ICO warning as business fined £60,000 following cyber attack

The Information Commissioner's Office (ICO) is warning SMEs to take care or face a fine. The warning comes after a company which suffered a cyber attack was fined £60,000.

The investigation by the ICO found Boomerang Video Ltd based in Berkshire failed to take basic steps to stop its website being attacked.

Sally Anne Poole, ICO enforcement manager, said:

'Regardless of your size, if you are a business that handles personal information then data protection laws apply to you.'  

'If a company is subject to a cyber attack and we find they haven't taken steps to protect people's personal information in line with the law, they could face a fine from the ICO. And under the new General Data Protection Legislation (GDPR) coming into force next year, those fines could be a lot higher.'

'Boomerang Video failed to take basic steps to protect its customers' information from cyber attackers. Had it done so, it could have prevented this attack and protected the personal details of more than 26,000 of its customers.'

Further details of the case can be found using the links below together with guidance on data protection issues including guidance on the new General Data Protection Regulations which come into effect on 25 May 2018.

Internet links: ICO news ICO report Boomerang data protection reform updated toolkit for SMEs

Home | Contact us | Site map | Accessibility | Disclaimer | Privacy | Help |

© 2024 Manningtons. All rights reserved. We use cookies on this website, you can find more information about cookies here.

Manningtons, 8 High Street, East Sussex, Heathfield, East Sussex TN21 8LS | powered by totalSOLUTION
Battle Office, 39 High Street, Battle, East Sussex TN33 0EE

This firm is not authorised under the Financial Services and Markets Act 2000 but we are able in certain circumstances to offer a limited range of investment services to clients because we are members of the Institute of Chartered Accountants in England and Wales. We can provide these investment services if they are an incidental part of the professional services we have been engaged to provide.

Registered to carry out audit work in the UK and regulated for a range of investment activities by The Institute of Chartered Accountants in England and Wales. Our registration number is C001366129 and details can be found on www.auditregister.org.uk. Also practising as Manningtons Ltd. Company No. 04988891 Registered in England & Wales at the above address.