Examination of Witnesses (Questions 1-19)
Mr Vernon Coaker, Mr Justin Millar, Baroness Vadera
and Mr Geoff Smith
20 MAY 2008
Q1 Chairman: 20 MAY
2008 May I welcome you and thank you very much for giving
us your time to come to pursue this clearly very interesting and,
from the front page of some of the papers, highly relevant topic
this morning. It seems we never escape it; it is with us. I welcome
too, members of the public who have come wanting to follow the
proceedings as they have done very carefully in the past. May
I remind you that it is of course all on the record? We have little
signs out saying who we are, we know who you are and we do appreciate
having two ministers at one meeting; it has taken some organising
and your cooperation in this has been very helpful. What we would
propose to do, unless either of you wanted to make any opening
comment, is just move straight to the questions. Do either of
you wish to make an opening statement?
Mr Coaker: No, thank you.
Q2 Chairman: May I take the first question
and then we will simply move around the table with various items
we want to raise? The original report that we put out was received
with a lot of interest and indeed the specialist press especially
took great care over some of the details in the report and the
many recommendations that we made. I have to say some of us thought
that the Government's response was just a little bit bland, which
is one way of putting it, but we followed through, in the light
not least of what has happened since then, some of the implications
that have arisen for the issues that we were considering. We thought
it timely to move now to further discussion and we would hope
to put out a short follow-up report on this topic. Perhaps I can
raise an opening question which is central to all the ground that
we covered which is; in the end, who is finally responsible for
personal Internet security? Is there a locus within the system,
within Parliament or elsewhere, and, if not, is there someone
who ought to be? We have seen various possibilities suggested;
it is a matter for the individual, it is a matter for the ISP
and so on, and we had our own recommendations on this. However,
may I just open the discussion by asking who is responsible for
personal Internet security?
Baroness Vadera: First of all, thank you very
much for the report, because I found it very interesting and read
it quite recently for the first time knowing that I was going
to be here. The report, which was somewhat more interesting than
our response, actually had it correctly pitched, that it is distributed
responsibility and that some of it is quite structural to the
sector, and there is quite a lot of complexity around this which
the report actually discusses very well. I found the analogy of
the road system quite compelling, even though, as you say, there
is no perfect analogy. I saw in some of the discussions, that
there was this view that you believed that we took the view that
it was the consumer who was ultimately responsible. I certainly
do not think that is true. I do not believe from the discussions
that I have had within the department since that, that is the
department's view, so I apologise if that was the view which came
across. It is distributed; it does make it complex. There is the
issue around both hardware and software vendors, and the security
vulnerabilities appear to come much more around the software vendors
and I know that there is an issue around what their liability
is. There is an interesting view around ISPs and what they have
to do and there is possibly more that we could do around that.
There is the Government and the consumer and of course the businesses
ultimately and to try to impose, on what is quite a complex system,
a single line of responsibility would have quite a lot of disadvantages
which you actually explore in the report around inflexibility,
inter-operability problems. Supposing you made the software vendor
liable, then you could end up with a system a little bit like
we have on mobile phones, which is that what is downloaded is
what you get access to because, in one sense they do not control
everything and they would need to control things if they felt
they were liable. We do have the system that we have and we have
to work to ensure that we raise the bar for each of those players.
Q3 Chairman: I would like to come to
ISPs in just a moment, but one of the concerns we had was that
the way the weight of the responsibility seemed to be distributed,
was that there was a very large responsibility on the individual.
This is a very complex world, that is one of the things we all
discover the more we immerse ourselves in it. You did query whether
or not we had got it right and we wondered whether the weight
should really be significantly elsewhere. Yes, individuals have
responsibilities; as with credit cards, they should not leave
them lying around and leave their pin numbers written down and
all that sort of thing. There are comparable issues here but it
is a more complicated world.
Baroness Vadera: It is right that it cannot
be weighted entirely towards consumers. As you say, it is not
that they are necessarily the best informed. There is a difference,
for example, when it comes to certain types of breaches of security.
At the time you were doing the report, phishing was quite a big
subject, but when there are things that are actually more around
the behaviour of the consumer, you can see that actually they
need to be careful. It is about actually listening to the fact
that your bank has told you not to respond to that email, so that
changes the level of responsibility. I would not say that this
needs to be entirely weighted towards the consumer at all.
