no surprise, been going on for years
Every business that has outsourced it's IT or has remote call centres has a gaping hole in it's security. None of these companies have complete control over their data - most won't even know where it all is (there could be copies all over the place, unknown to the "owner").
Outsourcing usually goes to the lowest price bidder. That in itself is not compatible with top quality security (security == delays, reviews, processes, permission, authorisation, audits ....). Add to this the outsourcer will employ people predicated on salary, not professionalism.
Question: can you apply UK data security laws if the IT operation is run in another country? Or is that one of it's "benefits"?


