Single memory stick costs police force £120K

happygeek 1 Tallied Votes 386 Views Share

The UK Information Commissioner's Office (ICO) has slapped the Greater Manchester Police force with a £150,000 fine (reduced to £120,000 for early payment) after a memory stick containing sensitive data about serious crimes was stolen from the home of a police officer.

dweb-police The ICO has the power to levy such fines if an investigation determines that sensitive data has been put at risk courtesy of a lack of proper data protection being in place. In this particular case it must have been a very quick investigation, filed under the no-brainer category, seeing as the data was being stored on a memory stick which the officer had seen fit to take home with him. A memory stick which required no password in order to access the information held upon it. Information that was stored without any encryption being applied. Information which included details concerning in excess of a thousand people with links to 'serious crime investigations' apparently.

The breach occurred when a burglar broke into the home of the officer and the memory stick was amongst the items stolen during that robbery. According to the ICO, Greater Manchester Police officers regularly used such unencrypted memory sticks. This despite a very similar breach having taken place in 2010, the lessons from which were obviously not learned and which led the ICO to conclude that the police force was not properly trained with regards to data protection matters.

ICO Director of Data Protection, David Smith, insists that it should have "been obvious to the force that the type of information stored on its computers meant proper data security was needed" and that the consequences of such a breach leaving this information in the hands of a burglar sends "a shiver down the spine".

Dani AI

Generated

The posts in this thread highlight the same root problem: sensitive data left on portable removable media without enforced technical controls or a clear, enforced workflow. summarised the event; ’s reaction and ’s point about protocol show the predictable mix of human error and weak systems. Below are concise, practical actions and controls that stop a single device from becoming a large-scale breach.

Immediate incident checklist (first 24–72 hours)

  • Start an incident log and preserve timelines and device metadata.
  • Contain and investigate: try remote wipe, revoke credentials, search for other copies and check logs.
  • Identify likely affected data subjects and assess risk to individuals.
  • Notify the regulator promptly if required — don’t wait for every fact to be known; start the clock on statutory reporting. (ico.org.uk)

Practical prevention (technical controls)

  • Stop reliance on personal USBs: restrict use to organisation-issued devices only, or disable ports for general users.
  • Enforce full-device or container encryption for any removable media; encrypting removable media is a reasonable, expected control. (ico.org.uk)
  • Use centrally managed solutions so keys/recovery material are escrowed (examples: platform encryption tools and vetted container tools). (ci.vse.cz)
  • Deploy DLP/EDR/MDM to prevent uncontrolled copying and to log/block unauthorized exports. Combine with anti-malware scanning and disable autorun. (essentialguide.docs.cisecurity.org)

Organisational fixes (policy + people)

  • Make a simple, enforced policy: only approved devices, mandatory encryption, documented exception process, and regular audits.
  • Train staff on the “why” (harm to people) and the “how” (approved transfer options like secure shares or encrypted containers).
  • Treat enforcement as critical: training without technical enforcement (DLP, port controls, managed encrypted media) will keep producing the same headlines.

These measures turn a one-person mistake into a survivable event. Implement the policy, enforce it technically, log and test the incident process — that combination prevents repeat incidents and reduces legal/regulatory risk.

Xlphos 16 Veteran Poster

Never learn do they?

Member Avatar for Member #949455
Member #949455

The UK Information Commissioner's Office (ICO) has slapped the Greater Manchester Police force with a £150,000 fine (reduced to £120,000 for early payment) after a memory stick containing sensitive data about serious crimes was stolen from the home of a police officer.

This is an sad article. I think the police officer didn't follow protocol. All sensitive data should be kept at the station or office not at their home. This is really serious why did the police officer brought home that stick in the first place. This is a hard lesson to be learn.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.