Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 23 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Bupa Data Breach hits over 500,000 customers – cyber security experts have their say

by The Gurus
July 14, 2017
in Editor's News
Data Breach Cyber attack code
Share on FacebookShare on Twitter

Bupa healthcare was hit by a data breach after one of its employees went rogue and inappropriately copied and removed information relating to 547,000 international health care plan customers.
Names, dates of birth, nationalities, some contact and administrative information were among the data leaked. No financial or medical data has been exposed and the relevant victims have been notified. Bupa in a statement has said protecting customer information was “an absolute priority”.
“A thorough investigation is under way and we have informed the FCA [Financial Conduct Authority] and Bupa’s other UK regulators,” said Sheldon Kenton, managing director of Bupa Global.
Cyber security experts have had their say on the breach:
Itsik Mantin, director of research at Imperva, said “Although people tend to associate breaches with hackers, the truth is that many data breaches involve inside work, as was this breach which happened, according to Bupa, by an employee.
This is not surprising given that Verizon DBIR 2017 report indicates that 1 out of 4 data breaches are attributed to insiders and, in the healthcare domain, the situation is even worse with 2 out of 3 breaches involving insiders and third-parties.
As we’ve seen in past high-profile cases, data breaches caused by careless, malicious or compromised insiders are real and serious. Because the problem begins with users that have legitimate access to enterprise data, attacks from the inside can be present for long periods of time before finally being detected. What’s more, costs associated with loss of data can run in the millions and lead to customer loss, brand damage and stock price decline.
To mitigate the risk, organisations should ask themselves where their sensitive data lies and invest in protecting it. Businesses can employ solutions, especially those based on machine learning technology that can process and analyse vast amounts of data, to help them pinpoint critical anomalies that indicate misuse of enterprise data and that also help them to quickly quarantine risky users to prevent and contain data breaches proactively.”
 
Paul Edon, Director at Tripwire:
“Unfortunately, humans are the weakest link in security. Despite many of us being trustworthy, there are some, insiders, that break and damage that trust. The worst thing is, anyone in the company could be an insider and it is very difficult to vet everyone who has access to the various networks and sensitive data. Knowing what data is where is the first step in selecting the relevant security measures. Then controlling not only who has access to said data but also the level of access would be the next step, ensuring each individual has only the access necessary to do their job, this can reduce the risk of an insider threat greatly. However, should a breach happen, it is imperative that the breached company has a rapid response. Changing passwords would be the first recommendation to further reduce exploitation. Victims of the breach would also need to monitor any indicators of identity theft and double check incoming emails and calls are from vetted addresses and numbers.”
 
Marco Cova, senior security researcher at Lastline:
“Unfortunately, the data revealed from this breach is the type that criminals can use to launch additional attacks. They merge data from multiple sources, building dossiers on potential victims, including spear phishing targets. The information that they gather does not have to be highly confidential in order to create successful attacks. Data breaches provide a distribution hub for malware for years to come.
“Overall, there are two major sources of cyber risk: people and technology. People can unwittingly (or purposely, of course) disclose confidential data like passwords, banking or personal information to a stranger. In addition, due to its complexity, Information Technology hides a high level of cyber risk buried deep in the software and in the processes to run and manage the technology.
“Cyber security practitioners generally recommend minimising the amount of data gathered and stored by an organisation. The aim is to reduce the amount of data that could be leaked during a cyber incident. However, healthcare firms need to gather and store large amounts of customer and case data to conduct their business. One way to address this challenge is to replicate the model of individual accountability often used in the financial and banking industries. First, every individual that has access to data in the company should be trained on the essentials of cyber security and data protection. Second, define data protection standards within the organisation. This includes identifying and classifying customer data, defining data protection processes and implementing the cyber security controls to protect the customer data. The process should also be supported by good auditing and monitoring processes. Finally, making a specific individual accountable for data protection across the organisation can also help. Given the resources and expertise of the cyber criminals and hacktivists, this individual would be ultimately responsible for handling the breach disclosure process.”

Tags: BreachCyberdatasecurityTechnology
ShareTweet
Previous Post

Imperva Insider Threats Study Finds More than Half of IT Security Professionals Are Concerned About Careless Users Putting Data at Risk

Next Post

Petya Cyber Attack Likely Done by ‘State Sponsor’

Recent News

Quantum computing: The data security conundrum

Trump Sets Post-Quantum Security Deadlines as White House Warns of Advanced Cryptographic Threats

June 23, 2026

Experts Warn: Passwords Still Winning Despite Passwordless Push

June 23, 2026
How Do Online Gaming Sites Keep Players and Their Data Safe?

KnowBe4 awarded in the email security industry

June 23, 2026
NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

June 23, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol