Widespread reports that the CEO of BeIN sports, Yousef Al-Obaidly, predicts that the sports rights bubble is about to burst directly as a result of piracy are significant. He is reported as saying that all sports rights are effectively wholly non-exclusive. Perhaps, but Mayweather v McGregor still generated massive PPV revenues.
But he has a point and this market shift probably occurred in about 2015 and possibly partly explains why the ever shrewd Rupert Murdoch sold Sky and why the recent float of the sports and media giant Endeavour was pulled at the last minute.
That said, from what we see, the audience for live sports is alive and kicking, it has just moved outside of the exclusive control of the traditional broadcasters. This is particularly the case when events are behind highly-priced subscription or PPV walls. The Mayweather v McGregor fight would have done even bigger numbers if piracy was not a factor. Once high-speed internet /mobile emerged this loss of control was inevitable.
The new reality is that piracy can be managed effectively - not eliminated - and that new distribution models with a global focus will emerge. The best guess is that sports rights will become less valuable to traditional broadcasters but as regulations such as Article 13 start to bite the new online platforms will step up and bid to keep their audiences engaged. Whether the revenues can match up remains to be seen as the exclusive satellite/cable distribution model was a great mechanism for extracting the maximum cash from consumers. A counter-argument would be that as traditional broadcasters fight for survival they will pay whatever it takes to keep premium rights. Imagine Sky without sport?
This all points in the medium term towards a free to air, sponsorship and ad-supported model as well as low-cost subscription models. Netflix is walking this path in the movie space as are DAZN in sport. In this quite dramatic shift, there are bound to be winners and losers with content and the customer as king.
Thursday, 10 October 2019
Friday, 18 January 2019
Netflix burns $3 billion of cash in 2018
The Netflix story itself should be made into a movie and released on......Netflix. The evolution from physical video distributor to video streamer (blockbuster in the home - remember them ?) and now content creator is amazing and the Netflix team have achieved what many thought was impossible.
It was always likely to be the case that vertical integration was unavoidable as online distribution of itself becomes of marginal value. Amazon, Disney etc have the capability to stream worldwide and in the case of Amazon a very powerful online marketing and monetisation platform.
Netflix however have decided to go for it big time and are gambling that as their competitors withdraw content from the Netflix platform they can compete and win with alternative original content such as BirdBox.
This represents quite a profound change to the Netflix consumer model which offered a very broad range of strong content at a super competitive price. They did not go for the Blockbusters - quite wisely in my view - as piracy has dented the ability of the blockbusters to drive online value.
This set of links on Reddit makes the point
Now - with original production of their own - Netflix will need to protect their exclusivity to achieve a return on investment from original production - or the cash burn may prove impossible to put out.
On the other hand if they can crack the production and worldwide distribution of streamed video content at an attractive and viable price point the hall of fame awaits.
https://www.cnbc.com/2019/01/17/netflix-says-its-cash-burn-will-peak-this-year-then-go-down.html
It was always likely to be the case that vertical integration was unavoidable as online distribution of itself becomes of marginal value. Amazon, Disney etc have the capability to stream worldwide and in the case of Amazon a very powerful online marketing and monetisation platform.
Netflix however have decided to go for it big time and are gambling that as their competitors withdraw content from the Netflix platform they can compete and win with alternative original content such as BirdBox.
This represents quite a profound change to the Netflix consumer model which offered a very broad range of strong content at a super competitive price. They did not go for the Blockbusters - quite wisely in my view - as piracy has dented the ability of the blockbusters to drive online value.
This set of links on Reddit makes the point
Now - with original production of their own - Netflix will need to protect their exclusivity to achieve a return on investment from original production - or the cash burn may prove impossible to put out.
On the other hand if they can crack the production and worldwide distribution of streamed video content at an attractive and viable price point the hall of fame awaits.
https://www.cnbc.com/2019/01/17/netflix-says-its-cash-burn-will-peak-this-year-then-go-down.html
Tuesday, 15 January 2019
Sports rights owners spoilt for choice as streaming platforms multiply
Rights owners can choose multiple routes to market for live content but the old geographically based distinctions are an illusion in the streaming space. VPN's and pirate activity make distribution global in reality whatever the rights contracts might say. For most sports once the 4 or 5 core markets are covered ROW is just bunce.
Opening up a new market from a technical perspective for a streaming provider is just a matter of adjusting the IP address range in the data base and ensuring that the CDN provider has a point of presence in country. The marketing is a different matter but Google and Facebook have the global footprint.
Distribution options for live video include YouTube, FaceBook, HotStar, DAZN, 11 Sports, ESPN Plus, B/R Live, ROKU, Hulu and many others.
The impact of this on the economic models is yet to be fully understood. YouTube will be tough to beat in my view but at this point before the online subscription model for live sport is proven, it is anybody's guess.
Opening up a new market from a technical perspective for a streaming provider is just a matter of adjusting the IP address range in the data base and ensuring that the CDN provider has a point of presence in country. The marketing is a different matter but Google and Facebook have the global footprint.
Distribution options for live video include YouTube, FaceBook, HotStar, DAZN, 11 Sports, ESPN Plus, B/R Live, ROKU, Hulu and many others.
The impact of this on the economic models is yet to be fully understood. YouTube will be tough to beat in my view but at this point before the online subscription model for live sport is proven, it is anybody's guess.
Tuesday, 6 November 2018
Sports rights valuations on OTT video platforms. The internet may be a much less profitable platform than TV for sports rights owners and holders.
