Site navigation

Interserve Fined £4.4m for Cybersecurity Failures

Ross Kelly

,

Interserve
An investigation by the ICO found that Interserve breached data protection law.

The Information Commissioner’s Office (ICO) has urged firms to invest in better staff training and security processes after issuing a seven-figure fine to Interserve Group.

The Berkshire-based construction firm was fined £4.4 million for failing to keep the personal information of its staff secure, resulting in a breach of data protection law.

An ICO investigation found that the company failed to implement “appropriate technical and organisational measures” to prevent a cyber-attack.

The firm subsequently fell victim to a phishing attack which exposed personal data belonging to 113,000 employees.

Data compromised in the attack included sensitive personal information such as contact details, national insurance numbers, and bank account details.

In addition, special category data including ethnic origin, religion, details of any disabilities, sexual orientation, and health information was also exposed in the breach.

Information Commissioner John Edwards said: “The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company.

“If your business doesn’t regularly monitor for suspicious activity in its systems and fails to act on warnings or doesn’t update software and fails to provide training to staff, you can expect a similar fine from my office.”

Interserve data breach

Interserve fell prey to this sophisticated phishing campaign in May 2020. During the attack, an employee forwarded a malicious email to a colleague who opened it and downloaded its content.

This resulted in the installation of malware onto the employee’s workstation.

Although the company’s anti-virus system quarantined the malware and sent an alert, the ICO investigation found that Interserve failed to follow up on the suspicious activity.


Recommended


Similarly, the ICO probe found that the firm used “outdated software” and had a lack of adequate staff training and insufficient risk assessments.

In total, the attack compromised 283 systems and 16 accounts, and resulted in the company’s anti-virus solution being completely uninstalled.

Edwards said the attack severely impacted Interserve staff and left them at risk of serious long-term impact.

He added: “Leaving the door open to cyber attackers is never acceptable, especially when dealing with people’s most sensitive information.

“This data breach had the potential to cause real harm to Interserve’s staff, as it left them vulnerable to the possibility of identity theft and financial fraud.

“Cyber-attacks are a global concern, and businesses around the world need to take steps to guard against complacency. The ICO and NCSC already work together to offer advice and support to businesses.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data