Mr Coaker: Yes, that is right.
Baroness Vadera: Certainly the Government needs
to show leadership and there are some things that you suggest
in the report that we need to look at. For example, you discuss
a kite mark for ISPs which is interesting. I have been told since,
that the BSI owns the kite mark as a concept but we might be able
to look at things like a code of conduct that ISPs need to consider.
We might be able to raise the game for software vendors by giving
them, at the EU level perhaps, a sense of expectation of what
the market will want from them so that they are not rushing things
to market. Again on ISPs, we know that the ten major ISPs cover
the majority, but there is a whole tail of other ISPs that we
do not know about, which I know Vernon will have to worry about
when it comes to things like what we have done recently. We maybe
need to do some research and we need to show some leadership on
this ourselves. The ISPs do do a fair bit and I have looked at
some of the research which my officials showed me that showed
that they do actually turn off contaminated users. I do not know
whether that is the right terminology, but you know what I mean.
There are things that people are in fact already doing. We know
that increasingly hardware is actually sold with the software
already bundled in, so there is a change and I would not want
it to be believed that it was entirely an issue for the consumer
but there are certain things that the consumer really needs to
be aware of because there are certain things you cannot deal with
in the software; they are about the way they actually use the
system.
Q4 Chairman: On the question of kite
marks, the Government's response suggested you were waiting for
the EU regulatory framework and we understand that there is now
a draft of that out. Has that moved things ahead? Has the consideration
of that within Government taken place?
Baroness Vadera: There are two bits; I do not
know which bit of the EU framework you are talking about. There
are two separate things. There was the review of the Consumer
Acquis where, it is fair to say, we are struggling to get the
consumer side of this looked at but that is a separate issue.
There is currently a framework discussion around telecoms; I was
in fact in France yesterday having a discussion with the French
minister responsible. They are going to take over the presidency
of the EU starting on 1 July, but I am not sure that we will be
covering ISPs in the regulatory framework in quite that way.
Mr Smith: May I just add something on the framework?
One of the headline issues when the draft proposals were issued
was that the Commission intended to increase the security of networks.
The way those discussions have gone is focusing responsibility
on network providers and service providers to protect personal
information, interconnection points and maintain availability
of networks. So the regulatory climate is changing and there will
be increased expectations on ISPs and others from 2010 onwards.
Negotiations are, of course, underway and we are nowhere near
finished but the background is shifting to a more security-aware
environment.
Q5 Chairman: Thank you, that was very
helpful, but could you identify yourself for the record?
Mr Smith: I am Geoff Smith, I am Deputy Director,
Communication Supply, in the Department for Business.
Q6 Lord Crickhowell: I was not on the
Committee when this report was prepared, so I have picked it up,
and I suppose I have picked it up as a consumer. As we started
on consumers, I thought I would pick it up now, but I was pretty
shaken by the statement right at the start of your response that
the Government do not agree with the implication that the public
has lost confidence because of the increase in trading. Well,
I am a pretty experienced computer user, I was chairman of an
IT net company but certainly members of my family are worried
and not a day goes by without several invitations, usually from
banks, but from other organisations, for me to come back to them;
very often banks with which I do not do business, so I never open
them. Then I order something, probably asked to by my wifeI
bought something on the Internet, as it happens, 48 hours ago
from a European companyand up comes a security crosscheck.
I may be familiar with the organisation that is doing it, but
the ordinary consumer is expected, according to the Government,
to realise that half these messages from apparently respectable
organisations like major banks and building societies inviting
them to provide security information or their account will be
closed down, to know who the organisations are that are secure
when they are asked to provide the financial information to complete
their purchase. I do not believe that is fair on a huge number
of new consumers. Surely there is a need to safeguard the consumer
by providing much more information about who the kite-mark-approved
people are and indeed we ought somehow to be able to stop all
these extraordinary numbers of invitations which appear on our
computers daily requesting information. If they are not from well-known
banks, why is something not being done to get them off the system?