An established and well supported article of faith in the sports tv industry is the ability of exclusive live rights to major sports events to drive paying subscribers to major distribution platforms. Conditional access systems in general did a solid job of protecting live rights from major leakage on satellite and cable platforms. Various models existed to create initial rights valuation ranging from detailed discounted cash flow analysis to the less structured pay more than the other guy and sort it out later approach. Companies like BskyB have been very successful driving value from sports rights on TV.
As a working assumption it has been accepted that exclusive live content that drives subscription and PPV on satellite and cable will work equally well on internet delivered platforms and common sense would seems to support that view - why should a consumer care about the technology of delivery ? Therefore the types of sports rights valuation applicable in the "TV" industry apply equally well online.
New data collected by Klipcorp suggests that this assumption may be wrong and if so this has some potential implications which are worth looking at. A hint of this was also provided in the last FA Premier League rights auction where the social media companies did not really "step up".
1. Our stand out piece of data from a 3 year rolling project suggests that the purchase decisions for consumers buying sports content online are very different in the online to the TV environment and very influenced by the perception that the material is available online free in good quality via unlicensed sites. This mainly applies to OTT services delivered to PC's, Tablets, Phones but not to OTT walled garden services where discovery of unlicensed content is harder. In the case of highlights the consistent availability of good quality delayed highlights on YouTube (see below) and elsewhere re-inforces this perception further. "Claiming" the content published on YouTube without license generates some income but erodes the perception of exclusivity.
2. It also seems to be the case that price points online for sports are lower by significant orders of magnitude than TV. Customers are also not automatically taking up "free trials" - when they realise a payment method also needs to be provided. A free pirate feed trumps a free trial on a legitimate site for a significant number of consumers.
3. Overall levels of interest and engagement remain very solid and in parts of the developing world interaction levels for video delivered via mobile devices are "off the charts". Monetisation of that interest is a challenge.
The music business, as it frequently does, offers a pretty good potential analogy. Vinyl records were a better tool for making money from the consumer that digital downloads - at least so far. But the music industry has adapted and new types of winners and losers have emerged.
Tentative conclusions are that sports rights drive a fraction of the value from consumers online than they drive on TV platforms - but the consumers are heading online fast in the search for value.
Netflix market penetration was initially built on range of choice, convenience and price rather than exclusivity, which was patently not in place, and works well for movies and drama - who could not watch Under Seige for the fifth time ? Whether the Netflix model works well in sport is yet to be seen and NetFlix has mainly created value through its share price gains as opposed to bottom line profits.
YouTube is the sleeping giant in this area and has the ability to create successful Sports pay-per-view events online from a couple of Vloggers and out audience "major" sports rights - see CSI v Logan Paul. Yet despite seeing all the data YouTube do not seem to want to aggressively acquire rights.
Predictions regarding the fall in the value of sports rights have almost always been wrong in the past. As more and more OTT platforms emerge the "pay more than the other guy" approach may well continue to keep values up.
As a helicopter view of the issue when exclusive sports rights were bought pre 2008 they were exclusive in reality. Now rights are exclusively licensed but are in fact non exclusive which has inevitable consequences.
Some conclusions;
1. YouTube has the ability to dominate the market either through content creation, unlicensed material or rights licensing if it decides to. It is already multiplatform, multi device worldwide and the worlds second biggest search engine.
2. Only very well funded OTT sports operators will survive what looks to be a very long battle to secure paying subscribers online.
3. Advertising and Sponsorship driven models which fully engage with all social media platforms are likely to be the online success stories and quite possibly non "official" events.
4. Rights holders will need to balance short term cash from ageing TV platforms against ensuring long term viability with the younger demographic.
As a working assumption it has been accepted that exclusive live content that drives subscription and PPV on satellite and cable will work equally well on internet delivered platforms and common sense would seems to support that view - why should a consumer care about the technology of delivery ? Therefore the types of sports rights valuation applicable in the "TV" industry apply equally well online.
New data collected by Klipcorp suggests that this assumption may be wrong and if so this has some potential implications which are worth looking at. A hint of this was also provided in the last FA Premier League rights auction where the social media companies did not really "step up".
1. Our stand out piece of data from a 3 year rolling project suggests that the purchase decisions for consumers buying sports content online are very different in the online to the TV environment and very influenced by the perception that the material is available online free in good quality via unlicensed sites. This mainly applies to OTT services delivered to PC's, Tablets, Phones but not to OTT walled garden services where discovery of unlicensed content is harder. In the case of highlights the consistent availability of good quality delayed highlights on YouTube (see below) and elsewhere re-inforces this perception further. "Claiming" the content published on YouTube without license generates some income but erodes the perception of exclusivity.
2. It also seems to be the case that price points online for sports are lower by significant orders of magnitude than TV. Customers are also not automatically taking up "free trials" - when they realise a payment method also needs to be provided. A free pirate feed trumps a free trial on a legitimate site for a significant number of consumers.
3. Overall levels of interest and engagement remain very solid and in parts of the developing world interaction levels for video delivered via mobile devices are "off the charts". Monetisation of that interest is a challenge.
The music business, as it frequently does, offers a pretty good potential analogy. Vinyl records were a better tool for making money from the consumer that digital downloads - at least so far. But the music industry has adapted and new types of winners and losers have emerged.
Tentative conclusions are that sports rights drive a fraction of the value from consumers online than they drive on TV platforms - but the consumers are heading online fast in the search for value.
Netflix market penetration was initially built on range of choice, convenience and price rather than exclusivity, which was patently not in place, and works well for movies and drama - who could not watch Under Seige for the fifth time ? Whether the Netflix model works well in sport is yet to be seen and NetFlix has mainly created value through its share price gains as opposed to bottom line profits.
YouTube is the sleeping giant in this area and has the ability to create successful Sports pay-per-view events online from a couple of Vloggers and out audience "major" sports rights - see CSI v Logan Paul. Yet despite seeing all the data YouTube do not seem to want to aggressively acquire rights.
