Eight of the most common IT security flaws that have led to organisations leaking sensitive information have been highlighted in a new report by the Information Commissioner's Office (ICO). The report Protecting personal data in online services: learning from the mistakes of others" - identifies errors thrown up during the ICO's investigations into data breaches caused by poor IT security practices. It offers guidance on how best to protect data. The top eight computer security vulnerabilities covered in the report were: a failure to keep software security up to date; a lack of protection from SQL injection; the use of unnecessary services; poor decommissioning of old software and services; the insecure storage of passwords; failure to encrypt online communications; poorly designed networks processing data in inappropriate areas; and the continued use of default credentials including passwords.