Baroness Vadera: Quite a lot of the ISPs have
for starters very good systems on spam. I have a private account
with an ISP, but I actually tend to find more of my emails are
quarantined than spam; I end up in a situation where, actually,
legitimate emails have been quarantined. So it is true and fair
that people need to go with good ISPs who actually can filter
emails and spam but at the end of it, if there is one basic instruction
which is "Don't give out your password by invitation in an
email", it is the same thing as "Don't leave your credit
card lying around". There is some level of responsibility
with consumers on that and I would suggest that. It is true though
that the majority of transactions from banks are actually their
responsibility, the reimbursement comes from the banks and they
have actually therefore taken it more seriously and the level
of bank security breaches has actually decreased recently. I am
not going to vouch for the numbers because they come from the
Banking Association so they are not our figures but it has gone
down, they claim, to under £25 million when it used to be
just over £30 million; it is reducing. We need to have a
number of measures, including possibly the kite-marking or code
of conduct with the ISPs, including making sure that banks feel
a sense of responsibility, which they appear to, and the fact
that consumers need to know a very basic thing. I understand it
is problematic for them to recognise who is respectable and who
is not respectable, for them to know not to voluntarily give somebody
their password on an email is a legitimate thing to ask them to
consider, and possibly for us to ensure that they are educated
about.
Chairman: I have to say I cannot resist
mischievously telling you that occasionally there is an over-zealousness
in excluding emails and I have had the House of Lords computer
exclude an email to me from the then Scottish Executive. Perhaps
that was a political statement, I do not know.
Q7 Lord Haskel: Continuing with the interests
of the consumer, in our report we recommended that there should
be an exploration of the general principle of software vendor
liability and, in the short term, that there should be liability
for negligence. You responded that this was being discussed with
the ongoing EU review of the Consumer Acquis. What is the position
on this? Is it still on the "to do" list'? Is this something
on the agenda for this meeting you were telling us about on 1
July?
Baroness Vadera: As I implied earlier, it is
fair to say that, in terms of the EU review of the Consumer Acquis,
we are not very hopeful that this will be taken up. However, we
do understand and accept the whole issue of software vendor liability.
It would be fair to say that there is more that we can do, but
I would be reluctant to start with the proposition that we need
to legislate and basically make them liable for a number of reasons.
First of all, it is actually quite hard to have attribution of
liability in a systemI actually learnt this from your report
in the first instance and then explored itbecause of the
way the Internet works on layersand actually to find a
way in which you can be clear about the liability is very difficult.
If we were, it would require a degree of control that the software
vendor would need, which, in the report again, you slightly shied
away from. You thought that was problematic, it would lead, like
mobile phones, where you only have a certain type of software
that is downloaded on it, to massive inter-operability issues.
It would also be very difficult to do this on a UK level. This
is a global industry. We do not have, in any shape or form, the
majority of the vendor industry in the United Kingdom, so we need
to be global and therefore one of the things that we were interested
in doing was taking it up at the EU level. On the issue of negligence,
the issue is whether you could prove negligence given the complexity
of the system, but if you could, then there are common law protections.
What we do need to do is to find a way, either a voluntary way
or at the EU level, to raise the bar of expectation on the software
industry, in particular this rush to market which has decreased,
famously since the memo from Bill Gates, but decreased over time,
that we ensure that there is an expectation. There are also very
interesting things that consumers are doing. I know that there
is an issue around consumers that we discussed, but, for example,
on the Microsoft Internet Explorer, that actually automatically
downloads security updates every 30 days and there is an interesting
thing going on, although I do not have the numbers, with a switch
to an alternative, Firefox, because they do it every six days
and people are beginning to become aware of that. So in one sense
a bit of competition would be a good thing to make consumers feel
more empowered. To start with the view that we need in the UK
to have a regulation that is simply for the UK, I am pretty sure
is not workable, but I know that we need to up the game and find
alternatives.
Q8 Lord Haskel: In your response you
said that there should be a debate to consider both how to improve
the reliability of software and to protect the interests of consumers,
while not reducing the quality of software available on the market
or the incentives to innovate. It does seem to me that these are
rather complicated and rather ambitious objectives. What actually
are you doing to promote this, because this is part of all this
business of protecting the consumer?
Baroness Vadera: We need to raise it at the
EU level. I was in France yesterday and we did discuss this with
the minister there; they have the French presidency. We need to
do some very basic things around licensing agreements, for example.