Predictions regarding the fall in the value of sports rights have almost always been wrong in the past. As more and more OTT platforms emerge the "pay more than the other guy" approach may well continue to keep values up.
As a helicopter view of the issue when exclusive sports rights were bought pre 2008 they were exclusive in reality. Now rights are exclusively licensed but are in fact non exclusive which has inevitable consequences.
Some conclusions;
1. YouTube has the ability to dominate the market either through content creation, unlicensed material or rights licensing if it decides to. It is already multiplatform, multi device worldwide and the worlds second biggest search engine.
2. Only very well funded OTT sports operators will survive what looks to be a very long battle to secure paying subscribers online.
3. Advertising and Sponsorship driven models which fully engage with all social media platforms are likely to be the online success stories and quite possibly non "official" events.
4. Rights holders will need to balance short term cash from ageing TV platforms against ensuring long term viability with the younger demographic.
Monday, 8 October 2018
Regional piracy data for UFC 229 - US with 45% of pirate viewing.
With PPV buys expected to hit over 3 million UFC 229 was bound to attract high levels of unauthorised streaming and viewing hand in hand with high levels of legitimate viewing.
Klipcorp systems analysed the regionality of the pirate viewing and we thought it would be useful to share the results.
Our systems saw pirate viewing in 65 countries worldwide but with 4 markets accounting for 67% of the activity.
The US market was by far the largest with 45% of the pirate viewing, followed by the UK with 9%, Canada with 7% and Australia with 6% of the pirate viewing.
A couple of examples of pirate activity are below.
Klipcorp systems analysed the regionality of the pirate viewing and we thought it would be useful to share the results.
Our systems saw pirate viewing in 65 countries worldwide but with 4 markets accounting for 67% of the activity.
The US market was by far the largest with 45% of the pirate viewing, followed by the UK with 9%, Canada with 7% and Australia with 6% of the pirate viewing.
A couple of examples of pirate activity are below.
The high concentration of pirate viewing in the US market for UFC 229 (as other content will deliver different results) is probably due to a combination of high levels of US promotion and the price point.
Sunday, 26 August 2018
KSI v Logan Paul marks fundamental shift
Last nights wildly popular amateur boxing event live on YouTube PPV proves a number of things;
1. The immense power of video enabled social media platforms. With respect to the competitors they are not at the pinnacle boxing - and yet the audience size dwarfed many (if not all ) genuine title fights online. The platform outscores the content - and the power of satellite and cable is now dwindling with the younger demographic. It has been on the cards for a while but now proven.
2. Live PPV can work on the internet at scale. The streams on my TV via the Amazon Fire TV stick were solid and while the production was a little kooky it maybe added to the charm - the presenters and commentary team were perfect IMO.
3. To those of us elbow deep in the digital space the graphic below showing YouTube being ripped off by the pirates on the Twitch platform (our monitoring showed it was everywhere else too) may bring a wry smile. Content protection and discovery is a big challenge. Individual streams at 400k and above.
1. The immense power of video enabled social media platforms. With respect to the competitors they are not at the pinnacle boxing - and yet the audience size dwarfed many (if not all ) genuine title fights online. The platform outscores the content - and the power of satellite and cable is now dwindling with the younger demographic. It has been on the cards for a while but now proven.
2. Live PPV can work on the internet at scale. The streams on my TV via the Amazon Fire TV stick were solid and while the production was a little kooky it maybe added to the charm - the presenters and commentary team were perfect IMO.
3. To those of us elbow deep in the digital space the graphic below showing YouTube being ripped off by the pirates on the Twitch platform (our monitoring showed it was everywhere else too) may bring a wry smile. Content protection and discovery is a big challenge. Individual streams at 400k and above.
Wednesday, 16 May 2018
Tuesday, 17 April 2018
Relieve the stress on GDPR
For those in the SME community hearing the bloodcurdling warnings re the new Data Protection regulations (4% turnover etc etc) help is at hand from Klipcorp IP.
Take our free online assessment (@30 questions) CLICK HERE and we will provide a free consultation on the phone to assess your risk levels and recommend simple and cost effective steps to reduce risk levels if they exist. For most companies compliance is not a major hurdle.
There are quite a few simple steps you can take to reduce the risk profile such as collecting and storing as little personal data as possible so don't be a soft target for the ICO.
Take our free online assessment (@30 questions) CLICK HERE and we will provide a free consultation on the phone to assess your risk levels and recommend simple and cost effective steps to reduce risk levels if they exist. For most companies compliance is not a major hurdle.
There are quite a few simple steps you can take to reduce the risk profile such as collecting and storing as little personal data as possible so don't be a soft target for the ICO.
Thursday, 15 March 2018
Find official worldwide broadcasters for The Masters 2018 with one click at SportsBox
To help the viewer get to the right place in an increasingly fragmented digital media landscape Klipcorp IP have developed the SportsBox platform.
.
.
Thursday, 6 July 2017
Monday, 26 June 2017
Connect to your official Wimbledon 2017 licensed broadcaster using SportsBox
Klipcorp IP are pleased to offer SportsBox technology which allows viewers with one click to connect with the licensed broadcaster in their local market.
By CLICKING HERE our super clever technology will send you to the correct broadcaster in your local market.
We are first using this tech for Wimbledon 2017 - any feedback welcome.
For for information please visit www.sportsbox.tv
By CLICKING HERE our super clever technology will send you to the correct broadcaster in your local market.
We are first using this tech for Wimbledon 2017 - any feedback welcome.
