Malicious email volume

East West Railway Company Limited did not have the information requested.

Dear East West Railway Company Limited,

Please find below my FOI request regarding malicious emails sent to the department.

The date range for the request is for 2022. The data shall include a breakdown by individual departments (e.g. separate departments, agencies, or public bodies within the main government agency), if applicable. Where data isn't available for the entire year, please provide the data and timescale it relates to (e.g. X emails over the last 90 days).

1. How many malicious emails have been successfully blocked/detected?
2. If possible, please provide a breakdown of figures by malicious email type, e.g. spam, malware, phishing, and ransomware.
3. What percentage of malicious emails were opened by staff?
4. What percentage of malicious links in the emails were clicked on by staff?
5. How many email accounts/employees are there within your department?

Yours faithfully,
Rebecca Moody

East West Rail Contact, East West Railway Company Limited

Thank you for getting in touch with the EWR Co team.

We try to deal with enquiries within ten working days though it may take
longer if we need to ask several colleagues for information. We'll keep
you up to date if that's the case.

Kind regards,
EWR Co Team East West Railway Company Limited is a company registered in
England and Wales. Registered office: One Grafton Mews, Midsummer
Boulevard, Milton Keynes, MK9 1FB. Company registration number: 11072935.

This message is private and confidential. If you have received it in
error, please notify us and remove it from your system. Unauthorised use,
disclosure, copying or distribution is prohibited. Neither East West
Railway Company Limited nor the sender accepts any responsibility for
malware and it is the recipient’s responsibility to check this e-mail and
any attachments accordingly. For more information on how we process
personal data please see our [1]Privacy Policy.

Disclaimer

The information contained in this communication from the sender is
confidential. It is intended solely for use by the recipient and others
authorized to receive it. If you are not the recipient, you are hereby
notified that any disclosure, copying, distribution or taking action in
relation of the contents of this information is strictly prohibited and
may be unlawful.

This email has been scanned for viruses and malware, and may have been
automatically archived by Mimecast Ltd, an innovator in Software as a
Service (SaaS) for business. Providing a safer and more useful place for
your human generated data. Specializing in; Security, archiving and
compliance. To find out more [2]Click Here.

References

Visible links
1. https://eastwestrail.co.uk/privacy-at-ew...
2. http://www.mimecast.com/products/

East West Rail team, East West Railway Company Limited

Dear R Moody,

Thank you for your interest in East West Rail. 

We are in receipt of your email 26 January 2023 and we are treating it as
a Freedom of Information request. 

The Freedom of Information Act oblige us to respond to requests for
information within 20 working days of the day we received your message,
but we aim to respond to all enquiries as quickly as we can.

Please do get in contact if you have any further questions.

Kind regards,

Leon Mitchell
Information Governance Officer 
East West Railway Company 

show quoted sections

East West Rail team, East West Railway Company Limited

Dear R Moody,

Re: Freedom of Information Request / Environmental Information Request

Thank you for your request for information, which was received on 26
January 2023

In that request you asked us for information below:

The date range for the request is for 2022. The data shall include a
breakdown by individual departments (e.g. separate departments, agencies,
or public bodies within the main government agency), if applicable. Where
data isn't available for the entire year, please provide the data and
timescale it relates to (e.g. X emails over the last 90 days).

1. How many malicious emails have been successfully blocked/detected?
2. If possible, please provide a breakdown of figures by malicious email
type, e.g. spam, malware, phishing, and ransomware.
3. What percentage of malicious emails were opened by staff?
4. What percentage of malicious links in the emails were clicked on by
staff?
5. How many email accounts/employees are there within your department?

I can confirm that the search for the information you requested has been
completed and I can advise you of the following:

With regard to the information that you have asked for, we consider this
to be exempt under Section 31(1)(a) of the Freedom of Information Act.

Section 31(1)(a) says that we do not need to provide information that
would be likely to prejudice the functions of law enforcement – the
prevention and detection of crime. We are of the opinion that releasing
this information could make East West Rail Company the target of crime.

Releasing information about malicious emails that were sent to the
organisation could allow criminals using the information to target attacks
against East West Rail systems. For example, if we were to release
information about the number of successfully blocked/detected mail types
then this could allow criminals to know what vulnerabilities existed at
that time and target attacks on those systems.

We have considered the public interest in releasing this information;
however, we believe that the balance of public interest favours
withholding the information due to the real risk of harm that disclosure
could create.

Our response is in no way intended to imply that we suspect you of any
criminal activity, but as information under the Freedom of Information Act
is provided to the world at large we must consider the wider implications
of any disclosure.
 

If you are unhappy with the service you have received in relation to your
request and wish to request a review of our response, you should write to
FOI Review, East West Railway Company Limited, 1 Grafton Gate, Midsummer
Boulevard, Milton Keynes, MK9 1FB, or by email to
[1][email address].

If you are unhappy with the service you have received following an
internal review, you have the right to ask the Information Commissioners
Office (ICO) to review our decision. The Information Commissioner can be
contacted at: The Information Commissioner’s Office, Wycliffe House, Water
Lane, Wilmslow, Cheshire, SK9 5AF. You can find further information on the
ICO website: [2]www.ico.org.uk.

Yours sincerely,

Leon Mitchell
Information Governance Officer
East West Rail

show quoted sections

Dear Leon Mitchell,

Thank you for your prompt response to our FOI request. We kindly ask that you reconsider your decision to reject our request, as you were able to fulfill a similar request back in 2021. We are interested to know if any changes have occurred since then.

You can find the 2021 request here: https://www.whatdotheyknow.com/request/m...

Date: 22nd December 2021

I look forward to your response.

Rebecca

East West Rail team, East West Railway Company Limited

Dear  R Moody

Thank you for your interest in East West Rail. 

We are in receipt of your email of 21 February 2023 and we are treating it
as an Internal review of our response to your Freedom of Information
request. 

The Freedom of Information Act and Environmental Information Regulations
oblige us to respond to requests for information within 20 working days of
the day we received your message, but we aim to respond to all enquiries
as quickly as we can.

Please do get in contact if you have any further questions.

Kind regards,

Leon Mitchell
Information Governance Officer | East West Railway Company

show quoted sections

Good afternoon,

I just wondered when I could expect a response to my internal review request, please?

Many thanks,
Rebecca

East West Rail team, East West Railway Company Limited

1 Attachment

Dear R Moody,

Thank you for your interest in East West Rail. 

We are in receipt of your email of 31 March 2023 and can advise that a
response to your request for an Internal review was sent on 15 March 2023.

However, we did receive a notification confirming that our correspondence
was undeliverable.
 
Please see attached response letter which concludes our response to this
request. 

Kind regards,

Leon Mitchell
Information Governance Officer | East West Railway Company

show quoted sections