Select Committee on Science and Technology Written Evidence


Memorandum by Symantec

ABOUT SYMANTEC

  Symantec is a world leader in providing solutions to help individuals and enterprises assure the security, availability, and integrity of their information. Headquartered in Cupertino, Calif., Symantec has operations in more than 40 countries.[12]

  Symantec welcomed the publication of the House of Lords report into Personal Internet Security in August 2007. Since its publication the report has encouraged discussion around the responsibility of security on the Internet and has helped to highlight and raise greater awareness of the need to fight e-crime in the UK. In preparation for the forthcoming debate on the Committee's findings Symantec appreciates the opportunity to provide additional input to the Committee.

  The aim of the following submission is to provide supplementary evidence in response to the recommendations made by the Committee and the Government's response to the Committee's report on three key issues:

    —  Vendor liability.

    —  Data security breach notification law.

    —  Establishment of a Police Central e-Crime Unit.

DATA SECURITY BREACH NOTIFICATION LAW

  It is suggested that the recent high profile incidents of personal data loss has prompted wide discussion in the UK on the level of security given to personal information shared, processed, stored and transmitted electronically. Incidents where personal sensitive information, such as financial, contact and employment information, and sensitive identity related data has been lost, stolen, accessed or disclosed without authorisation, are leading to questions and increasingly, demands for answers, by citizens as to what happens if their data is involved in such incidents. Gaining and maintaining the trust and buy-in of citizens that their data is secure and protected therefore represents a potential risk to the future development of innovative, higher value added online services and will be a key challenge going forward for organisations and the Government.

  Symantec, therefore, welcomed the Committee's recommendation for the introduction of data breach notification law in the UK as a matter of urgency. While the Government's recognition that such a suggestion warrants further discussion and consideration is understood and accepted, the view that the introduction of notification initially within the UK would not "lead to an improvement" or have an impact on the safety and protection of personal information is, we feel, debatable.

  The development and introduction of an appropriately drafted data breach notification legal requirement is seen as an important incentive to increase levels of security and also help raise greater awareness, and reassurance, of how personal data is protected online. It is also suggested that a data breach notification law could help to raise citizen's awareness of the risks their data is being open to and therefore enable them to take appropriate action where necessary. By being given information, citizens can become more empowered to make informed decisions and take measures to protect their identities that may be at risk. Such activities may include monitoring financial accounts for discrepancies, not responding to potential phishing emails related to a data breach or simply ensuring personal information is not disclosed unnecessarily. It can be argued that the action of presenting an individual with a data breach notification letter, for example, could mean that individuals become more aware of the situation and by being fully informed are able to take action they see as appropriate to protect their identity or personal information going forward.

  Based on the evidence given in its response, regarding the disjointed approach taken across US States to the introduction of data breach laws, the Government's concerns and questions expressed as to the positive impact of the data breach legislation in the US are understood. However, it should be recognised that if introduced, a data breach notification requirement would simply be an addition to the already effective existing Data Protection legal framework in place in the UK and across Europe. The current European Data Protection law effectively protects the lifecycle of personal data from its collection and processing to its storage. However, the current legal framework does not address circumstances where data is lost or stolen. A legal gap therefore exists that needs to be closed particularly in light of the increase in incidents of data being lost or stolen occurring in Europe. Closing this gap would not only complement the current Data Protection legislation but also serve to enhance the security of data throughout its complete lifecycle.

  Symantec does agree with the Government that given the potential impact of legislation in this area it is important that the move towards data breach notification is one which is carefully considered. This is vital to ensure that a clearly defined legal framework and appropriate operational procedures are established that is workable and not burdensome on either citizens or industry. For example, there is further discussion needed on how a data breach notification requirement in the UK would work in practice; fundamentally in the event of a breach what immediate action would an organisation have to take. This includes the definition of an incident that would be considered a "breach" of data and the level of seriousness a breach would have to be to trigger a notification obligation; in addition, as identified by the Government's response, whether companies would be required to notify the Information Commissioner's Office (ICO) before alerting customers. This raises the question of whether the decision to notify customers will rest with the ICO or with the organisation itself. These definitions are a vital part of any data breach legal framework and must be clearly defined so that companies clearly understand when a data breach notification requirement would be triggered. Also any legal requirement that is drafted should include a safe harbour provision to ensure that in the event of a data breach, organisations that can demonstrate an adequate level of data security are relieved from liability and possible legal or financial penalties for the breach.

  Nevertheless Symantec welcomed the Government's recognition that any data breach notification requirement should not apply solely to communication provider "in isolation". Recent incidents of data loss in other key sectors, such as finance and retail, indicates a strong argument that companies in all sectors, public and private, that are processing and storing individuals personal data electronically should be required to comply with a data breach notification law. In the latest Symantec Internet Security Threat Report, published in September 2007, education was the highest sector for data breaches that could lead to identity theft with 30 per cent. This was followed by government (26 per cent), healthcare (15 per cent) and the finance sector (14 per cent). The Government's review that if a data breach law is introduced in the UK it should not impact solely any one sector is therefore supported by Symantec.