For for information please visit www.sportsbox.tv
Tuesday, 11 April 2017
Streaming server blocking Part 2
Just to update on the FAPL blocking order impact in March 2017 vs key pirate sites it looks like either the process has not really started yet or there is a technical issue.
See a 3 minute overview here
See a 3 minute overview here
Tuesday, 4 April 2017
Directors liability for cyber and data breach
Barely a day passes when there is
no fresh news of another data breach. In the digital age information is like
money and therefore worth stealing. It now matters when information that is
valuable is handled without due care as it can be spread around the world to
large numbers of people with ease.
We are at the start of
understanding the extent of the financial liabilities in this area as cases
such as the massive Yahoo breach work its way through the system. To get a
sense of the scale of possible liabilities see the Yahoo class action suit here
The cynics might argue that the
response of business Directors and Boards to the cyber threat falls into three
main buckets;
1. Do
nothing and blame the IT people if there is a data breach (most common).
2. Do
something (get it minuted) and blame the IT people if there is a data breach.
3. The
experienced IT people persuade the Directors / Board to invest in a smart bit
of kit that generates amazing graphics, goes ping a lot and then blames the
vendor of the kit that looks good and goes ping if it goes wrong. Job done and
blame shifted nicely.
The scope of this post is to
identify the potential legal pressure points that put liability directly onto
the Directors and Board of Company for cyber breach and therefore progress the
nature of the debate in this area.
Directors have always owed legal
duties to companies of which they are Directors. The Companies Act 2006
codified these into seven separate duties.
Two of the duties are
particularly relevant;
Section 172 – duty to promote the
success of the company.
Section 174 – duty to exercise
reasonable care, skill and diligence.
Under 174 in particular the high
profile nature of cyber risk is likely to make it necessary, to meet the test
of reasonableness, that proper care is taken to protect information.
Beyond the fairly general duties
of the Companies Act we also have the Data Protection Act which is soon to
become the GDPR. The Data Protection Act (and its 8 core principles) is the key
legislative framework in the cyber area and with the new GDPR coming into force
next year the maximum fines are rocketing from a maximum of £500k to 4% of
turnover.
Section 61 of the DPA makes it
clear that when an offence under the DPA has been committed and it can be
attributable to the neglect of a Director then “he as well as the body
corporate shall be guilty of that offence”.
Potentially therefore could
Directors be liable for up to 4% of the turnover of the companies they work for
under the GDPR?
The ICO seems keen to ensure that
data protection and its sub-set of cyber security become a mainstream board
issue and therefore when the next TalkTalk happens it may well not be enough to
point the finger at the IT people, say you can barely switch on a computer and
rapidly exit stage left.
Directors of companies which
process sensitive personal data (which includes CCTV) are going to need to take
a much more robust approach to personal data management and cyber risk under
the new GDPR regime to avoid finding themselves exposed personally.
Some simple steps to reduce
liability for Directors could include;
1. Have
a data protection officer who understands the risks and regulatory framework.
2. Have
a simple written data protection and cyber policy regularly communicated and
updated.
3. Insist
on an independent digital audit to check for glaring weaknesses and
vulnerabilities across all 8 principles of the DPA – not just security.
4. Ensure
extra care is taken with any sensitive personal data.
5. Independently
audit your data supply chain / hosting providers.
6. Don’t
collect data you don’t need. You may be building a bigger liability than asset.
Monday, 20 March 2017
FAPL streaming server blocking order impact on live piracy levels - review 1
To follow up in respect of the new blocking order obtained by the FA Premier League which came into force on the 18th March Klipcorp IP ran our systems over the 3.00pm kick off FAPL games on the 18th to monitor impact.
Klipcorp looked at the main high audience pirate sites and the conclusion must be that either the enforcement of the order has not started (perhaps not enough time to give notice to the hosting providers) or there is a material technical issue at this point.
All the core sites were offering uninterrupted coverage of the full game and a sequence of screen grabs can be seen here.
We will run our systems again over the next few weeks to determine if any changes have taken place.
The order runs to the end of this FAPL season (22nd May) so a couple of months to judge impact.
Klipcorp looked at the main high audience pirate sites and the conclusion must be that either the enforcement of the order has not started (perhaps not enough time to give notice to the hosting providers) or there is a material technical issue at this point.
All the core sites were offering uninterrupted coverage of the full game and a sequence of screen grabs can be seen here.
We will run our systems again over the next few weeks to determine if any changes have taken place.
The order runs to the end of this FAPL season (22nd May) so a couple of months to judge impact.
Tuesday, 14 March 2017
FA Premier League takes extra step to fight piracy - admission that DMCA is not working
Very interesting order from Justice Arnold this week in which, for a period from this Saturday to the end of this FAPL season, will require the main UK ISP's to block certain streaming server IP addresses which stream FAPL content live. The blocking will occur in real time based on information provided by a technical provider to the FAPL to the ISP's.
The FAPL have experimented with blocking orders before but previously they were aimed at websites and despite arguments to the contrary were fairly easily avoided using proxies.
Contained within the judgement were the following comments;
1. The problem of illegal streaming is getting bigger
2. The audiences are large
3. DMCA notices are not effective with non-compliant operators
Of the 3 criteria being used to justify the blocking one was kept confidential to minimise risk of circumvention but the other two are;
1. FAPL and its contractor must reasonably believe that the server has the sole or predominant purpose of enabling or facilitating access to infringing streams of Premier League match footage.
2. FAPL and its contractor must not know or have reason to believe that the server is being used for any other substantial purpose.
Collateral damage is a key issue therefore.
Ian Mill QC instructed by DLA Piper acted for the FAPL.
Klipcorp IP will monitor the effectiveness of this approach this Saturday and report back on initial effectiveness levels.
