1 min read

8.7M Data Breach: Would Your Business Face an ICO Fine?

8.7M Data Breach: Would Your Business Face an ICO Fine?

Whilst a breach affecting 8.7 million people sounds like an automatic ICO fine, but it might not be depending on their security.

 

Manchester Airports Group has confirmed that customer data linked to Manchester, Stansted and East Midlands airports was accessed. We know the affected systems held information from Wi-Fi sign-ups and car park, lounge and Fast Track bookings. We also know that no bank or payment details were held on those systems. What we do not yet know is whether MAG had reasonable security in place before the attack.

In previous breaches at British Airways and (pre gdpr) Cathay Pacific, they were not fined simply because attackers got in. The ICO found serious security failings behind each incident. BA was fined £20 million after the regulator found it was processing large amounts of personal data without adequate security measures. Cathay Pacific received the maximum £500,000 penalty available under the old law after the ICO identified a series of basic weaknesses across its systems.

The lesson is not that every company must spend an unlimited amount on cyber security. Businesses are making difficult choices while salaries, software, insurance and almost every other operating cost continue to rise. The lesson is that cost pressure does not remove the obligation to understand and manage risk.

Vibe Coding Doesn't Mean Secure Coding

That matters even more as companies build their own apps, integrations and AI-assisted tools. Vibe coding can help a business move quickly, but speed is not the same thing as security. An app may work perfectly and still expose data through weak authentication, excessive permissions, poor API configuration, missing rate limits, insecure secrets or inadequate logging if MAG have had an incident small business can most definitely be assured if they have vibe coded an app with API interface its not as secure as it would be if completed professionally.

Before a customer-facing system goes live, and regularly afterwards, get it reviewed by a security professional.

To help keep security costs down configuration changes in the already in place technology can do more than a new firewall or latest software.

We cannot say yet whether MAG's security was sufficient as yet. Every other business should use the time before its own incident to ask a simpler question: is ours?

Further expansion for Infuse with new specialist recruit

1 min read

Further expansion for Infuse with new specialist recruit

We’ve welcomed Pete Marsden in the new role of Senior Projects Engineer, as we celebrate our recent office move to Pride Park in Derby and continued...

Read More
Facebook quizzes and the risk of cyber crime

1 min read

Facebook quizzes and the risk of cyber crime

We have all seen those quizzes on Facebook and other social media platforms calling out for our personal information. Whilst they can seem fun and...

Read More
The end of passwords? What the NCSC’s new guidance means for your business

1 min read

The end of passwords? What the NCSC’s new guidance means for your business

This week, the National Cyber Security Centre (NCSC) made headlines by officially recommending that people ditch traditional passwords in favour of ...

Read More