The Information Commissioner’s Office (ICO) has urged firms to invest in better staff training and security processes after issuing a seven-figure fine to Interserve Group.
The Berkshire-based construction firm was fined £4.4 million for failing to keep the personal information of its staff secure, resulting in a breach of data protection law.
An ICO investigation found that the company failed to implement “appropriate technical and organisational measures” to prevent a cyber-attack.
The firm subsequently fell victim to a phishing attack which exposed personal data belonging to 113,000 employees.
Data compromised in the attack included sensitive personal information such as contact details, national insurance numbers, and bank account details.
In addition, special category data including ethnic origin, religion, details of any disabilities, sexual orientation, and health information was also exposed in the breach.
Information Commissioner John Edwards said: “The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company.
“If your business doesn’t regularly monitor for suspicious activity in its systems and fails to act on warnings or doesn’t update software and fails to provide training to staff, you can expect a similar fine from my office.”
Interserve data breach
Interserve fell prey to this sophisticated phishing campaign in May 2020. During the attack, an employee forwarded a malicious email to a colleague who opened it and downloaded its content.
This resulted in the installation of malware onto the employee’s workstation.
Although the company’s anti-virus system quarantined the malware and sent an alert, the ICO investigation found that Interserve failed to follow up on the suspicious activity.
Recommended
- Edinburgh firm praised for Ukraine cyber support
- 5G service revenue set to hit £278bn next year
- Diversity progress in the spotlight in UK data industry
Similarly, the ICO probe found that the firm used “outdated software” and had a lack of adequate staff training and insufficient risk assessments.
In total, the attack compromised 283 systems and 16 accounts, and resulted in the company’s anti-virus solution being completely uninstalled.
Edwards said the attack severely impacted Interserve staff and left them at risk of serious long-term impact.
He added: “Leaving the door open to cyber attackers is never acceptable, especially when dealing with people’s most sensitive information.
“This data breach had the potential to cause real harm to Interserve’s staff, as it left them vulnerable to the possibility of identity theft and financial fraud.
“Cyber-attacks are a global concern, and businesses around the world need to take steps to guard against complacency. The ICO and NCSC already work together to offer advice and support to businesses.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