If this approach works it will be a major step forward in dealing with piracy and hats off to the FAPL for taking the risk of failure here.
Areas likely to provide a technical challenge are;
Deliberate concealing or spoofing of the source video stream IP address leading to blocking of the wrong IP
Rapid automated switching of IP address between different hosts
Unanticipated collateral damage.
More information early next week.
The FAPL have experimented with blocking orders before but previously they were aimed at websites and despite arguments to the contrary were fairly easily avoided using proxies.
Contained within the judgement were the following comments;
1. The problem of illegal streaming is getting bigger
2. The audiences are large
3. DMCA notices are not effective with non-compliant operators
Of the 3 criteria being used to justify the blocking one was kept confidential to minimise risk of circumvention but the other two are;
1. FAPL and its contractor must reasonably believe that the server has the sole or predominant purpose of enabling or facilitating access to infringing streams of Premier League match footage.
2. FAPL and its contractor must not know or have reason to believe that the server is being used for any other substantial purpose.
Collateral damage is a key issue therefore.
Ian Mill QC instructed by DLA Piper acted for the FAPL.
Klipcorp IP will monitor the effectiveness of this approach this Saturday and report back on initial effectiveness levels.
If this approach works it will be a major step forward in dealing with piracy and hats off to the FAPL for taking the risk of failure here.
Areas likely to provide a technical challenge are;
Deliberate concealing or spoofing of the source video stream IP address leading to blocking of the wrong IP
Rapid automated switching of IP address between different hosts
Unanticipated collateral damage.
More information early next week.
Thursday, 19 January 2017
The limits of consent to the use of personal data
When does yes really mean yes ? That is a very broad subject but it becomes very specific in the context of data protection.
The areas of data protection, cyber
security and IP protection in the Digital Age generally are very much in the
news. They are a slightly splintered area of law falling variously under the
Data Protection Act 1998, the Computer Misuse Act 1990, Investigatory Powers
Act 2016, Freedom of Information Act 2000, Human Rights Act 1998 and the Copyrights, Designs and Patents Act
1988 as amended and updated by various WIPO treaties.
A key tension is the balance between an individual’s
right to privacy and protection of their personal data and IP balanced against the often
quoted desire of the state to keep us safe. The rapid growth of the internet,
computing power and increased storage capacity allow for unprecedented data
collection and processing.
Generally hackers make the news and
highlight security shortcomings leading to the Information Commissioners Office
becoming involved. However serious breaches of Data Protection law occur
without a hacker anywhere to be seen through the illegal use of data provided
voluntarily.
In the case of the RSPCA (until
recently taking some very aggressive positions in respect of private
prosecution) they were collecting personal data from donors who were presented
with the following notice;
“The
RSPCA may allow other organisations whose aims are in sympathy with our own or
whose offers will benefit animal welfare to contact our supporters, if you do
not wish to hear from them please tick the box”
It seems that the RSPCA then decided
this was carte blanche to use the data collected very broadly indeed and
participated in a data sharing scheme called “reciprocate” without knowing who
the other parties in the scheme were. They also provided data to wealth
screening companies and participated in data matching and telematching schemes.
On a few occasions they also released data on individuals who had opted out.
This was brought to the attention of
the new Information Commissioner Elizabeth Denham via the press and
unsurprisingly after a 9 month investigation serious breaches of the Data
Protection Act were identified. A monetary penalty was issued of £25,000 but
criminal charges could have been brought.
The Data Protection Act has at its
heart 8 key principles of Data Protection with the first 2 being that personal
data must be processed fairly and lawfully and that, crucially in this case,
shall be obtained for a specified purpose and used consistently with that
purpose. Generally to be lawful consent must have been obtained in respect of
the purpose.
The Commissioners view was that the
initial notice was too vague and ambiguous and did not provide data subjects
with sufficient information. Consent must be freely given, specific and
informed. Just ticking any old box does not do it. Therefore the data subjects had not consented
and therefore the data processing was illegal.
The Data Protection Act covers all
personal data (with certain limited exemptions) which includes names, addresses
and even IP addresses. Generally consent must be sought to process that data so
everybody is going to need to take great care when collecting data to ensure
proper consent has been obtained and also that if the person collecting the
data (the data controller) decides to use the data for another purpose to seek
fresh consent.
The world of big data is going to
struggle a bit with this but perhaps has consoled itself that currently the
maximum fine from the ICO is capped at £500,000. Fatal for an SME probably but
merely a deduction for a large corporate. However new legislation proposes a
fine of 4% of turnover.
Of the 8 principles of Data
Protection only 1 is directly concerned with security of data (principle 7).
Organisations and individuals need to devote resources to ensure the legal
collection and management of personal data as well as making sure appropriate
security is in place to avoid substantial fines and potential criminal
prosecution.
Personal data collected which
requires consent can only be lawfully used in ways which derive directly from
the consent given. It has been said that personal data is like money and if so
when you provide your personal data to a third party it is analogous to a loan
on specific terms for a specific purpose.
Friday, 6 January 2017
2016 - how secure do you feel (about your data) ?
With thanks to Lewis Morgan, blogger in residence at IT Governance, for putting together a list of breaches in 2016 that he was aware of. Notable by it's absence is the alleged hack of the US Elections which was possibly the Russians, or possibly the Democrats or possibly Elvis Presley from beyond the grave.
In any event it certainly shows that the hackers look to have the upper hand at the moment.
