<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CEI Compliance Consultancy &#187; data security</title>
	<atom:link href="http://cei-compliance-limited.co.uk/blog/tag/data-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://cei-compliance-limited.co.uk/blog</link>
	<description>UK Financial Services Regulatory Compliance Consultancy Briefing</description>
	<lastBuildDate>Sun, 05 Feb 2012 16:56:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>IFAs Fined Nearly £1M in 2010</title>
		<link>http://cei-compliance-limited.co.uk/blog/ifas-fined-nearly-1m-in-2010/</link>
		<comments>http://cei-compliance-limited.co.uk/blog/ifas-fined-nearly-1m-in-2010/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 06:37:59 +0000</pubDate>
		<dc:creator>Speechless</dc:creator>
				<category><![CDATA[Mumbles]]></category>
		<category><![CDATA[approved persons]]></category>
		<category><![CDATA[broker]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[consultancy]]></category>
		<category><![CDATA[costs]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[enforcement action]]></category>
		<category><![CDATA[Financial Services and Markets Tribunal]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[fsa]]></category>
		<category><![CDATA[IFAs]]></category>
		<category><![CDATA[professionalism]]></category>
		<category><![CDATA[remedial action]]></category>
		<category><![CDATA[s166]]></category>
		<category><![CDATA[systems & controls]]></category>
		<category><![CDATA[TCF]]></category>

		<guid isPermaLink="false">http://cei-compliance-limited.co.uk/blog/?p=252</guid>
		<description><![CDATA[Another ArticleThat is over 3 times last year! Figures released by Wolters Kluwer Financial Services under the Freedom of Information Act found that the FSA has already issued fines worth £941,500 directed at IFAs, during the first half of 2010, which is a significant increase from the £236,676 that IFAs coughed up to the City regulator in [...]]]></description>
			<content:encoded><![CDATA[<div class="bblitz_prefix">Another Article</div><p>That is over 3 times last year! Figures released by Wolters Kluwer Financial Services under the Freedom of Information Act found that the FSA has already issued fines worth £941,500 directed at IFAs, during the first half of 2010, which is a significant increase from the £236,676 that IFAs coughed up to the City regulator in 2009.</p>
<p>Last year, IFA fines amounted to just 0.7 per cent of the total penalties. But this has now spiked to 1.5 per cent of total issued in 2010 so far.</p>
<p>Mary Stevens, regulatory editorial UK manger from Wolters Kluwer Financial Services, said: &#8220;Even though we are only part way through 2010 the fines percentage is well over double last years’ final total reflecting the FSA&#8217;s increased pressure on IFAs as it gears up for the retail distribution review implementation.&#8221;</p>
<p>Lee Werrell, CEO of CEI Compliance Consultancy said &#8220;The FSA fines are not always a measure of findings as many investigations take a long time to materialise or fizzle out. There is no doubt that S166 activity is increasing, and that is derived from many reasons. Many distributors still stick their head in the sand and pretend that it won&#8217;t happen to them but they need to be aware that S166 actions can cost them well into 6 figures for a modest organisation of only a few advisers. Prevention is always cheaper than cure.&#8221;</p>
<p>CEI have recently produced a Guide for Senior Managers on S166 Reports and this can be downloaded free from <a title="S166 Reports Guidance" href="http://www.cei-compliance-limited.co.uk/s166_download.html" target="_blank">HERE</a>.</p>
<div class="bblitz_prefix"><a href="http://cei-compliance-limited.co.uk/blog">Join Our Blog </a></div>]]></content:encoded>
			<wfw:commentRss>http://cei-compliance-limited.co.uk/blog/ifas-fined-nearly-1m-in-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FSA Reveal IFA Email Addresses</title>
		<link>http://cei-compliance-limited.co.uk/blog/fsa-reveal-ifa-email-addresses/</link>
		<comments>http://cei-compliance-limited.co.uk/blog/fsa-reveal-ifa-email-addresses/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 08:18:47 +0000</pubDate>
		<dc:creator>Speechless</dc:creator>
				<category><![CDATA[Mumbles]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[fsa]]></category>
		<category><![CDATA[IFAs]]></category>
		<category><![CDATA[procedures]]></category>

