Jonathan Richards
Download 'Too Hot', an exclusive Specials track from iTunes
Security experts said today that HM Revenue & Customs was "totally irresponsible" to have sent personal information between offices on a CD.
The information contained on it - bank account details and national insurance numbers - constituted the "holy grail" for criminal, who if they intercepted the disc would be free to commit identity fraud on a vast scale.
They said that older and more risky means of transporting information - such as sending it via courier on a compact disc, were, however, "surprisingly common" as organisations sought to avoid the cost of implementing safer methods.
Increasingly, sensitive information is passed between organisations needing access to it - banks, for instance - via electronic transfer.
Almost all the banks in the US, where security breaches have been more common, have updated their systems to facilitate electronic transfer, and whilst the major financial institutions in the UK have done the same, Government departments were often slower to catch up, experts said.
It was often preferable to save information onto a CD and then send the 'hard copy' because of the enormous amount of bandwidth required to send large files electronically, and the complicated systems that need to be in place to rescue a transaction if it is interrupted.
Sending the 25 million odd individual records that were contained on the discs lost by HMRC would take approximately 4 hours on a high speed connection, an analyst at Gartner said. There was also the added complication of managing the 'encryption keys' - the tools which enable a recipient to decypher encrypted, or scrambled, information.
Information sent on a CD can - and should - be encrypted, they said, but there was no evidence that the HMRC had protected the data effectively in this case.
"The main issue with electronic transfer methods is getting everyone on board," Aviva Latin, chief security analyst at Gartner, said. " Say you're sending information to 5 banks. Each of them has to agree to the procedures you set up, and that presents an enormous challenge.
"Changing business and technical processes like this is also very expensive, which is why improving data transfer often falls to the bottom of an IT manager's list."
Ms Litan said, however, that the Government should be taking greater care with data transfer because of the "havoc" that incidents like this were capable of wreaking on the banking system.
She added that in 99 per cent of cases where information was lost or stolen in this way, no fraud was subsequently committed.
Brian Spector, a spokesman for the security firm Workshare, said it was "staggering" that an organisation responsible for the data of millions of child benefit claimaints "was still copying data onto CDs and not ensuring full protection through encryption techniques."
Ross Anderson, a computer security expert at the University of Cambridge, said that the breach was indicative of a wider failure of the Government's e-Government strategy which, in attempting to centralise information such as patient records, had led to vast numbers of records being shared, increasing the risk in the event that data was stolen or lost.
Win a luxury weekend to Newcastle and its neighbour Gateshead, find out more here
Risk, resilience and embracing new technology
Industry sectors news at a glance. Interactive heatmap, video and podcast
Discover the power of collective thinking. Submit a solution and be in with a chance to win a Media Hub Home Entertainment System
The inside track on current trends in the charity, not for profit and social enterprise sectors
Everything the Business Traveller needs to know to make a better trip
Make the most of the summer and enter our fabulous photographic competition, you could win a £5000 holiday
Corsica is an island of beauty and contrast, an ideal holiday destination
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
The clever way to lease a new car is with Car leasing made simple™
2009
per month on 36-month
Personal Contract Hire (PCH)
2008
42850
Car Insurance
£24,250 - £30,346
MI5
London
£60,000
The Environment Agency
Bristol
Up to £90K
Boots
Midlands
OTE £85k
Credit Protection Association
Nationwide Opportunities
Completely London
Luxury Condo's in Manhattan with NYC views
The best new homes in Wimbledon?
Nationwide
Fabulous Cruise And Cruise & Stay Offers Including Virgin Atlantic Flights Prices Start From Only £699pp!
Last Minute Cruise And Cruise & Stay Offers. Med From £499pp, Caribbean From £699pp!
5 star quality at a 3 star price.
8 fabulous Canadian cities ...you won’t find cheaper
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Property Finder | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
utterly astonishing incompetence.
Gordon - you and your Civil Service does realise it is 2007, not 1907, doesn't it?
Peter, London,
A massive betrayal of our wavering trust in this government's ability to look after the nation's best interests. Hopefully this sounds the death knoll for ID cards.
Isabella Perry, Winchester,
Sending information by CD is perfectly safe - as long as the date on it is encrypted. (Encryption software is easily available, relatively cheap, and easy to use).
This is just another example of the civil services' lack of understanding of IT.
Even worse, they force their incompetent standards onto vendors who deal with them; they insist that all government IT projects use an excessively bureaucratic project management system that has an unenviable reputation for delivering IT solutions that are late, over budget and not fit for purpose.
Mike, Bristol,
Words fail me.
Forget identity cards....can the State be trusted to manage anything effectively?
Margaret, Berkhamsted,
.....and they still want us to believe that they can be trusted with an identity database?
If this does not prove the stupidity of having id cards and and id database then nothing will!
John Macnab, Southampton, UK
The same government wants us to have ID cards and for us to have our DNA put onto a database. First the immigration scandal and now this. No wonder we don't have any faith in politicians!
Amber, Stevenage,