2016 Cyber Attacks & Data Breaches
US health insurer Centene loses 950,000 people’s records
Asda website leaves customer details vulnerable for 677 days
Etihad Airways investigating data breach dating back to 2013
Wendy’s Probes Reports of Credit Card Breach
Bitcoin Worth $USD 6 Million Stolen
Hackers have stolen €50 million from an aerospace parts manufacturer
Linux Mint hacked – lone attacker creates botnet
Lincolnshire Council forced to use pen and paper after ransomware attack
@ChileanCrew Hacks, Leaks Details for 300,000 Chilean Citizens Looking for State Benefits
9000+ Department of Homeland Security staff have their details leaked by hacker
3,000 Tidewater Community College workers victimized in W-2 scam
Attacker compromises information of 250K in Bailey’s data breach
Cyber criminals steal $25 million from Russian banks via phishing attack
Rosen Hotel chain was hit by credit card-stealing malware for 17 months
Minecraft community lifeboat suffers data breach affecting seven million members
CoinWallet Bitcoin Trader Shuts Down Following Data Breach
93.4 million Mexicans at risk after voter database breach
BeautifulPeople.com Leaks Very Private Data of 1.1 Million ‘Elite’ Daters — And It’s All For Sale
ShapeShift loses $230,000 in bitcoin data breach – ex-employee to blame
Trump Hotel chain suffers data breach again
MySpace and Tumblr hit by ‘mega breach’
117 million hacked LinkedIn email addresses and passwords put up for sale
Kiddicare customers at risk after data spills from test server
EPISD employee accounts hacked, money stolen
Payroll vendor employee falls for phishing scam, all clients’ W-2 data involved
1.4 Billion Yen Stolen From 1,400 Japanese ATMs
154 million voter records exposed, revealing gun ownership, Facebook profiles, and more
77K accounts of Financial Giant, State Farm, leaked due to DAC Group Hack
Muslim Match dating website hack exposes more than half a million intimate messages
45 million records from over 1100 Verticalscope.com domains and communities hacked and leaked
51 Million iMesh Passwords Dumped Online
Personal info on 7.93 million people feared leaked
King’s counselling department breaches students’ privacy
Athens Orthopedic Clinic to begin notifying patients of hack
WikiLeaks Put Women in Turkey in Danger, for No Reason
10 million customer’s data leaked from online shopping site
‘Warframe’ Hacked, Details on 775,000 Players Traded
Illinois online voter registration portal hacked, information compromised
Omegle, the Popular ‘Chat with Strangers’ Service Leaks Your Dirty Chats and Personal Info
Data for 6 Million Minecraft Gamers Stolen from Leet.cc Servers
SCAN Health Plan notifying members of unauthorized access to their information
Dominican Hospital notifies patients whose PHI was sent to wrong health plan
Epic’s forums hacked again, with thousands of logins stolen
Turkish Hackers Launch Second Cyber-Attack on Killeen’s Website
Defense university computers hacked, ‘information secure’
Olympics: Hackers attack Russian whistleblower’s doping account
Florida Bar Association hacked, members’ data leaked
6.6 million plaintext passwords exposed as site gets hacked to the bone
Russian hackers leak Simone Biles and Serena Williams files
Russian internet giant Rambler.ru hacked, leaking 98 million accounts
Login details for 800,000 Brazzers users leaked
MarsJoke ransomware targets the government and K-12 educational sector
A single ransomware network has pulled in $121 million
Medical marijuana patients’ personal information found in trash pile
Security Firm Tries Desperate Solution to Alert Company of Data Leak
Hacker grabs over 58 million customer records from data storage firm
Hutchinson Community Foundation falls victim to data breach
DDoS attack against DNS provider knocks major sites offline
Whoops: Pro-Donald Trump super PAC publishes donor credit card numbers
Hackers stole credit card data from Republican website for 6 months
Department of National Defence investigating possible hack of its recruiting site
Over 412 million ‘adult’ accounts exposed – including 15 million deleted ones
Ransomware attack targets Seguin dermatology practice
Report holds Hitachi responsible for debit card data theft
Thieves Use Skimmers on ATMs in Four NYC Hospitals
Madison Square Garden Company Alerts Customers of Payment Card Data Breach
Data of 34 million Keralites leaked in massive breach
85 million login details stolen from Dailymotion
Joan Jett’s BlackHeart Records leaks thousands of files online
KFC warns 1.2 million Colonel’s Club loyalty scheme members of data breach after website hacked
Japanese hosting company Kagoya hacked; credit card data stolen
ThyssenKrupp secrets stolen in ‘massive’ cyber attack
Yahoo’s billion account database for sale on the black market
In any event it certainly shows that the hackers look to have the upper hand at the moment.
