Data security - cloud and outsourcing

We consider the security of your computer systems, and how to minimise the risks of data loss within the cloud and where some or all services are outsourced.

Cloud data storage and outsourcing can often be more secure than using internal resources however there are some additional things to bear in mind. We consider issues which should be taken into account when reviewing the security of your computer systems. At PHM, we can provide guidance on data security in the Northamptonshire area.

Many companies are now completely reliant on the data stored on their network servers, PCs, laptops, mobile devices or in the cloud. Some of this data is likely to contain either personal information and/or confidential company information.

We have a related factsheet that covers the conventional data security considerations.

Here we look at some of the issues to consider when reviewing the security of your computer systems, and how to minimise the risks of data loss, within the cloud and services are outsourced.

Whilst cloud data storage and outsourcing can often be more secure than using internal resources, there are some additional things to bear in mind when some, or all, of your data is not held on-site.

Audit use and storage of personal data

Consider the potentially sensitive and confidential data that is stored in the cloud by your business.

Find out what is happening to that data and which controls are in place to prevent accidental or deliberate loss of this information.

Risk analysis and risk reduction

The key question is - if all or some of this data is lost who could be harmed and how?

Once that question has been answered, steps to mitigate the risks of data loss must be taken. Here are some steps that should be undertaken to reduce the risk of data loss:

  • ensure that the cloud provider or outsourcer will not share your data with a third party
  • check which countries the data will be stored and processed - this could have data protection implications
  • ensure that you can take local backup copies of your data
  • a data subject has the same rights of access wherever data is being stored, so ensure that a subject access request can be facilitated
  • try to minimise the amount of personal data stored in the cloud, or with a third party
  • what happens if the provider becomes insolvent? Have a contingency plan in place
  • is the data encrypted - if so have you got access to the keys and who else has access to the keys?

There are many resources available including:

ico.org.uk/media/for-organisations/documents/1540/cloud_computing_guidance_for_organisations.pdf

How we can help

Please contact us if you require help in the following areas:

  • performing a security/information audit
  • reviewing cloud and outsourcing/third-party agreements
  • training staff in security principles and procedures.

If you are in the Northamptonshire area please do contact us and we would be happy to help with data security issues.

PDF download Download content as a PDF

Come And Meet Us

Initial meetings are free of charge and totally without obligation

Call us

Contact Us

T: 01604 718866
F: 01604 716880
E: info@phm-accountants.co.uk

Social

Home | Privacy | Site map | Contact us | Accessibility | Disclaimer | Help | Diversity Report

© 2020 Phipps Henson McAllister. All rights reserved.

powered by totalSOLUTION

We use cookies on this website, you can find more information about cookies here.

Phipps Henson McAllister are registered to carry on audit work in the UK & Ireland and regulated for a range of investment business activities by the Institute of Chartered Accountants in England & Wales.

Details about our audit registration can be viewed at www.auditregister.org.uk for the UK and www.cro.ie/auditorsfor Ireland, under reference number EWC008449569.

This firm is not authorised under the Financial Services and Markets Act 2000 but we are able in certain circumstances to offer a limited range of investment services to clients because we are members of the Institute of Chartered Accountants in England and Wales. We can provide these investment services if they are an incidental part of the professional services we have been engaged to provide.