Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

More Talk, Less Practical Advice: UK Government Recommendations Resulting from TalkTalk Breach

by The Gurus
June 21, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

In late 2015, TalkTalk Telecom Group, a telecommunications provider in the United Kingdom, suffered a breach. The breach exposed the details of over 150,000 customers, including more than 15,000 bank account details and 28,000 credit card numbers. The breach cost TalkTalk 42 million British Pounds, cutting the company’s profits for the year in half, and resulted in the loss of more than 95,000 customers.
The breach was so significant that the British Government opened up an inquiry into the protection of personal data online.
After eight months, the initial conclusions and recommendations have been released. The following are some highlights:

  • The report focuses heavily on the role of victims, not only TalkTalk and other enterprises but also consumers. For example, the primary recommendation is to increase customer awareness of online and telephone scams, recommending that the government initiate a public awareness-raising campaign similar to that for smoke alarm testing.
  • It addresses the role of board members, and particularly the CEO in the case of a breach, recommending that “a portion of CEO compensation be linked to effective cyber security.”
  • It talks about escalating fines “based on the lack of attention to threats and vulnerabilities, which have led to previous breaches.” At one point, it recommends that the EU General Data Protection Regulation (GDPR) increase the fines to €20 million from the current £500,000!
  • It also recommends calling into force “Sections 77 and 78 of the Criminal Justice and Immigration Act of 2008” to punish those “obtaining and selling personal data.”
  • It also recommends creating a “privacy seal” which would “be awarded to entities which demonstrate good privacy practice and high data protection compliance standards.”

Sadly, as is all too often the case with these types of inquiries, these recommendations provide very little practical advice on how to prevent the theft in the first place. It focuses more on how to help people avoid becoming the victim of a crime, and less on how to prevent the crime from taking place.
Protecting consumer data is an endless task for enterprises, which requires the constant adoption of new technologies in the face of new threats. In particular, enterprises have been slow in adopting data-centric protection measures while over investing in old school endpoint and perimeter security. Enterprises are still dragging their feet with deploying technologies that could mitigate existing and imminent threats like SQL injection although these technologies are readily available (e.g. Web Application Firewalls). So clearly there is room for improvement on the enterprise side, and some incentive in the form of stricter (enforceable) regulation is good. However, the report does not address the crux of the matter—which is reducing cyber-crime.
The inquiry repeatedly mentions that the ICO investigation is not over yet – eight months after the incident. Though there’s no word on the criminal investigation into who stole this information, why, and how they succeeded.
Finally, if this incident directly affecting UK businesses and consumers were critical enough to invoke investigative committee for the Parliament, why is it not getting the same attention from a law enforcement perspective?
While organizations can and should do more to protect consumer data, they cannot be left alone to fight cyber-crime. A strategy that involves both prevention and prosecution are essential to reducing these events in the future. Moreover, it seems like those are the two points that are glaringly missing from this report.

ShareTweet
Previous Post

GoToMyPC data breach – Industry Reaction

Next Post

New research uncovers widespread compromised login credentials across the UK

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol