Cyber Security Training - Find a freedom of information request

Request

1. For each of the last five financial years, including the present financial year (regardless of completion), please would you provide available data on the:

  • Gross training expenditure on all county council employees.
  • Gross expenditure spent on cyber security training and awareness programmes for all county council employees.
  • Number - and if recorded, the type - of cyber and non-cyber data breaches reported to the Information Commissioner’s Office (ICO).
  • Number - and if recorded, the type - of personal data related ‘incidents’.

 

Notes for clarification:

  • By ‘incident’, I mean cases when sensitive information is threatened, but not necessarily compromised. Incidents may not be reported to the ICO.
  • By ‘type’, I mean the nature of a security breach or incident. Examples of type might be ‘malware’, ‘phishing’, ‘misconfigured software/hardware’, ‘data emailed to incorrect recipient’ or ‘verbal disclosure of sensitive information’.

In your response, please would you also confirm the dates of your financial year.

Decision

1. Lincolnshire County Council do not hold this information centrally as the budgets for training are delegated to individual service areas

With regard to cyber security training – this is an e learning course which was developed as part of a suite of on-line training and LCC do not have a specific cost for this

Year Number of data breaches reported to the ICO Type
15/16 5

4xdisclosed in error

1 x theft of data/hardware

16/17 3

2x disclosed in error;

1 x theft of data/hardware

17/18 0 N/A
18/19 13

10x unauthorised disclosure

2x theft of data/hardware

1 x loss of data/hardware

19/20 (to 1 Dec 19) 5 5 x unauthorised disclosure

 

Year Number of personal data related incidents Type
15/16 126

78x disclosed in error

3x insecure disposal

6x insecure transmission

14x loss of data/hardware

7x other

4x theft of data/hardware

14 x unauthorised access

16/17 146

71x disclosed in error

2x insecure disposal

14x insecure transmission

20x loss of data/hardware

16x other

7x theft of data/hardware

16 x unauthorised access

17/18 210

19x failure to safeguard 1

x insecure disposal

4x insecure transmission

46x loss of data/hardware

7x other

4x theft of data hardware 1

6x unauthorised access

113 x unauthorised disclosure

18/19 250

13x failure to safeguard

3x insecure transmission

26x loss of data/hardware

11x other

3x theft of data/hardware

14x unauthorised access

180 x unauthorised disclosure

19/20 (to 1 Dec 19) 155

137x unauthorised disclosure

7x loss of data/hardware

4x theft of data/hardware

2x failure to safeguard

4x unauthorised access

1 x other

Reference number
FOI0901
Date request received
22 November 2019
Date of decision
29 January 2020