Jump to content

Recommended Posts

Posted

The sender probably didn't know there was that option - hands up - I didn't until I Googled it today! Anyhow, chances are some would have opened it prior to the recall being sent. Good blog about that here.

 

Could they not have recalled the message rather than sending out a message asking not to read?
Posted
Recall is never foolproof. It's more a hail Mary, cross your fingers and hope solution. Also if it was sent to non-University addresses they wouldn't have had a hope.
Posted

Either way, there's a lesson here for us all even before GDPR slaps us in the face. Educate our staff about a) being careful and b) the recall option.

 

Used it many times in my last place; talking a panicked user through the recall steps: any mitigation is better than nothing.

Posted

The point here is that a message was sent out containing personal data, unencrypted which allowed anyone to read the contents. Even if it reached the right people this message broke every rule today let alone when GDPR comes our way.

 

I'm guessing such a dreadful event will result in an ICO fine - at least it will be this year's rates not next years.

  • Thanks 1
Posted
This worse thing they could have done was send another email out asking people not to read it! I'd defiantly read it if I was told not to :D
Posted
Word to the wise... the last time I have seen the Recall function used was 9+ years ago when I worked in Business. It required the user to read the recall message and accept the recall of the original e-mail, which could not be processed if the original e-mail was already marked as read. Don't know how good it is these days.
Posted
Word to the wise... the last time I have seen the Recall function used was 9+ years ago when I worked in Business. It required the user to read the recall message and accept the recall of the original e-mail, which could not be processed if the original e-mail was already marked as read. Don't know how good it is these days.

 

Not sure about the reading of the recall message but if the original message has been read recall will not work.

Posted
Recall is never foolproof. It's more a hail Mary, cross your fingers and hope solution. Also if it was sent to non-University addresses they wouldn't have had a hope.

 

Yup. If they had send out a link to OneDrive \ Google Drive \ dropbox you could have at least deleted\revoked permissions the spreadsheet. Also you'd a have valid audit log of who \ how many people have accessed it - still all this would have done is reduce the ICO fine.

Posted
If they had just encrypted the document with a password or DRM before hand it would have been a much more minor issue. It doesn't matter if its going internally only you should protect the document and then things like this are a much smaller deal and if you are using DRM you can stop it being forwarded out as well although there are ways to get the document even if its using a mobile to take pictures of the monitor at least you can say you did everything reasonable other than sitting watching the person read it.
Posted

I'm disappointed at the general usage of the data anyway. Why is it sat in a spreadsheet like that, not individual files? Who is it that should have received that document? Did they need all the detail?

Their basic information handling seems poor, let alone how they managed to smurf this particular incident up.

Posted
Also wasn't it a distribution list ? Wonder if they should have really had permissions to send it?

 

I suspect it was a typo that caused it to be sent to a dist list rather than a person.

 

Some videos that could be worthwhile:

 

Posted
Also wasn't it a distribution list ? Wonder if they should have really had permissions to send it?

Exactly. There's more wrong than the initial slip up.

Posted
If they had just encrypted the document with a password or DRM before hand it would have been a much more minor issue. It doesn't matter if its going internally only you should protect the document and then things like this are a much smaller deal and if you are using DRM you can stop it being forwarded out as well although there are ways to get the document even if its using a mobile to take pictures of the monitor at least you can say you did everything reasonable other than sitting watching the person read it.

 

You just know if they had set a password that they would have included the password in the email ;)

  • Thanks 1
Posted
You just know if they had set a password that they would have included the password in the email ;)

Yeah thats a huge problem, its like people forget phones can call as well as tweet/whatsapp nowadays.

Posted

We operate a policy of having 5 'school' passwords that all staff have access to and then in the body of the email we just reference the passwords by numbers and everyone who should know what they are knows! They are NEVER sent via email or to external organisations.

 

That way if a slip up like this occurs the person doesn't have access to the contents.

 

Regards,

 

Dean.

Posted
We operate a policy of having 5 'school' passwords that all staff have access to and then in the body of the email we just reference the passwords by numbers and everyone who should know what they are knows! They are NEVER sent via email or to external organisations.

 

That way if a slip up like this occurs the person doesn't have access to the contents.

 

Regards,

 

Dean.

 

Good idea :thumb:

Where is the access?

Do you get them whacking it on a post-it or any breaches?

Is it better to have random dynamic ones ad hoc, or a common one? I'm just thinking for when it does become public domain - balancing ease with security.

We had a common password for some LSPs, it changed annually. Seemed to work ok.

Posted
Good idea :thumb:

Where is the access?

Do you get them whacking it on a post-it or any breaches?

Is it better to have random dynamic ones ad hoc, or a common one? I'm just thinking for when it does become public domain - balancing ease with security.

We had a common password for some LSPs, it changed annually. Seemed to work ok.

 

The passwords are stored in the Data Protection folder on the Staff Shared area on the network. We haven't had anyone writing them down or sharing with other people. The two shortest passwords are used the most commonly so most people know these off the top of their head. We use 5 'Common' passwords and change these anually and they are announced at the first INSET day at the start of term.

 

It has worked really well.

 

Dean.

  • Thanks 1
Posted
I'm sure IT instantly got a request - please delete this email or how can we prevent this from happening plus the 'it's your fault'.

I.T. is your fault. :madgrin:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...