Managing how employees use their own devices for work How to mitigate the security risks of Bring Your Own Device (BYOD) The switch to remote working due to the COVID pandemic, and subsequently, means even more employees now use their own devices to access work emails, systems and files. This can make practical sense for many organisations, but the use of personal devices can pose a serious security risk if appropriate measures are not in place. A risk to personal information, as well as other confidential or commercially sensitive information. Some organisations (particularly those handling sensitive data) might take the step of banning the use of any personal devices for work purposes. But for others there are good reasons for allowing personal devices to be used. The key is making sure security risks have been considered and appropriate measures are in place to protect the organisation and those whose personal data is held. It’s essential for any organisation which allows employees to use their own devices for work purposes, to have robust security measures in place to address security risks, along with appropriate measures to protect personal data. Furthermore, employees need to know what’s expected of them and this is where having a Bring Your Own Device (BYOD) Policy is crucial. What are the risks, what key security measures should be in place, and what should a BYOD Policy cover? Key BYOD risks 1. Loss or theft of devices – we’re all human, and I suspect many of us have lost a mobile before, or perhaps even left a laptop somewhere. There’s a clear risk if it’s possible for someone else to access valuable or sensitive information on the device. 2. Use of public wi-fi services – connecting to open public wi-fi when employees are out and about can leave personal devices vulnerable to hackers. There’s also a risk if home networks aren’t secure. 3. Malware and viruses – employees can view any website and download any app on their own device, raising the risk these could contain damaging malware or viruses. 4. Former employees – failing to remove access and data from devices when people leave the organisation could come back to haunt the organisation. I know of cases where this has caused a data breach. Key steps to mitigate BYOD risks Here are some methods to reduce or eliminate the risks. This is by no means an exhaustive list, but will hopefully give you some useful pointers. Require employees to use appropriate authentications settings when accessing their devices. For example, access via a passcode or fingerprint. Restrict which business applications and data employees can access via their own device. Implement enhanced user authentication for business apps – multi-factor authentication (MFA). That includes access to their business email account (e.g. via Outlook) which may include personal information in the content or in attachments. Consider measures to make sure personal data from business apps can’t be downloaded, stored or shared via personal devices. Don’t allow staff to share data or screenshots from any business app they use with any other app they may have on their device (e.g. social media or file sharing apps). Put clear procedures in place for lost or stolen devices. For example, reporting the loss and the capability to remotely delete data from a lost or stolen device. Make sure clear procedures are in place to update access controls when people leave the business. or change roles. Prohibit the use of public wi-fi services, which may be insecure. Provide advice on making sure your home wi-fi is secure. Ask employees to update apps regularly to make sure any security vulnerabilities are ‘patched’. Ask them to run antivirus / malware checks regularly. Creating a Bring Your Own Device Policy A BYOD Policy sets out the rules for employees when using their personal devices – be it laptops, smartphones or tablets in for work purposes. It should set out the organisations expectations and the security measures required. When employees are accessing the organisation’s information, it’s okay to insist employees comply with a BYOD Policy. Such a policy would cover all the measures in place to mitigate the risks above, making sure employees’ responsibilities are clearly laid out. You’d also want it to include, or point to, clear onboarding, leavers and procedures for lost or stolen devices. In addition, a BYOD Policy is also likely to cover; Types of device permitted. Establishment of company rights on devices (this can be a tricky area and may be worth seeking legal advice. List of company systems / apps allowed to be accessed via personal devices. An explanation of acceptable use and behaviours. For example, what employees are not permitted to do may include; – Allowing others (e.g. family members) to access work systems and apps – Storing or transferring copies of organisation’s information onto their own devices – Using private email accounts for work purposes – Uses which may be illegal or bring the organisation into disrepute Details of the IT support available to employees. Any necessary sanctions should employees fail to follow the policy. By the way, whilst we refer to employees above, you should bear in mind you may also have contractors who access the organisation’s systems / apps via their own devices. If so, the Policy should apply to contractors too. Recently the Information Commissioner’s Office took action against a company following a data breach. It’s worth noting one of the key failings found was the lack of a BYOD policy. We’ve written more about this here: Information Security Tips

