Showing posts with label poynter. Show all posts
Showing posts with label poynter. Show all posts

Wednesday, 6 February 2008

Postal Security

Postal SecurityDespite attempts by HMRC to try to portray last year's datagate fiasco as one of a small number of "one off" cock ups (a contradiction in terms of course), HMRC face claims that it was in "chaos" even before it lost 25 million personal records.

The Government recently confirmed that several hundred jobs were axed at the Washington office of HMRC (that's where the information was lost) since 2005, and 179 staff in the North-East have been dismissed in the past three years.

In order to make up for the shortfall in staff, HMRC have paid private postal contractors £226M to handle the organisation's mail since 2005.

On top of this, HMRC have hired consultant PricewaterhouseCoopers to review HMRC's data handling. However, the government will not tell anyone how much this consultation is costing the British taxpayer; seemingly they regard it as "commercially confidential".

How very inconvenient!

As the Chief executive of the TaxPayers' Alliance, Matthew Elliott, succinctly put it a fortnight ago:

"HMRC has clearly been operating in a state of chaos, apparently staggering from one mistake to another.

Given this sorry tale of mismanagement, poor morale and shoddy data practices, it is no wonder that they ended up making such a disastrous error.

With such systemic failings, they were an accident waiting to happen. Taxpayers have a right to expect their money is spent competently and their information is protected – HMRC has failed on both counts
."

Newcastle Central Labour MP Jim Cousins, is also not impressed with HMRC:

"The pressure from outsourcing to private contractors and to reduce the number of staff – and they are ahead of schedule in their job cuts – I think has produced a chaotic situation."

Hexham Conservative MP Peter Atkinson recently warned that the cost benefits of cutting jobs and outsourcing don't seem to have taken account of the security risks:

"I have no objection to outsourcing postal and courier services, but if they are going to have an outsourced service, they should at least make sure it is a secure service."

You pay peanuts, you get monkeys!

Tax does have to be taxing.

HMRC Is Shite (www.hmrcisshite.com) is brought to you by www.kenfrost.com "The Living Brand"

Tuesday, 18 December 2007

A Serving of Fudge

A Serving of Fudge
Alastair darling served MP's up a generous portion of fudge yesterday, when he outlined the results of the Poynter review into the HMRC "Datagate" fiasco.

Seemingly the review is not yet finished.

How convenient!

"Let us wait and establish the facts rather than jump to conclusions."

Was Darling's response to detailed probings from MPs.

In the meantime, Poynter has come up with a few urgent recommendations.

HMRC will need a new organisational structure, simpler one with accountability at executive level.

A fair point, the trouble is "simplicity" and Gordon Brown simply do not go together.

Here are some his other recommendations, the pharse "bleeding obvious" springs to mind:
  • A reminder to all staff from the Chairman of HMRC of the importance of data
    security with some specific guidance


  • The appointment of a senior official to the new post of Director of Data
    Security


  • The appointment of Data Guardians in each area of HMRC


  • The imposition of a complete ban on the transfer of bulk data onto removable
    media without adequate security protection such as encryption


  • The disabling of the download function on all personal and laptop computers
    in use across HMRC to prevent their use to download data onto removable
    media


  • The utilisation of secure couriers and appropriate tamper proof packaging in
    the transport of bulk data stored on removable media
The full verdict on the failure HMRC's data procedures is due "in the first half" of next year. A standard ploy by government, designed to ensure that by then everyone will have lost interest in the subject.

Here is the Poynter Review in full (all 6 pages of it).

A nice little earner for the consultants!

By the way, let us be perfectly clear, the report is complete shite and a waste of our money (anyone who uses the phrases "world class" and "HMRC" in the same sentence is clearly out of his depth).

www.hmrcisshite.com is brought to you by www.kenfrost.com "The Living Brand"

Friday, 14 December 2007

Spin

Spin
The Chairman of PricewaterhouseCoopers, Kieran Poynter, will publish an interim report into the IT failures at the HMRC on Monday. It had been scheduled for today, unaccountably it is being delayed until the final week in the run up to Christmas.

I wonder why?

Coincidentally, or maybe not, Chancellor Alistair Darling is to announce measures on Monday that will in his view prevent a repeat performance of "Datagate". He will also call a halt to the police search for the missing discs.

The search was downgraded last week from 47 detectives to 32.

