Security

8.1 Security Risks

8.1.1 Confidential information held by organisations

Human Resources Information
Human Resources departments hold confidential information such as:
  • Salaries and benefits
  • Staff personal details
Commercially Sensitive Information
Organisations store sensitive commercial information including:
  • Client details
  • Stakeholder details
  • Intellectual property
  • Sales numbers
  • Contracts
Access Information
Access information must be kept secure to prevent unauthorised use:
  • Usernames
  • Passwords
  • Multi‑factor authentication details
  • Personal Identification Numbers (PIN)
  • Access codes and passphrases
  • Biometric data

8.1.2 Why organisations must keep information confidential

Reasons for Confidentiality
Organisations must protect confidential information to:

Salaries and benefits:
  • Prevent competitors from offering higher wages
  • Avoid disputes over comparable pay
Staff details:
  • Protect employee privacy
  • Stop competitors contacting staff directly
Intellectual property:
  • Prevent copying of designs and ideas
Client details:
  • Protect client privacy
  • Stop competitors targeting clients
Sales data:
  • Prevent competitors gaining commercial advantage
Access information:
  • Prevent unauthorised access to systems

8.1.3 Impact of failing to maintain privacy and confidentiality

Impact on Organisations
Failing to protect confidential information can result in:
  • Non‑compliance with regulations:
    • Loss of licence to operate
  • Loss of customer and stakeholder trust
  • Damage to organisational reputation and image
  • Financial loss:
    • Fines and penalties
    • Refunds
    • Loss of earnings or terminated contracts
  • Legal action from individuals or regulators
  • Overall reduction in system security