Request for information surrounding data loss

The request was partially successful.

Dear HM Revenue and Customs,

I would like to know to what extent you have implemented data encryption and cyber insurance policies and losses that you have incurred specifically covering the following;

1. How many laptops, mobile, tablet or USB devices have been lost or stolen from your organisation in the past year (Sept 2021-Sept 2022)? Please specify numbers of each device type.

2. How many of these devices were encrypted? Please specify numbers of each device type.

3. Have you had to disclose or inform the ICO of a data breach as a result of any of these devices being lost or stolen in the past year (Sept 2021-Sept 2022)?

4. Have you had to disclose or inform the ICO of a data breach for any other reason e.g., cloud breach, supply chain breach...

5. How many data breaches (information has been lost, stolen or taken from a system without the knowledge or authorisation of the department/organisation) have you experienced within your organisation (department) within the past year (Sept 2021-Sept 2022)?

6. Do you have an existing cyber insurance policy in place, and how long have you had it? If not, do you plan to invest in cyber insurance in the coming year?

7. Have you had to claim on an existing cyber insurance policy in the past year (Sept 2021-Sept 2022) - if so, what was the reason for this i.e. ransomware attack, phishing scam...

Yours faithfully,

Alicia Broadest

Team, FOI, HM Revenue and Customs

Our ref: FOI2022/74259

Dear Alicia Broadest,

Freedom of Information Act 2000 Acknowledgement

Thank you for your communication of 25 November.

We have allocated the above reference which you should quote if you need
to contact us.

We will arrange for a reply to be sent to you which will either comply
with our obligations under Freedom of Information Act or, if we think it's
an enquiry that we don't need to address under the terms of the Act, let
you know why. If it is the latter we will, if possible, pass it on to a
more appropriate part of the Department for answer.

While we aim to r espond to all freedom of information requests within 20
working days, if for some reason this timescale cannot be complied with,
we will, where possible, write to you explaining the reason for the delay
and provide an estimated time for response.

Yours sincerely

HMRC Freedom of Information Team

Team, FOI, HM Revenue and Customs

1 Attachment

Dear Alicia Broadest,

We are writing in response to your request for information, received 25
November.

Yours sincerely,

HMRC Freedom of Information Team