The National Consumer Council has referred 17 companies to the
OFT for consumer licence breaches of some sort. Apparently, in
some of these cases, you cannot actually read your licence agreement
until after you have bought the product, which strikes me as slightly
interesting and bizarre. So there are things that we can do but
we do need to have a discussion and it does need to be at the
EU level. Most of the software that is used is not produced in
the UK, so we do need to have a discussion at a different level.
Q9 Lord Haskel: Is there going to be
anything in the Bill that we were promised in the statement last
week?
Mr Coaker: It is up for discussion but I do
not know.
Baroness Vadera: It sounds like it is not because
none of us is aware of it.
Q10 Chairman: "I do not know"
is a good answer sometimes.
Mr Coaker: It is an early draft, if it is a
draft at all.
Q11 Earl of Northesk: You mentioned automatic
software updates. You will also be aware no doubt that over the
past week or fortnight, Windows issued their SP3, Service Pack
3, update. That had the effect of freezing people out of their
own computers and crashing those computers. It is all very well
to say automatic updates are useful but they are not, because
they have their problems. So the question I am really trying to
drive at is that vendor responsibility and liability have to sit
in there somewhere.
Baroness Vadera: I am sure the fact that they
have crashed systems means they will be clearly liable, but one
of the things that we do need to look at is the whole issue of
what is expected of them as an industry and although the culture
has changed quite significantly, there is still a slight sense
of rushing the next thing to the market. I can only repeat what
I said, which is that we need to have a clearer sense or expectation
that this is not acceptable.
Q12 Earl of Erroll: I would like to mention
that actually they do exclude liability, and what is worse is
that the solution is to go online to get a fix and the trouble
is they have just crashed, you so you cannot get back online so
you are in a fix. Unless you know how to do rollback, there is
not a lot you can do about it or it will be very expensive and
it is a serious problem.
Baroness Vadera: Yes, I understand.
Q13 Lord Harris of Haringey: In our report,
we said we wanted the Government to ensure " ... the right
incentives are in place to persuade businesses to take the necessary
steps, to act proportionately to protect personal data".
The Government's response said "... we do not accept that
the incidence of loss of personal data by companies is on an upward
path". Now clearly that response did not refer to government
departments. However, I suspect that things that have happened
since might mean that the response would be in different terms.
We also recommended that the Government examine, as a matter of
urgency, the effectiveness of the Information Commissioner's Office
in enforcing good standards of data protection across the business
community. You responded to that that the enforcement regime was
fit for purpose. Given all that has happened, have the Government
changed their position on any of this?
Baroness Vadera: It is fair to say that some
of the data loss experienced by the Government has been a bit
of a wake-up call. I do not know whether we would have answered
the question differently. The only thing I would point out is
that a lot of it has been around security practice; rather than
necessarily something that is current in the software or anything
else, there is an issue around security practice. The first thing
is obviously for the Government to get their house in order and
you will be aware, from the statements that have been made by
Alistair Darling and Ruth Kelly, that there is quite a lot going
on here. We have a report being done by PWC on HMRC. We have Richard
Thomas and Mark Walport doing something around whether we need
to look at the Data Protection Act 1998. Gus O'Donnell has been
asked by the Prime Minister to work with departments and I would
say that in fact probably we will find that performance on this
has improved. I know for a fact that in BERR in the last six months,
there have been changes so that laptops and disks and things cannot
be taken out unless they are encrypted. There is stuff going on
in Government. I do not know about the exact timing, whether it
was just after the report, but, with reference to the Information
Commissioner, the Criminal Justice and Immigration Act has actually
given him powersI think it is since the reportto
impose monetary penalties. In the process of going through the
Regulatory Enforcement and Sanctions Bill, if there were illegal
activity then we could give the Information Commissioner an Order
that would give the ability to impose monetary fines which are
actually unlimited, unless we limit them in the Order. The ICO
has also since published guidance on how to notify companies about
breach of security. We ourselves do have a business survey on
information breaches which is interesting and we are very happy
to send you that; I personally found it quite intriguing. There
is quite a mixed picture, some improvements and some things that
are still a little bit worrying but I was pleased that of IT spend,
there is a trend of increasing spend on security, although still
20 per cent or thereabouts of companies only spend less than one
per cent of their IT spend on security so there is clearly more
that we could do. There is a lot going on. The fact that it is
something that people are very aware ofthat is on the front
pages of the papershas certainly meant that business as
well as Government are taking this very seriously.
