TalkTalk hit with record £400k fine over ‘preventable’ cyber-attack
The Guardian is reporting that TalkTalk has been hit with a record £400,000 fine for the security failings that led to the company being hacked in October 2015.
The Information Commissioner’s Office levied the fine saying that the attack “could have been prevented if TalkTalk had taken basic steps to protect customers’ information”.
The hack resulted in the attacker accessing the personal information of more than 150,000 customers of the internet service provider, including sensitive financial data for more than 15,000 people.
The information commissioner, Elizabeth Denham, said: “TalkTalk’s failure to implement the most basic cyber security measures allowed hackers to penetrate TalkTalk’s systems with ease.
“Yes, hacking is wrong, but that is not an excuse for companies to abdicate their security obligations. TalkTalk should and could have done more to safeguard its customer information. It did not and we have taken action…”
The amount the ICO can fine companies for serious breach of data protection obligations is capped at £500,000, leaving TalkTalk’s fine almost as large as it could possibly receive. Repeat offenders can also be issued “enforcement notices” under the same legislation, which entail the ICO requiring a business to take particular steps to prevent a re-occurrence.
Large as it sounds, a fine of £400,000 only works out at £2.67 for each customer whose data was breached which seems pretty inadequate as a deterred to others.
More at: TalkTalk hit with record £400k fine over cyber-attack
PENTESTING & VULNERABILTY SCANNING, EXETER, DEVON
Pentesting UK is based in Exeter, Devon and offers penetration testing, ASV scanning, website testing and vulnerability scanning for clients in Devon, the South West and across the UK and beyond. Contact us for help…