		<guid isPermaLink="false">http://cei-compliance-limited.co.uk/blog/?p=144</guid>
		<description><![CDATA[Another Article The FSA has failed to protect the email addresses of hundreds of IFAs and apologised for the failing which were revealed in a mass email.  Earlier this month, keen to sound out the possible effects of the RDR proposals on their business, the FSA emailed an online questionnaire to firms requesting information. The [...]]]></description>
			<content:encoded><![CDATA[<div class="bblitz_prefix">Another Article</div><div>
<p>The FSA has failed to protect the email addresses of hundreds of IFAs and apologised for the failing which were revealed in a mass email. </p>
<p>Earlier this month, keen to sound out the possible effects of the RDR proposals on their business, the FSA emailed an online questionnaire to firms requesting information. The regulator made the addresses of advisers receiving a carbon copy plainly visible in the email.</p>
<p>This is hardly on a par with losing thousands of private individuals&#8217; personal financial details on a USB drive or laptop, but no doubt the FSA knockers will have their two pennyworth. IFA email addresses are available on the FSA register and undoubtedly on the websites for those that have them, not to mention the online business directories.</p>
<p>CEI&#8217;s View: Yes it was an error as the survey was presumably confidential and suitably random for statistical purposes: yes it could negate the results if someone were to influence any or all of the IFAs regarding their RDR views, however we seriously doubt any IFAs have that much influence over others. The FSA will undoubtedly review their procedures and smack someone&#8217;s wrists, but the front page can carry on rolling off the press. Its not a show stopper.</p>
</div>
<div class="bblitz_prefix"><a href="http://cei-compliance-limited.co.uk/blog">Join Our Blog </a></div>]]></content:encoded>
			<wfw:commentRss>http://cei-compliance-limited.co.uk/blog/fsa-reveal-ifa-email-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Model Compliance Consultancy in the UK</title>
		<link>http://cei-compliance-limited.co.uk/blog/new-model-compliance-consultancy-in-the-uk/</link>
		<comments>http://cei-compliance-limited.co.uk/blog/new-model-compliance-consultancy-in-the-uk/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 19:04:07 +0000</pubDate>
		<dc:creator>Speechless</dc:creator>
				<category><![CDATA[Mumbles]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[broker]]></category>
		<category><![CDATA[building society]]></category>
		<category><![CDATA[consultancy]]></category>
		<category><![CDATA[costs]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[fees]]></category>
		<category><![CDATA[fsa]]></category>
		<category><![CDATA[professionalism]]></category>

		<guid isPermaLink="false">http://cei-compliance-limited.co.uk/blog/?p=101</guid>
		<description><![CDATA[Another ArticleWith a bitter taste in my mouth I had suddenly come to realise that the consultancy work I was providing for agencies and consultancies, was being charged out for vastly inflated amounts: sometimes up to 200% over and above the rate I was being paid. My initial thoughts are unprintable and I can see that [...]]]></description>
			<content:encoded><![CDATA[<div class="bblitz_prefix">Another Article</div><p>With a bitter taste in my mouth I had suddenly come to realise that the consultancy work I was providing for agencies and consultancies, was being charged out for vastly inflated amounts: sometimes up to 200% over and above the rate I was being paid.</p>
<p>My initial thoughts are unprintable and I can see that for very short term jobs, then a premium may have to be charged to cover the initial sales involvement, the administration and the QA function if only using a small number of consultants.</p>
<p>On looking into the figures, realising that a consultant’s daily rate has been driven down by about a third over the last year, I have resolved to champion a better rate for consultants and providing an excellent service for the client at a realistic price.</p>
<p>I have calculated that, compared to some consultancies (not including the big 4) then costs can be cut by about 30% and thus giving an edge to my projects, whilst still using the same consultants who would do the same job for the same clients. The difference is that the consultants would earn a fair daily rate, the client would be paying a better rate and therefore look favourably for further work or alternatively get a longer contract agreement and everyone is happy.</p>
<p>If you want to join me in this development period, which is rapidly taking hold, please contact me by sending your CV and contact details to me at <a href="mailto:md@cei-compliance-limited.co.uk">md@cei-compliance-limited.co.uk</a></p>
<p>If you are a budget holder and looking to engage a consultancy for your company please contact me at the same email address, <a href="mailto:md@cei-compliance-limited.co.uk">md@cei-compliance-limited.co.uk</a> , with your requirements.</p>
<div class="bblitz_prefix"><a href="http://cei-compliance-limited.co.uk/blog">Join Our Blog </a></div>]]></content:encoded>
			<wfw:commentRss>http://cei-compliance-limited.co.uk/blog/new-model-compliance-consultancy-in-the-uk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCIDSS Security Requirements</title>
		<link>http://cei-compliance-limited.co.uk/blog/pcidss-security-requirements/</link>
		<comments>http://cei-compliance-limited.co.uk/blog/pcidss-security-requirements/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 18:50:28 +0000</pubDate>
		<dc:creator>Speechless</dc:creator>
				<category><![CDATA[Mumbles]]></category>
		<category><![CDATA[costs]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[PCIDSS]]></category>

