Data breach reports see 75% increase in last two years

Data breaches are up 75% in two years, finds a report from the Information Commissioner (ICO).
The study, carried out by Kroll, took into account an array of personal data, including health, financial and employment details.
Access to this data was made possible under the Freedom of Information Act, in addition to some ICO data being publicly available.
Kroll found that over 2,000 reports received by the ICO within the last year could be attributed to human error, compared to just 292 that were deliberate cyber incidents.
Of the reports that were possibly caused by human error, the most common breach types were identified as emails to incorrect recipients (447), data posted or faxed to incorrect recipients (441), and loss or theft of paperwork (438).
As for purely cyber-related attacks without human involvement, the most frequent type within the last year was unauthorised access (102).
Additionally, the health sector was revealed to be the most common source of data breach reports, yielding a total of 1,214, with general business (362), which yielded the highest increase percentage over the past two years (215%), following behind.
Kroll said that the increase in reports indicates a correlating increase in transparency on the part of companies as a result of the EU General Data Protection Regulation (GDPR)’s introduction back in May.
“Reporting data breaches wasn’t mandatory for most organisations before the GDPR came into force,” explained Andrew Beckett, Managing Director and EMEA Leader for Kroll’s Cyber Risk Practice, “so while the data is revealing, it only gives a snapshot into the true picture of breaches suffered by organisations in the UK.
“The recent rise in the number of reports is probably due to organisations’ gearing up for the GDPR as much as an increase in incidents.