Data protection and our suppliers How to manage the third parties we work with One of the more challenging aspects of data protection compliance has been identifying and managing all our suppliers.  Those acting as our processors, supporting our business. Making sure appropriate contractual terms are in place, whilst doing all we can to protect the business from supply chain data breaches (which are all too common) can become onerous. It can help to take a risk-based approach, focusing on the suppliers which represent the biggest business risk first. Alongside this, for any new suppliers we need to make sure we carry out appropriate and robust due diligence. Years after GDPR was implemented, many projects to tackle supplier management remain unfinished, representing an ongoing risk. If we have limited visibility into how our data is processed by our suppliers (and any sub-processors) it clearly leaves the business exposed. What does good supplier management look like? In short, we need to make sure our suppliers are doing what they say they’ll do to protect personal data, using risk assessments and audits. This includes knowing how our suppliers will respond when it comes to the crunch– a data breach. How quickly and fully will they notify us, how will they assist us? Seven-point supplier management checklist 1. Due diligence – Do you have a questionnaire in place to identify the what, where, when and how of data processing? What data protection and security measures are in place? Is there evidence to prove this? It’s good practice to request meaningful answers to certain questions, such as: Do they have a DPO or another individual in the business responsible for data protection? Can they provide evidence of data protection policies and procedures? Have they experienced a data breach before? What information security procedures do they have in place? How regularly are their security measures tested? Do they hold any form of certification? In which country/region will the data be processed? Who are their sub-processors and where do they process the data? The above is by no means an exhaustive list. 2. International Data Transfers  There are additional considerations if international data transfers come into play. If we’re sharing data (or allowing it to be accessed) by a supplier in a third country, we need to check what safeguards need to be in place. For countries where there’s no adequacy decision (allowing for the free flow of data), we need to implement a transfer mechanism such as the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (SCCs).  There’s also the relatively new requirement to conduct a transfer risk assessment, and consider if additional security measures are needed. 3. Contracts – Do we have a clear list of standard clauses for supplier contracts? What do the liability clauses look like? Are we prepared to walk away from suppliers whose contracts aren’t up to scratch? Do we have a good understanding of the level of contractual risk the business is prepared to accept? UK/EU GDPR is clear on what should be included in contractual arrangements and the ICO have published useful contracts guidance. There are often negotiations to be had, especially when it comes to those tricky liability clauses. 4. Instructions –  Have we provided clear instructions on how our suppliers are permitted to handle the personal data, for what purposes and how long they must retain it? 5. Ongoing risk assessment – Do we have a process for evaluating the level of risk suppliers may represent? It’s important to recognise some suppliers may bring greater risks than others. It may not be necessary to risk assess every supplier to the same level of granularity. Effectively we need to risk assess the risk assessments. 6. Review / Audit – Do we have a review or audit programme in place? Annual audits of all suppliers may not be possible, but it makes sense to rotate audits and maintain an up-to-date record of their processing activities. For suppliers considered a higher risk, it may be prudent to routinely audit them. In doing so it’s important to be clear what aspects of the supplier’s business needs to scrutinised. Creating a framework which is tuned and makes sense for the business is a good step and will mean there’s something to show the thought process if the ICO ever comes calling. Here are some factors to consider: What categories of data is handled? What’s the data volume? How risky is the processing? What could be the impact if a data breach occurred? Was any due diligence carried out when the supplier was onboarded? Is the supplier accredited or certified? Have there been any complaints relating to privacy / breaches? Have there been changes in ownership or scope of processing? Have there been significant changes in processes and workflow? 7. Certification – in the absence of an approved certification scheme, alignment with ISO 27701 (the standard extending ISO27001 into data privacy) is worth considering. It can sometimes feel like a mountain to climb, especially if operating using multiple suppliers. As the saying goes ‘you can only eat an elephant one bite at a time’, the key to supplier management is identifying the biggest risks and prioritising where action is needed the most.