Q14 Lord Harris of Haringey: We recommended
very specifically that the Information Commissioner be able to
implement random audits of security measures. On 21 November Downing
Street was briefed, after the HMRC incident, that the Government
were taking this forward. What progress has actually been made?
Baroness Vadera: I am afraid I do not know the
answer to that. I do not know whether Geoff knows, otherwise we
will let you know in writing.
Mr Smith: That would be the best solution. I
know that the Information Commissioner had been developing ideas
around that and they have not been particularly well received,
but that is not to mean that that is not going to happen. It may
be that we might be waiting for the Thomas/Walport report which
is going to be quite a fundamental look at the Data Protection
Act, but yes, we will certainly write to you.
Q15 Lord Harris of Haringey: I am sure
that would be helpful. You mentioned your survey on what is being
done. In the report we recommended a data security breach notification
law. The Government's response was that you "would consider
whether we need to find more formal ways of ensuring that companies
doas a matter of routinecontact the ICO when problems
arise. Government of course is now almost falling over itself
to tell us when problems have arisen, even when data has been
heavily encrypted. However, the number of communications from
the private sector seems to be a trickle. I cannot believe they
are immune to this sort of problem, and your survey suggests that
will not be the case. What is the current thinking on a breach
notification law?
Baroness Vadera: There is basically guidance
that the ICO has since put out for the private sector that tells
them about when and how they might consider
Q16 Lord Harris of Haringey: That is
guidance. Do you want to make it a compulsory requirement that
people should notify those whose data is distributed generally?
Baroness Vadera: Your report and evidence that
I read subsequently show that this is not straightforward, you
want to find the balance between a tick box approach which makes
people feel a little bit immune and actually some level of significance
in the event. As you say, we are falling over ourselves to notify,
as Government, every breach even when it is encrypted so we do
have to find the balance. My personal view is that it is very
hard and we are looking at all of this in terms of the various
reviews that I have already mentioned, so I do not want to suggest
something before we know what may come out of that. It would be
very difficult to legislate or regulate for the level at which
you should inform because it is really about proportionality and
significance, is it not? All of this is being considered in the
variety of reviews that are going on.
Q17 Lord Harris of Haringey: Health and
safety legislation, by placing personal responsibility on individual
managers and indeed on boards of directors, has transformed attitudes
towards health and safety in the workplace. Is there not a case
for equivalent legislation, as far as information security is
concerned, to make sure that all managers and indeed all employees
and indeed those who are responsible for organisations in both
the public and private sectors, take this as their personal responsibility,
with perhaps implications for their personal liability if they
fail to do so?
Baroness Vadera: I do not personally believe
that that would be a proportionate response, but, again, these
are things that are being considered and looked at and I would
not want to presume to speak before everybody has really considered
all of the issues. All I would say about the health and safety
regulations is that nobody said that anything is perfect and the
reason I know that is because we are reviewing those as well right
now in my department. We need to have something that is proportionate
and is going to be effective. The most important thing is being
effective rather than just to say automatically that we need to
legislate.
Q18 Chairman: Lord Harris's point does
require underlining, that in the health and safety sector, major
companies put policies in place and it transformed the statistics
and the reality and that is worth putting on the record.
Baroness Vadera: I did have a statistic which
I cannot remember off the top of my head, but actually quite a
significant proportion of companies have security policies in
place, as you will see from the survey.
Mr Smith: It is near 80 per cent.
Q19 Earl of Erroll: I just wanted very
quickly to ask whether you do actually hold out much hope of being
able to strengthen the powers even if you do alter the Data Protection
Act when you consider what happened in the Criminal Justice and
Immigration Bill when they watered down what was originally section
216 or 219 and introduced section 75, and then further watered
it down so that the powers that were to be given to the ICO basically
got watered down to a fine. There is no point in fining a government
department, it will merely make the service worse, and as for
fining an individual, well the person who has bribed them to release
the information will probably offer to pay the civil penalty.
So how are you going to strengthen it, if you are going to water
down your provisions the whole time? It was not under parliamentary
pressure either.
Baroness Vadera: Vernon knows more about that
particular Act but on the Data Protection Act, we are still waiting
for the recommendations so it would be slightly premature to talk
about the fact that we are going to water down the recommendations
before we have received the recommendations. That is not entirely
fair.
|