Shaking head
I read about the HMRC fiasco and wonder what is going on in the UK. I worked for a Government agency down here in OZ, and data transport between us and other Government agencies was done via FTP. Over a dedicated data-line. With a VPN on it. Encrypted. That was the rule - unless it was sent via the dedicated encrypted VPN lines, the data did not move without clearance the the Security section. Want to sent a data file via e-mail? Better get it vetoed first, otherwise the email firewall would bounce it to high heaven and you'd get a message asking you to report to ISS to get screamed at.
Yes, it sometimes made for tedious delays, but considering the data we were handling (*mucho* personal) we considered it an acceptable evil compared to the alternative - with the "open policy" 'round here, anybody leaked the data would have been handed over to the media, bound and gagged.
No, it would not have stopped someone from copying the data onto discs and sending them by mail... but the point of all this is: there was a *secure* alternative in place for data transfer. In OZ, where traveling 100km to work is considered simple commuting. So I still don't get it when the UK's goverment departments, which (comparatively speaking) live in each other's back pockets, still use unsecured methods to send data.
Personally, I think a Minister or two should lose their job over this one - might make the next think about putting decent policies in place.