Ransomware attack leads to £98k ICO fine Solicitors firm failed to implement ‘adequate technical and organisational measures’ Are you using Multi-Factor Authentication? Are patch updates installed promptly? Do you encrypt sensitive data? Reports of cyber security incidents in the UK rose 20% in the last 6 months of 2021. These figures from the ICO, combined with the heightened threat in the current climate, provide a stark warning to be alert. The ICO says; “The attacks are becoming increasingly damaging and this trend is likely to continue. Malicious and criminal actors are finding new ways to pressure organisations to pay.” Against this backdrop the ICO has issued a fine to Solicitors’ firm following a ransomware attack in 2020. The organisation affected was Tuckers Solicitors LLP (“Tuckers”) which is described on its website as the UK’s leading criminal defence lawyers, specialising in criminal law, civil liberties and regulatory proceedings. While each organisation will face varying risks, this case highlights some important points for us all. Here’s a summary of what happened, the key findings and the steps we can all take. For increasing numbers of organisations this case will unfortunately sound all too familiar. What happened? On 24 August 2020 Tuckers realised parts of its IT system had become unavailable. Shortly after IT discovered a ransomware note. Within 24 hours it was established the incident was a personal data breach and it was reported to the ICO. The attacker, once inside Tuckers’ network, installed various tools which allowed for the creation of a user account. This account was used to encrypt a significant volume of data on an archive server within the network. The attack led to the encryption of more than 900,000 files of which over 24,000 related to ‘court bundles’. 60 of these bundles were exfiltrated by the attacker and released on the ‘dark web’. These compromised files included both personal data and special category data. The attacker’s actions impacted on the archive server and backups. Processing on other services and systems were not affected. By 7 September 2020, Tuckers updated the ICO to say the servers had been moved to a new environment and the business was operating as normal. The compromised data was effectively permanently lost, however material was still available in management system unaffected by the attack. Tuckers notified all but seven of the parties identifiable within the 60 court bundles which had been released, who they did not have contact details for. Neither Tuckers, nor third party investigators, were able to determine conclusively how the attacker was able to access the network in the first place. However, evidence was found of a known system vulnerability which could have been used to either access the network or further exploit areas of Tuckers once in side the network. What data was exfiltrated? The data released on the ‘dark web’ included: Basic identifiers Health data Economic and financial data Criminal convictions Data revealing racial or ethnic origin This included medical files, witness statements and alleged crimes. It also related to ongoing criminal court and civil proceedings. Tuckers explained to the Regulator, based on its understanding, the personal data breach had not had any impact on the conduct or outcome of relevant proceedings. However, the highly sensitive nature of the data involved increased the risk and potential adverse impact on those affected. Four key takeaways The ICO makes it clear in its enforcement notice that primary culpability for the incident rests with the attacker. But clear infringements by Tuckers were found. The Regulator says a lack of sufficient technical and organisation measures gave the attacker a weakness to exploit. Takeaways from this case: 1) Multi-Factor Authentication (MFA) Tuckers’ GDPR and Data Protection Policy required two-factor authentication, where available. It was found that Multi-Factor Authentication (MFA) was not used for its ‘remote access solution’. The ICO says the use of MFA is a relatively low-cost preventative measure which Tuckers should have implemented. The Regulator concluded the lack of MFA created a substantial risk of personal data on Tuckers’ systems being exposed to consequences such as this attack. Takeaway: If you currently don’t use MFA, now would be a good time to implement it. 2) Patch management The case reveals a high-risk security patch was installed in June 2020, more than FOUR months after its release. The ICO accepts the attacker could have exploited this vulnerability during the un-patched period. Considering the highly sensitive nature of the personal data Tuckers were handling, the Regulator concludes they should not have been doing so in an infrastructure containing known critical vulnerabilities. In other words the patch should have been installed much sooner. Takeaway: Make sure patches are installed promptly, especially where data is sensitive. 3) Encryption During the investigation Tuckers informed the ICO the firm had not used encryption to protect data on the affected archived server. While the Regulator accepts this may not have prevented the ransomware attack itself, it believes it would have mitigated some of the risks posed to the affected individuals. Takeaway: There are free, open-source encryption solutions are available. Alternatively more sophisticated paid for solutions are available for those handling more sensitive data. Also it’s worth checking you’re adequately protecting archives to the same standard as other systems. 4) Retention The enforcement notice reveals some ‘court bundles’ affected in the attack were being stored beyond the set 7-year retention period. Takeaway: This again exposes a common issue for many organisations. Too often data is held longer than is necessary, which can increase the scale & impact of a data breach. Our comprehensive Data Retention Guidance is packed with useful tools, templates and advice on tackling how long you keep personal data for. What else can organisations do? Clearly, we can’t be complacent and shouldn’t cut corners. We need to take all appropriate steps to protect personal data and avoid common pitfalls. Here are some useful resources to help you: Cyber Essentials – The enforcement action notes that prior to the attack Tuckers was aware its security was not at the level of the NCSC Cyber Essentials. In October 2019, it was assessed against the ‘Cyber Essentials’ criteria and failed to meet crucial aspects of its requirements. Cyber Essentials was launched in 2014 and is an information security assurance scheme operated by the National Cyber Security Centre. It helps to make sure you have the basis controls in place to protect networks/systems from threats. Cyber Essentials – gain peace of mind with your information security National Cyber Security Centre ICO Ransomware guidance – The ICO has recently published guidance which covers security policies, access controls, vulnerability management, detection capabilities and much more. DPN Data Breach Guide – Our practical guide covers how to be prepared, how to assess the risk and how to decide whether a breach should be reported or not. You can read the full details of this case here: ICO Enforcement Action – Tuckers Solicitors LLP

Data Breach Guide How to handle a data breach Our practical, easy-to-read guide takes you through how to be prepared for a breach, and how to assess the risks should you suffer a personal data breach. This data breach guide covers: Common causes of breaches Data incident and breach planning How to assess the risks Breach reporting checklists How technology can help