The ICO issued one of its largest ever fines last week. While the breach is notable for the number of records accessed (3 million), the interesting thing is the commentary by the Information Commissioner.
Her comments really do underline the message "do the basics", which security professionals have been saying for years. It's easy to focus on the latest tools and systems, but if you aren't doing the basics then all the next-gen tech in the world is not going to help.
This is an area where the government really has been trying to help business with the '10 Steps to Cyber Security', among other things. Is this the opening message of 2018: "Do the basics"?
The Information Commissioner, Elizabeth Denham, said: "A company as large, well-resourced, and established as Carphone Warehouse, should have been actively assessing its data security systems, and ensuring systems were robust and not vulnerable to such attacks. "Carphone Warehouse should be at the top of its game when it comes to cyber-security, and it is concerning that the systemic failures we found related to rudimentary, commonplace measures."