		<guid isPermaLink="false">http://cei-compliance-limited.co.uk/blog/?p=93</guid>
		<description><![CDATA[Another ArticleThe standards covered by the PCI Council can be used to help build or augment the security policies and structure for the enterprise, data centres and your customers. This comprehensive set of requirements for security management, policies, procedures, network architecture, software design and other critical protective measures will be used by the wise as [...]]]></description>
			<content:encoded><![CDATA[<div class="bblitz_prefix">Another Article</div><p>The standards covered by the PCI Council can be used to help build or augment the security policies and structure for the enterprise, data centres and your customers. This comprehensive set of requirements for security management, policies, procedures, network architecture, software design and other critical protective measures will be used by the wise as a best practices guide to implement and follow.</p>
<p>Although the PCI Council manages the underlying security standards, compliance is set independently by the individual brands. Each brand has its own set of financial penalties per incident, with additional penalties ranging from restrictions to outright loss of use.</p>
<p>A common misconception is that this is an IT issue and best left solely to the technical departments to resolve. In fact, most companies find that this is a multi-discipline exercise best co-ordinated by a risk and compliance function who can then co-ordinate any IT requirements and engagement; governance for policy writing or amendment; operations for current practices and training; HR for new hires security checks; as well as providing feedback to the audit function for reporting to senior management.</p>
<p>In the latest release of PCI DSS is the requirement that all Web-facing applications be protected against known attacks. Also, further consideration is paid to the vulnerability of the application if someone does get access: How much damage can they do? Historically hosting companies over the years have become very good at protecting the networks and the operating systems from attacks, while the applications themselves have been left vulnerable.</p>
<div class="bblitz_prefix"><a href="http://cei-compliance-limited.co.uk/blog">Join Our Blog </a></div>]]></content:encoded>
			<wfw:commentRss>http://cei-compliance-limited.co.uk/blog/pcidss-security-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FSA Fine HSBC firms £3m</title>
		<link>http://cei-compliance-limited.co.uk/blog/fsa-fine-hsbc-firms-3m/</link>
		<comments>http://cei-compliance-limited.co.uk/blog/fsa-fine-hsbc-firms-3m/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 11:20:32 +0000</pubDate>
		<dc:creator>Speechless</dc:creator>
				<category><![CDATA[Mumbles]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[fsa]]></category>
		<category><![CDATA[HSBC]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[SYSC]]></category>
		<category><![CDATA[systems & controls]]></category>

		<guid isPermaLink="false">http://cei-compliance-limited.co.uk/blog/?p=69</guid>
		<description><![CDATA[Another ArticleAdvertising Three arms of HSBC have been fined over £3m for control failures which potentially left customers&#8217; confidential details open to being lost or stolen. The Financial Services Authority (FSA) has fined HSBC Life UK £1,610,000, HSBC Actuaries and Consultants £875,000 and HSBC Insurance Brokers £700,000 for not having adequate systems and controls in [...]]]></description>
			<content:encoded><![CDATA[<div class="bblitz_prefix">Another Article</div><p style="margin-top: -18px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-family: inherit; color: #453f3b; text-indent: -9999px; line-height: normal; padding: 0px; border: 0px initial initial;"><span style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-family: inherit; margin: 0px; border: 0px initial initial;">Advertising</span></p>
<h3>Three arms of HSBC have been fined over £3m for control failures which potentially left customers&#8217; confidential details open to being lost or stolen.</h3>
<p style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-family: inherit; padding-top: 0px; padding-right: 0px; padding-bottom: 8px; padding-left: 0px; color: #453f3b; line-height: 1.2em; margin: 0px; border: 0px initial initial;">The Financial Services Authority (FSA) has fined HSBC Life UK £1,610,000, HSBC Actuaries and Consultants £875,000 and HSBC Insurance Brokers £700,000 for not having adequate systems and controls in place.</p>
<p style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-family: inherit; padding-top: 0px; padding-right: 0px; padding-bottom: 8px; padding-left: 0px; color: #453f3b; line-height: 1.2em; margin: 0px; border: 0px initial initial;">The fines follow an investigation by the regulator which found that large amounts of unencrypted customer details had been sent via post or courier to third parties.</p>
<p style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-family: inherit; padding-top: 0px; padding-right: 0px; padding-bottom: 8px; padding-left: 0px; color: #453f3b; line-height: 1.2em; margin: 0px; border: 0px initial initial;">Confidential information about customers was also left on open shelves or in unlocked cabinets and could have been lost or stolen.</p>
<p style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-family: inherit; padding-top: 0px; padding-right: 0px; padding-bottom: 8px; padding-left: 0px; color: #453f3b; line-height: 1.2em; margin: 0px; border: 0px initial initial;">In addition, staff were not given sufficient training on how to identify and manage risks like identity theft, the FSA said.</p>
<div class="bblitz_prefix"><a href="http://cei-compliance-limited.co.uk/blog">Join Our Blog </a></div>]]></content:encoded>
			<wfw:commentRss>http://cei-compliance-limited.co.uk/blog/fsa-fine-hsbc-firms-3m/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

