- Request
-
1. For each of the last five financial years, including the present financial year (regardless of completion), please would you provide available data on the:
- Gross training expenditure on all county council employees.
- Gross expenditure spent on cyber security training and awareness programmes for all county council employees.
- Number - and if recorded, the type - of cyber and non-cyber data breaches reported to the Information Commissioner’s Office (ICO).
- Number - and if recorded, the type - of personal data related ‘incidents’.
Notes for clarification:
- By ‘incident’, I mean cases when sensitive information is threatened, but not necessarily compromised. Incidents may not be reported to the ICO.
- By ‘type’, I mean the nature of a security breach or incident. Examples of type might be ‘malware’, ‘phishing’, ‘misconfigured software/hardware’, ‘data emailed to incorrect recipient’ or ‘verbal disclosure of sensitive information’.
In your response, please would you also confirm the dates of your financial year.
- Decision
-
1. Lincolnshire County Council do not hold this information centrally as the budgets for training are delegated to individual service areas
With regard to cyber security training – this is an e learning course which was developed as part of a suite of on-line training and LCC do not have a specific cost for this
Year Number of data breaches reported to the ICO Type 15/16 5 4xdisclosed in error
1 x theft of data/hardware
16/17 3 2x disclosed in error;
1 x theft of data/hardware
17/18 0 N/A 18/19 13 10x unauthorised disclosure
2x theft of data/hardware
1 x loss of data/hardware
19/20 (to 1 Dec 19) 5 5 x unauthorised disclosure Year Number of personal data related incidents Type 15/16 126 78x disclosed in error
3x insecure disposal
6x insecure transmission
14x loss of data/hardware
7x other
4x theft of data/hardware
14 x unauthorised access
16/17 146 71x disclosed in error
2x insecure disposal
14x insecure transmission
20x loss of data/hardware
16x other
7x theft of data/hardware
16 x unauthorised access
17/18 210 19x failure to safeguard 1
x insecure disposal
4x insecure transmission
46x loss of data/hardware
7x other
4x theft of data hardware 1
6x unauthorised access
113 x unauthorised disclosure
18/19 250 13x failure to safeguard
3x insecure transmission
26x loss of data/hardware
11x other
3x theft of data/hardware
14x unauthorised access
180 x unauthorised disclosure
19/20 (to 1 Dec 19) 155 137x unauthorised disclosure
7x loss of data/hardware
4x theft of data/hardware
2x failure to safeguard
4x unauthorised access
1 x other
- Reference number
- FOI0901
- Date request received
- 22 November 2019
- Date of decision
- 29 January 2020