According to findings made through an FoI request by tech manufacturer Apricorn, Her Majesty’s Revenue and Customs declared 635 lost and stolen devices throughout 2022, an increase of 45% from the previous year.
This put HMRC at the top of the list with regards to lost or misplaced devices such as phones, tablets, computers, and USB drives.
Other departments disclosed lost and stolen devices in the FoI requests, such as the Home Office declaring 469, the Ministry of Defence declaring 467, and the Department of Business, Energy and Industrial Strategy declaring 204, doubling from the previous year.
“We have asked these same questions via these FoI requests for the last 3 years and whilst it’s not surprising to see devices unaccounted for, we would hope to see the numbers declining as cybersecurity becomes more established,” said Jon Fielding, Managing Director of Apricorn.
All government departments who were questioned on the devices missing said that they were encrypted, which is a security measure to ensure sensitive information is protected.
“Hardware encrypted storage devices should be provided as standard to ensure that any sensitive data held on them should always be unintelligible if they happen to be misplaced and fall into the wrong hands,” said Fielding. “Additionally, encryption should be combined with the automation and enforcement of security policies through technology wherever possible,” he said.
Recommended
- What does Digital Transformation Mean to Incremental CEO, Mark Skelton?
- Edinburgh 3D Holographic Tech Firm Holoxica Facing Liquidation
- How do Employees Feel About AI-powered IT?
According to an annual report from April 2021-2022, 5,782 security incidents were not deemed necessary to report to the Information Commissioner’s Office. Incidents which include loss of theft of information, or insecure disposal of equipment or documents.
“It’s worrying to think that a government entity that holds so much responsibility, and retains so much sensitive and personal information, can pose this much risk,” said Fielding, “The number of recorded security incidents, whether reported to the ICO or not, should alarm security teams.”





