Red Mosquito - Blog

Cyber-security flaws lead to £20m fine

The Information Commissioner’s Office (ICO) has fined British Airways (BA) £20m for failing to protect the personal and financial details of more than 400,000 of its customers. This eye watering sum is actually far less than the original fine they faced of £183m. The ICO has reduced the fine saying they are taking the economic impact of Covid into account.  There are lessons to be learned, for businesses of all sizes, from the cyber-security weaknesses which enabled this attack to succeed.

BA was the target of a cyber-attack in 2018 but only became aware of the issue 2 months later when it was identified by an independent 3rd party. The ICO found that BA were processing personal data without having adequate security measures in place. As we all know, GDPR stipulates that organisations must have “appropriate technical and organisational measures in place” to protect data. BA ought to have identified and addressed the cyber security weaknesses. In addition, ICO investigators were seriously concerned that BA was not aware that it had been attacked. Interestingly, the weaknesses identified would most likely have been addressed by certification to the UK’s Cyber Essentials Scheme.

In BAs case some of the actions they could have taken to prevent the attack include:

· Access Control – limiting access to applications, data and tools to only that which are required to fulfil a user’s role

· Penetration Testing – undertaking rigorous testing, in the form of simulating a cyber-attack, on the business’ systems;

· Multi Factor Authentication – protecting employee and third party accounts with multi-factor authentication.

These measures are neither complex nor expensive to implement. In fact, all would be addressed during the process of certification to Cyber Essentials. Our previous blogs give a great overview of the scheme.  Certification ensures the basic cyber-security controls are in place. Implemented corrected these would prevent the vast majority of cyber attacks. We strongly advise all of our IT Support customers in Glasgow and Edinburgh to get Cyber Essentials in place. It will protect your data and help you avoid cyber attacks & the hefty fines which may follow.

As an outsourced IT provider, we support all of our IT Support customers to ensure they have the correct cyber-security measures in place. We always recommend a multi-layered approach to cyber-security. If you would like to speak to one of our IT consultants about your cyber security needs or Cyber Essentials certification – just contact us today.

The Growing Importance of Cybersecurity for Irish SMEs in 2025

The Growing Importance of Cybersecurity for Irish SMEs in 2025

Introduction The digital world is evolving at an unprecedented pace, and with it, the risks that businesses face are also growing. Cybersecurity is no longer just a concern for large corporations; it has become a critical priority for Small and Medium Enterprises (SMEs) in Ireland. Many SMEs mistakenly believe that[…]

19 Mar 2025
The Future of IT Support: How Irish Businesses Can Stay Ahead in 2025

The Future of IT Support: How Irish Businesses Can Stay Ahead in 2025

Introduction The way businesses approach IT support is undergoing a significant transformation. In the past, IT support was primarily reactive—companies would only call for help when something broke. However, in 2025, Irish businesses must adopt a proactive approach, ensuring that systems remain efficient, secure, and[…]

18 Mar 2025
Disaster Recovery Planning: Why Irish Businesses Need It in 2025

Disaster Recovery Planning: Why Irish Businesses Need It in 2025

Introduction Unexpected IT failures, cyberattacks, and natural disasters pose serious risks to businesses. Without a solid disaster recovery plan (DRP), companies may suffer data loss, operational downtime, and financial damage.

17 Mar 2025
Cloud Computing Trends: How Irish Businesses Can Benefit in 2025

Cloud Computing Trends: How Irish Businesses Can Benefit in 2025

Introduction Cloud computing is no longer just an IT trend; it has become the foundation of modern business operations. Over the past decade, companies in Ireland have transitioned from traditional on-premise IT infrastructure to cloud-based solutions, benefiting from scalability, flexibility, and cost efficiency.

15 Mar 2025