The public body in charge of the UK's state investments has been pushed to improve its internal security after a data breach left "high-level management information" publicly accessible for 40 hours, the Guardian reported on August 2. The breach affected 51 government officials.
What Happened
The British Business Bank, which manages the UK's state investments, accidentally made a portion of its internal SharePoint accessible without authentication. The exposure included names, contact details, and certain internal documents related to senior government officials. The bank closed the access gap within 40 hours after being notified.
"The public body in charge of the UK's state investments has been pushed to improve its internal security after a data breach left 'high-level management information' publicly accessible for 40 hours," the Guardian wrote.
Why It Matters
The breach is one of several recent incidents that have raised questions about the UK government's data-handling practices. The Information Commissioner's Office is investigating. The bank has committed to an internal review and additional staff training. Opposition MPs have called for a wider review of how UK public bodies handle sensitive data.
What's Next
The ICO investigation will determine whether the bank breached UK GDPR. If so, the bank could face a fine - the ICO has issued several significant fines for similar incidents in recent years. The bank has also engaged an external cybersecurity firm to review its systems. The breach is the latest reminder that even basic misconfigurations can expose sensitive government data.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.