Needless to say, HMRC and the government continue to blame a junior member of staff for the loss.

How convenient!

This blame game continues to be played out, despite the fact that the CDs were sent unencrypted three times and the HMRC ignored a request to send only part of the information rather than the complete database.

A pretty lousy way to deflect blame, and to spin the story, but this is what we have come to expect from this government.

www.hmrcisshite.com is brought to you by www.kenfrost.com "The Living Brand"

Monday, 3 December 2007

Heads in The Sand

HMRC Heads in The Sand
Much like ostriches with their heads in the sand, the people "in charge" of HMRC are refusing to learn the lessons of the recent shambolic loss of data and are still using the post to transfer people's personal details.

The Telegraph reports that details of 9 million people's investments (worth £60BN) are being sent insecurely through the post, because HMRC requires these discs to be unencrypted.

HMRC requires fund managers to submit details every year of all investors' names, addresses, dates of birth, National Insurance numbers and the amount each individual has invested in Isas and Peps.

So far so good.

However, HMRC stipulates that this data must be delivered in an unencrypted extended binary coded decimal interchange code (EBCDIC), or American standard code for information interchange (ASCII) text format.

Why does HMRC make such a stipulation?

Richard Saunders, chief executive of the Investment Management Association (IMA), believes that he has the answer:

"I assume this is because HMRC does not have systems to cope with this information in encrypted form and it may cost more for it to have systems that cope with secure data."

Mr Saunders has written to David Hartnett, chairman of HMRC, asking for this practice to be stopped. He awaits a response.

A spokesman for HMRC said:

"Sorry, we are not commenting as this falls under the terms of reference of the Poynter review."

So that's alright then!

They just don't get this security issue do they?

www.hmrcisshite.com is brought to you by www.kenfrost.com "The Living Brand"

Tuesday, 20 November 2007

Darling Admits HMRC Data Loss

Alistair Darling told the House of Commons this afternoon that a police investigation has been launched into how Her Majesty's Revenue and Customs has lost child benefit records relating to 25 million people.

Records for 25 million people, relating to child benefit payments for 7.25 million families, were sent using the HMRC's own postal system, called grid, but never arrived.

The Chancellor, flanked by PM Gordon Brown, told the House that the National Audit Office requested information which was first sent to them in March, in breach of HMRC procedures, and then returned to HMRC.

In October the NAO made another request and the entire database was put onto two password-protected discs which were sent by grid post.

Those discs did not arrive and cannot be found. A further copy of the information was sent again, this time by registered post.

Darling was first told November 10 and called for an immediate search. On Monday, November 12, he was told HMRC believed it would find the data but on Wednesday Darling called the police in to investigate. Police are continuing to search NAO and HMRC offices.

Darling said in light of the most recent failures, along with previous losses of a laptop and 15,000 records, he was asking Kieron Poynter of PWC to investigate HMRC procedures. An interim report is expected next month and the full report next spring.

Banks have been informed and are monitoring relevant accounts as well as tracking back to transactions made after 18 October. Darling said police had found no evidence of the data being misused.

Vincent Cable, acting leader of the Lib Dems, asked why any information was being sent around via CD rather than electronically and if this was a result of HMRC's ancient IT system.

Richard Thomas, Information Commissioner, said:

"This is an extremely serious and disturbing security breach. This is not the first time that we have been made aware of breaches at the HM Revenue and Customs – we are already investigating two other breaches.

Any system was only as good as its weakest link
."

Thomas said:

"The alarm bells must now ring in every organisation about the risks of not protecting people's personal information properly.

As I highlighted earlier this year, it is imperative that organisations earn public trust and confidence by addressing security and other data protection safeguards with the utmost vigour
."

Thomas said the PWC report would be passed on to him, "and we will then decide what further action may be appropriate. Searching questions need to be answered about systems, procedures and human error inside both HMRC and NAO."

Jamie Cowper, Director of European Marketing at PGP Corporation, said in a statement:

"These discs should never have been transported in the first place - information of this type should only be transmitted using the strongest security protocols available such as encrypted batch transfer - but more to the point, these details should not have been stored in this medium.

Discs are easy to lose, but difficult to protect. This type of information should only be stored on formats where the data can be encrypted transparently, so that it remains protected wherever it resides, and whether at rest or in motion
."

Source The Register