How Swiss Cheese Security Cost Zurich $3.5m

happygeek 1 Tallied Votes 609 Views Share

Zurich Insurance in the UK has just discovered the true cost of failing to secure confidential customer data properly, as the Financial Services Authority (FSA) fines the company a record £2.275m ($3.5m) for the data loss incident in 2008 which potentially put some 46,000 customers at risk.

The incident occurred when an unencrypted back-up tape containing those 46,000 customer records disappeared in transit between two sites in South Africa in 2008, although apparently it took the best part of a year before Zurich UK heard about the data loss.

According to the FSA . But it could have been much worse, Zurich were granted a 30 percent discount for settling at an early stage during the investigation which dropped the fine from an original amount of £3.25m ($5m).

The misplaced data included customers' personal details such as bank account and credit card information as well as information about insured assets and security arrangements. Although Zurich UK states it has seen "no evidence" to support suggestions that the data has been misused or compromised in any way, the fact remains that it certainly had the potential to cause serious problems for the 46,000 customers concerned.

FSA Director of Enforcement and Financial Crime, Margaret Cole, said "Zurich UK let its customers down badly. It failed to oversee the outsourcing arrangement effectively and did not have full control over the data being processed by Zurich SA. To make matters worse, Zurich UK was oblivious to the data loss incident until a year later. Firms across the financial sector would do well to look at the details of this case and learn from the mistakes that Zurich UK made."

The FSA states, and the case highlights, how Zurich UK failed to "take reasonable care to ensure it had effective systems and controls to manage the risks" relating to the security of customer data resulting from the outsourcing arrangement and further that it "failed to ensure that it had effective systems and controls to prevent the lost data being used for financial crime".

Stephen Lewis, Chief Executive of Zurich Insurance PLC (UK) said in a statement : "This incident was unacceptable. It served to remind us of the need to strive continually to improve the ways in which we seek to protect customers’ data. We are appointing a dedicated Information Security Officer to provide ongoing assurance that appropriate measures are in place and that they will continue to be effective. We believe our customers can be confident that we are doing everything we can to keep their data secure and protected."

So it seems that Zurich has learnt from the mistakes it has made, despite the 'record fine' being but a drop in the ocean in financial terms for a company of this size. Other companies should take note that if you effectively crap on customer data security concerns then it should come as no great surprise if, when the brown stuff hits the fan as it inevitably will, the green folding stuff starts flying out of the bank...

Dani AI

Generated

A concise, practical addendum to the thread: the regulator’s findings, where Zurich went wrong, and what to do differently.

As described, the UK regulator announced a £2.275m penalty on 24 August 2010 after an unencrypted backup tape containing roughly 46,000 general‑insurance customer records was lost in transit in August 2008; Zurich’s UK arm did not learn of the loss for about a year and qualified for a 30% early‑settlement discount. (fca.org.uk) (FCA press release).

Why this blew up: the loss combined three control failures — weak technical protection of media (no encryption), poor asset/tracking procedures for removable/transported media, and insufficient oversight/contractual controls over an outsourcing relationship. Regulators make clear that outsourcing does not remove the firm’s accountability for security or incident reporting. (fca.org.uk) (FCA outsourcing guidance, ICO: encryption & backups).

Concrete, prioritized controls to avoid the same mistake:

  • Encrypt backups in transit and at rest; use vetted algorithms and separate, auditable key management (HSMs, split knowledge).
  • Prefer network replication or secure cloud vaulting to physical tape transfers; avoid paper/physical media when possible.
  • If physical transfer is unavoidable, require hardware‑encrypted cartridges, tamper‑evident packaging, tracked couriers and signed chain‑of‑custody receipts.
  • Put mandatory contract clauses in place for processors: security requirements, right to audit, SLA response times and immediate incident notification.
  • Keep an authoritative media inventory and transfer log; test restoration and decryption on schedule.
  • Apply media‑sanitization and disposal standards and require proof (certificates) from any third‑party storage provider.

These controls map to regulator and best‑practice guidance on outsourcing, encryption and media handling; see the FCA, ICO and NIST media/key‑management guidance for implementation detail. (ico.org.uk)

A closing caution: encryption is essential, but only if keys, processes and testing are managed. Treat third parties as part of the control perimeter — the regulator will still hold the firm responsible. This is the practical lesson behind the fine noted by . (fca.org.uk)

Member Avatar for Member #949455
Member #949455

So it seems that Zurich has learnt from the mistakes it has made, despite the 'record fine' being but a drop in the ocean in financial terms for a company of this size. Other companies should take note that if you effectively crap on customer data security concerns then it should come as no great surprise if, when the brown stuff hits the fan as it inevitably will, the green folding stuff starts flying out of the bank...

Good Aritcle. It is sad that something like that happend.

It really can hurt any company asset. Losing that much money.

I think now most Insurance and Banks read about it and are very cautious and already adding security to prevent something like that from happening to their own company.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.