  Given that the European Commission's proposals to introduce a data breach notification law for the communication sector may not come into force until at least late 2009 early 2010, it is suggested that further consideration and discussion is needed on the need for the UK to become a pioneer and lead the way in Europe but introducing an appropriate, and reasonable, data breach notification requirement in the UK and not wait possibly for five years for the European legislative process to introduce breach notification that will only impact one sector. Symantec believe that an appropriate data breach notification law could be effective if applied to all sectors that are processing and storing individual's personal data. However, the steps currently being taken by the European Commission to introduce an appropriate data breach notification requirement across Europe is seen as a step in the right direction.

ESTABLISHMENT OF A POLICE CENTRAL E -CRIME UNIT

  The Committee's acknowledgment that the Internet has become a powerful and critical tool in the UK's national infrastructure is reflective of the in-depth investigation and consideration the Committee has given to this important topic. Symantec agrees with the Committee that industry, end users and the Government all need to be doing more to ensure the protection of this resource. In particular Symantec endorses the Committee's recommendation supporting the creation of a Police central e-Crime Unit. The Government's response that consideration was being given to the business case for creation of a dedicated law enforcement unit for e-crime along the lines proposed by the Committee is also encouraging. However, while it is understood that the National Fraud Reporting Centre has been given additional funding in the recent Comprehensive Spending Review to develop a strong "anti-fraud culture", in addition to further investment for policing and a more strategic approach to be taken towards "cutting crime", e-crime was noticeable by its absence in the Government's spending plans published back in October 2007. As we now move into March 2008 it is still not clear whether the business case for the creation of a Police central e-Crime unit will be supported both operationally and more importantly financially.

  In its response, the Government acknowledged that national co-ordination for policing in this area could bring benefits to the fight against e-crime in the UK. This view is supported as is the comment that for the creation of any new unit there must be a clearly defined need in order to ensure an effective response. It is agreed that an e-Crime policing unit would need to have clearly defined aims, objectives and goals. However, Symantec believe there is a clear need for a national police presence in the fight against e-crime in the UK.

  The recent shift in the online threat environment towards computer related attacks being motivated, not by notoriety, but by economic gain has resulted in individual users, as well as companies, becoming front line targets for cyber criminals. Individuals are increasingly targeted by attacks designed to steal confidential information that can be used to commit fraud and theft. It is understood that such crimes must be investigated and prosecuted as traditional crimes (such as fraud) merely conducted using a new tool (technology). However, it must be recognised that policing resources, focus and training are needed to effectively investigate and address these modern technological enabled crimes. This is why there is a clear need for the creation of a central e-crime police unit that can support law enforcement efforts. The UK is currently one of the most effective and best placed countries in addressing cyber crime. In order for this reputation to continue however, Symantec believe more training and more resources are needed by UK police not just in London but across the whole of the UK. The introduction of a dedicated national e-Crime policing unit would be a step in the right direction to enhancing the UK police's ability to respond to e-crime effectively; at a time when concerns regarding online security risks, arising from spam, phishing, social networking sites and online data theft, may be preventing citizens gaining the full benefits from the Internet. For example results of a recent Get Safe Online campaign survey, to which Symantec is a leading sponsor, indicates that almost one in three UK internet users[13] will not conduct banking online due to their fears about safety and security.

VENDOR LIABILITY

  When the Committee's findings were published in August 2007, Symantec welcomed the Committee's recognition of the importance of ensuring interoperability, consumer choice and a competitive landscape in the information security market. However, the view that software companies should be liable for ineffective products and services offered to users is nevertheless challenged. There is also concern at the Government's response to the Committee which suggested that there is "scope" for further discussion of this issue at the European level. Symantec believe extending the product liability regime of the European Consumer Sales Directive, as discussed in the European Commission's Green Paper, to digital content including software could result in reducing consumer choice and risks the opposite effect of reducing users' security and privacy.

  The Committee's suggestion in this area does not take into account the complexity of the IT industry. Essentially software companies cannot be liable for what they do not effectively control. For example, how the customer installs, configures, uses and updates its software. Effective security is a combination of a layered security approach, processes, people and technology. An approach whereby the liability burden is placed on software providers therefore runs the risk of simply putting the burden only on technology and ignores all the other components. Also, it is doubtful that companies would be prepared to take liability for their products unless they can assume a level of control on how the interoperability takes place and ensure it does not affect their applications This may lead to technology providers using more privacy-invasive technologies to control not only the interoperability allowed but possibly user actions in order to avoid or limit liability. Ultimately, an approach along those lines could fundamentally impact the control users have on their computer. It could also result in more and more closed platforms and a potential situation where one dominant provider could dictate what can be installed and may limit the choices of consumers to "approved content". This could have a negative impact on competition in the market and risks creating monocultures in information security terms which, as explained to the Committee in our written and oral evidence, could create a single point of failure across the Internet's infrastructure. As a result there is real concern that the introduction of vendor liability could have the unintended consequences of reducing consumer choice and negatively impacting the level of information security that users currently enjoy. If vendors have to absorb product liability in their business models then the current innovation environment of open and interoperable platforms will be radically shifted.

  Symantec remains supportive of the overall objectives of the Committee in trying to support Internet users and ensure there is an adequate level of protection for users against online threats. The Government's recognition that the debate around vendor liability should not prevent innovation in the market or lead to a reduction in the quality of software is welcomed. However, it is argued that by following a legislative path discussed by the Committee that may lead to the introduction of vendor liability could very well result in the situation that the Government agrees must be prevented.

March 2008






12   www.symantec.com Back

13   Get Safe Online Survey Published November 2008 www.getsafeonline.org. Back


 
previous page contents

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008