2016 Cyber Attacks & Data Breaches
US health insurer Centene loses 950,000 people’s records
Asda website leaves customer details vulnerable for 677 days
Etihad Airways investigating data breach dating back to 2013
Wendy’s Probes Reports of Credit Card Breach
Bitcoin Worth $USD 6 Million Stolen
Hackers have stolen €50 million from an aerospace parts manufacturer
Linux Mint hacked – lone attacker creates botnet
Lincolnshire Council forced to use pen and paper after ransomware attack
@ChileanCrew Hacks, Leaks Details for 300,000 Chilean Citizens Looking for State Benefits
9000+ Department of Homeland Security staff have their details leaked by hacker
3,000 Tidewater Community College workers victimized in W-2 scam
Attacker compromises information of 250K in Bailey’s data breach
Cyber criminals steal $25 million from Russian banks via phishing attack
Rosen Hotel chain was hit by credit card-stealing malware for 17 months
Minecraft community lifeboat suffers data breach affecting seven million members
CoinWallet Bitcoin Trader Shuts Down Following Data Breach
93.4 million Mexicans at risk after voter database breach
BeautifulPeople.com Leaks Very Private Data of 1.1 Million ‘Elite’ Daters — And It’s All For Sale
ShapeShift loses $230,000 in bitcoin data breach – ex-employee to blame
Trump Hotel chain suffers data breach again
MySpace and Tumblr hit by ‘mega breach’
117 million hacked LinkedIn email addresses and passwords put up for sale
Kiddicare customers at risk after data spills from test server
EPISD employee accounts hacked, money stolen
Payroll vendor employee falls for phishing scam, all clients’ W-2 data involved
1.4 Billion Yen Stolen From 1,400 Japanese ATMs
154 million voter records exposed, revealing gun ownership, Facebook profiles, and more
77K accounts of Financial Giant, State Farm, leaked due to DAC Group Hack
Muslim Match dating website hack exposes more than half a million intimate messages
45 million records from over 1100 Verticalscope.com domains and communities hacked and leaked
51 Million iMesh Passwords Dumped Online
Personal info on 7.93 million people feared leaked
King’s counselling department breaches students’ privacy
Athens Orthopedic Clinic to begin notifying patients of hack
WikiLeaks Put Women in Turkey in Danger, for No Reason
10 million customer’s data leaked from online shopping site
‘Warframe’ Hacked, Details on 775,000 Players Traded
Illinois online voter registration portal hacked, information compromised
Omegle, the Popular ‘Chat with Strangers’ Service Leaks Your Dirty Chats and Personal Info
Data for 6 Million Minecraft Gamers Stolen from Leet.cc Servers
SCAN Health Plan notifying members of unauthorized access to their information
Dominican Hospital notifies patients whose PHI was sent to wrong health plan
Epic’s forums hacked again, with thousands of logins stolen
Turkish Hackers Launch Second Cyber-Attack on Killeen’s Website
Defense university computers hacked, ‘information secure’
Olympics: Hackers attack Russian whistleblower’s doping account
Florida Bar Association hacked, members’ data leaked
6.6 million plaintext passwords exposed as site gets hacked to the bone
Russian hackers leak Simone Biles and Serena Williams files
Russian internet giant Rambler.ru hacked, leaking 98 million accounts
Login details for 800,000 Brazzers users leaked
MarsJoke ransomware targets the government and K-12 educational sector
A single ransomware network has pulled in $121 million
Medical marijuana patients’ personal information found in trash pile
Security Firm Tries Desperate Solution to Alert Company of Data Leak
Hacker grabs over 58 million customer records from data storage firm
Hutchinson Community Foundation falls victim to data breach
DDoS attack against DNS provider knocks major sites offline
Whoops: Pro-Donald Trump super PAC publishes donor credit card numbers
Hackers stole credit card data from Republican website for 6 months
Department of National Defence investigating possible hack of its recruiting site
Over 412 million ‘adult’ accounts exposed – including 15 million deleted ones
Ransomware attack targets Seguin dermatology practice
Report holds Hitachi responsible for debit card data theft
Thieves Use Skimmers on ATMs in Four NYC Hospitals
Madison Square Garden Company Alerts Customers of Payment Card Data Breach
Data of 34 million Keralites leaked in massive breach
85 million login details stolen from Dailymotion
Joan Jett’s BlackHeart Records leaks thousands of files online
KFC warns 1.2 million Colonel’s Club loyalty scheme members of data breach after website hacked
Japanese hosting company Kagoya hacked; credit card data stolen
ThyssenKrupp secrets stolen in ‘massive’ cyber attack
Yahoo’s billion account database for sale on the black market
Thursday, 8 December 2016
New UK Information Commissioner shows her teeth issuing fines for wealth screening to RSPCA and BHF
What on earth has been going on at the RSPCA ? Assumed to be a quiet backwater for helping out animals in distress it became a vehicle for what looked like politically motivated criminal cases and now has been found to have been breaking the law with very aggressive data profiling or "wealth screening" without consent in order to generate income.
All credit to Elizabeth Denning, the new head of the ICO, for the bravery to take this organisation on as they would not immediately fit into the category of data villain.
One of the areas of breach was the sharing of data in a group with others (unidentified) called "reciprocate". Effectively when agreeing to share data (or not) with the RSPCA they took it as carte blanche to share your personal data with everyone.
Perhaps up to now Data Protection has been seen as a box ticking exercise with many government agencies relying on blanket exemptions and busily building databases.
However as the Alan Lord case showed there are no blanket exemptions and each case must be considered on its merits. The rights of data subjects to request information via a subject access request will need to be taken even more seriously now.
A new attitude at the ICO should send a warning shot across the bows of both government and big business who have been harvesting and processing personal data without getting proper consent and being clear about the purpose.
All credit to Elizabeth Denning, the new head of the ICO, for the bravery to take this organisation on as they would not immediately fit into the category of data villain.
One of the areas of breach was the sharing of data in a group with others (unidentified) called "reciprocate". Effectively when agreeing to share data (or not) with the RSPCA they took it as carte blanche to share your personal data with everyone.
Perhaps up to now Data Protection has been seen as a box ticking exercise with many government agencies relying on blanket exemptions and busily building databases.
However as the Alan Lord case showed there are no blanket exemptions and each case must be considered on its merits. The rights of data subjects to request information via a subject access request will need to be taken even more seriously now.
A new attitude at the ICO should send a warning shot across the bows of both government and big business who have been harvesting and processing personal data without getting proper consent and being clear about the purpose.
Friday, 25 November 2016
Data protection and cyber issues for small and medium sized business
Having been involved in setting up and running a number of small businesses it is very clear that generally there is a relentless focus on sales, cash and new customers (and survival). Regulation and bureaucracy are not your friend as unlike larger businesses there is not the scale to support the army of required admin people ticking boxes with feverish intensity.
