Site navigation

Documents Show Record Number of Security Issues at Ministry of Defence

David Paul

,

ministry of defence

Secrets were potentially exposed by staff sending files via personal email accounts, as well as a series of other security issues.

Secret files held by the Ministry of Defence (MoD) have been potentially exposed after being sent through personal email channels.

Heavily redacted documents obtained by Sky News revealed that last year the organisation suffered a record number of security breaches originating from the British military’s private sector partners.

The redacted documents show a total of 151 incidents were filed with the MoD’s defence industry Warning, Advice and Reporting Point (WARP) last year, compared with just 75 the previous year.

As well as this, two incidents that occurred in April last year were supposedly so sensitive that associated dates were hidden by the MoD.

Despite many of the records being obscured, multiple paragraphs supposedly including numerous incidents when the information were sent to personal email accounts as staff work from home during the pandemic.

Commenting on the movement of sensitive information through personal email addresses, Tim Sadler, CEO and co-founder of human layer security company Tessian said: “People sending data to personal email accounts is a much bigger problem than most organisations and institutions even realise.

“According to our data, employees send company sensitive information to personal email accounts 38x more often than their IT and security leaders expect.

“The problem is that data loss prevention has only been made more challenging since the staff have been working remotely as employees send data to their personal accounts to print out or work on documents on home devices.

“While it might seem harmless, highly sensitive information in those emails now sits in an environment that is not secured by the company, leaving it vulnerable to cybercriminals.

“Today’s reports are an important reminder to all companies to remind employees of data sharing policies and ensure there are procedures in place to prevent data loss caused by people sending emails home.”


Recommended


The released documents potentially put a dampener on Prime Minister Boris Jonson’s announcement that the UK must “build up” offensive cyber capabilities to combat future threats, and calling for the creation of a National Cyber Force last year.

News of the potential breaches raise questions about the UK’s ability to combat cyber threats ahead of the government’s publication of a national security review.

The national lockdowns have caused many people to continue their day-to-day work at home, meaning some have had to move sensitive information from secure office servers into private home networks, causing potential breaches of GDPR and mishandling of sensitive data.

Even before the pandemic, research by the UK Information Commissioner’s Office (ICO) revealed that human error was responsible for 90% of the UK’s cyber data breaches in 2019, a number that likely increased as the country spent more time working from home.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data