: we do not extradite our geeks to face medieval punishment in the United States."</p><p>The Crown Prosecution Service is now expected to attempt to prosecute Love in the UK for the alleged offences, and the court said it expected US authorities to provide assistance.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 36% of ex-employees are breaking the computer misuse act ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Over a third of IT workers have admitted to accessing corporate systems after they have left a company, potentially breaching the Computer Misuse Act.</p><p>According to a survey carried out by Vason Bourne on behalf of Protected Networks, 49 per cent of those surveyed said they had retained access to their former employer's network after leaving the company. Of these, 75 per cent admitted continuing to access the corporate systems, sometimes repeatedly over the course of up to a year.</p><p>Furthermore, 57 per cent of businesses involved in the survey noticed that former IT employees still had access, but failed to take action to cut them off.</p><p>Keith Maskell, country manager at Protected Networks, criticised the "astonishingly liberal attitude of UK businesses to managing access to data on the corporate network" saying that this lax attitude creates "a serious vulnerability that can be exploited later by hackers".</p><p>While this failure to properly manage access rights is a serious oversight on the part of businesses, those still accessing their ex-employer's systems may be breaking the law.</p><p>Frank Jennings, a lawyer and partner at Wallace LLP, told IT Pro: "The Computer Misuse Act 1990 ... prohibits unauthorised access to any program or data held in any computer and anyone convicted of this could be liable to pay a fine and could face up to two years in prison.</p><p>"If someone accesses their former employer's system with the knowledge or help of their new employer, that could give rise to liability for the new employer under the CMA."</p><p>Mark Taylor, a partner with law firm Osborne Clarke, agreed.</p><p>"Any criminal liability under the Act would sit primarily sits with the relevant individuals (and not their past employer)," Taylor said.</p><p>"However, if an individual is using such access for the benefit of a new employer or at their new employer's behest, then liability may also attach to them. Consequently, new employers should be careful that they are not encouraging or facilitating such access."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act</link>
                                                                            <description>
                            <![CDATA[ Companies are failing to revoke access when IT workers leave ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sP9oT3w5VjtYhpxGmYcFv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jun 2016 14:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man typing code on a laptop]]></media:description>                                                            <media:text><![CDATA[Man typing code on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Man typing code on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over a third of IT workers have admitted to accessing corporate systems after they have left a company, potentially breaching the Computer Misuse Act.</p><p>According to a survey carried out by Vason Bourne on behalf of Protected Networks, 49 per cent of those surveyed said they had retained access to their former employer's network after leaving the company. Of these, 75 per cent admitted continuing to access the corporate systems, sometimes repeatedly over the course of up to a year.</p><p>Furthermore, 57 per cent of businesses involved in the survey noticed that former IT employees still had access, but failed to take action to cut them off.</p><p>Keith Maskell, country manager at Protected Networks, criticised the "astonishingly liberal attitude of UK businesses to managing access to data on the corporate network" saying that this lax attitude creates "a serious vulnerability that can be exploited later by hackers".</p><p>While this failure to properly manage access rights is a serious oversight on the part of businesses, those still accessing their ex-employer's systems may be breaking the law.</p><p>Frank Jennings, a lawyer and partner at Wallace LLP, told IT Pro: "The Computer Misuse Act 1990 ... prohibits unauthorised access to any program or data held in any computer and anyone convicted of this could be liable to pay a fine and could face up to two years in prison.</p><p>"If someone accesses their former employer's system with the knowledge or help of their new employer, that could give rise to liability for the new employer under the CMA."</p><p>Mark Taylor, a partner with law firm Osborne Clarke, agreed.</p><p>"Any criminal liability under the Act would sit primarily sits with the relevant individuals (and not their past employer)," Taylor said.</p><p>"However, if an individual is using such access for the benefit of a new employer or at their new employer's behest, then liability may also attach to them. Consequently, new employers should be careful that they are not encouraging or facilitating such access."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>