Overall the digital age has been a positive for small business allowing lots of admin activity to be simplified and reducing the need for infrastructure. A lot can be done with a mobile phone number, email address and website. Welcome to the gig economy.
However it has become very clear that digital data has a huge value, and personal data even more so. Data is like money. Since it has value some people want to steal it and stealing data is generally called hacking.
Also Governments, ever keen to "guide" or "nudge" the people to the correct conclusions (not going so well with Brexit and Trump) have been spying on the population leading to the game changing revelations from Edward Snowden.
Therefore into the previous wild west of big digital data comes regulation. In the UK the very analog Data Protection Act has been updated piecemeal by the Regulation of Investigatory Powers Act, The Protection of Freedoms Act, Freedom of Information Act soon to be in force GDPR.
Small and Medium Businesses are presented with quite a challenge as a result. For example issues like encryption of sensitive data, explicit consent and right to be forgotten all need to be considered. All these are important issues but for the owner of a small business who has not changed his passwords in 12 month these issues seem esoteric at best.
Unfortunately if small business does ignore this issue they can destroy customer trust if hacked and also suffer on the compliance side as this case from the ICO shows.
Therefore what ?
At klipcorp IP we have developed this simple free risk assessment tool aimed to help small business on this complex journey and would encourage engagement with it.
It is inevitable that business will need to allocate resource into this area (both large and small) and over time those that do not will lose customer trust / business and sometimes suffer at the hands of the regulator.
Overall the digital age has been a positive for small business allowing lots of admin activity to be simplified and reducing the need for infrastructure. A lot can be done with a mobile phone number, email address and website. Welcome to the gig economy.
However it has become very clear that digital data has a huge value, and personal data even more so. Data is like money. Since it has value some people want to steal it and stealing data is generally called hacking.
Also Governments, ever keen to "guide" or "nudge" the people to the correct conclusions (not going so well with Brexit and Trump) have been spying on the population leading to the game changing revelations from Edward Snowden.
Therefore into the previous wild west of big digital data comes regulation. In the UK the very analog Data Protection Act has been updated piecemeal by the Regulation of Investigatory Powers Act, The Protection of Freedoms Act, Freedom of Information Act soon to be in force GDPR.
Small and Medium Businesses are presented with quite a challenge as a result. For example issues like encryption of sensitive data, explicit consent and right to be forgotten all need to be considered. All these are important issues but for the owner of a small business who has not changed his passwords in 12 month these issues seem esoteric at best.
Unfortunately if small business does ignore this issue they can destroy customer trust if hacked and also suffer on the compliance side as this case from the ICO shows.
Therefore what ?
At klipcorp IP we have developed this simple free risk assessment tool aimed to help small business on this complex journey and would encourage engagement with it.
It is inevitable that business will need to allocate resource into this area (both large and small) and over time those that do not will lose customer trust / business and sometimes suffer at the hands of the regulator.
Thursday, 6 October 2016
Yahoo: Directors liability for cyber breach : IP protection in the Digital Age
With only 20 months until the implementation of the GDPR large organisations such as Barclays have already put big teams and resources in place to meet the new requirements. With breach fines up to 4% of turnover and the requirements to maintain a personal data inventory and report breaches within 72 hours this will be a big challenge for the SME and Mid Size community. The requirements of explicit consent for processing sensitive personal data (likely to include video and voice) and a linked right to be forgotten will require significant resource commitment and expertise.
TalkTalk were fined a record £400,000 yesterday by the ICO for a very poor level of cyber security which is close to the maximum under current UK legislation. This is a wake up call for businesses handling personal data in the UK as fines will be much higher under the new regime. Dido Harding may be regretting that she did not obtain an independent view of her cyber safety levels and allowed her IT team to mark their own homework.
The Yahoo hack has made the news but most of the focus has been around its scale in terms of numbers of email addresses. The class action suit available HERE alleges under Count V Negligence. The specific wording is "Defendant owed a duty to Plaintiffs and the other class members to exercise reasonable care in safeguarding and protecting their PI and financial information in its possession from being compromised, lost, stolen, misused, and/or disclosed to unauthorised parties".
Further in the suit it is suggested that that the identity thieves may wait for years to use the information gained and that therefore class members will need to be vigilant for years or decades to come.
The combination of negligence and the potential for decades of required monitoring points to a potentially huge damages number. This could be the end of the road for Yahoo and open the way for personal negligence claims against Directors in this area.
Taken together the regulatory regime in terms of personal data is significantly tightening up and the associated risk level is beginning to become clear.
TalkTalk were fined a record £400,000 yesterday by the ICO for a very poor level of cyber security which is close to the maximum under current UK legislation. This is a wake up call for businesses handling personal data in the UK as fines will be much higher under the new regime. Dido Harding may be regretting that she did not obtain an independent view of her cyber safety levels and allowed her IT team to mark their own homework.
The Yahoo hack has made the news but most of the focus has been around its scale in terms of numbers of email addresses. The class action suit available HERE alleges under Count V Negligence. The specific wording is "Defendant owed a duty to Plaintiffs and the other class members to exercise reasonable care in safeguarding and protecting their PI and financial information in its possession from being compromised, lost, stolen, misused, and/or disclosed to unauthorised parties".
Further in the suit it is suggested that that the identity thieves may wait for years to use the information gained and that therefore class members will need to be vigilant for years or decades to come.
The combination of negligence and the potential for decades of required monitoring points to a potentially huge damages number. This could be the end of the road for Yahoo and open the way for personal negligence claims against Directors in this area.
Taken together the regulatory regime in terms of personal data is significantly tightening up and the associated risk level is beginning to become clear.
Subscribe to:
Posts (Atom)








