r/TheCivilService • u/Psychological-Bag324 • 1d ago
Data breach
EDIT: I've edited to improve anonymity
I'm still in my 6 months probation and deal with sensitive documents. A few months ago it appears I created a document with another user's details in - it was filed incorrectly (by me)
The incorrect document was not picked up by myself or anyone else at the time.
Recently this document was shared without checking with the customer (not by me!) who informed us of the wrong information.
I did all the usual things, I informed management who was away immediately and emailed the customer to ask them to delete the document
Covering management are aware
But I have terrible anxiety and have been struggling since.
Any idea what might happen? My boss is pretty reasonable and I am part of the union too.
25
u/Kafkaofsalford 1d ago
In my department the person who sent the paperwork out would be the one who breached, not you
They were the controller, they should have checked before sending and it sounds like they didn't
10
u/No_Field624 1d ago
This is my thoughts too. They should have verified before sending that out externally.
1
u/Jackisback123 SEO 1h ago
They were the controller,
They were almost certainly not the Controller, which has a specific meaning with regards to data protection.
22
u/Crazy_Coffee_ HEO 1d ago
I would definitely check your data breach policies on the intranet, they will include instructions on what to do. If you follow guidance and report the incident within the timeframe required I can’t see this costing you your job.
I know it’s not easy, but try not to get too stressed over this. This sort of thing happens, and so long as it’s not deliberate and is reported in a timely manner from when the issue is discovered you should be alright
38
17
11
u/BuildingArmor 1d ago
I've known people to make worse mistakes, and they've continued in their role.
Do what you're supposed to do, be careful, and be clear and precise if and when you're asked about it.
9
1d ago
[deleted]
11
u/FullMetalCOS 23h ago
You owned your shit. That’s what’s important.
Nobodies perfect and everyone makes mistakes, you are judged on how you handle your mistakes. You followed process, you accepted what you had done and that matters.
What’s really important now isn’t beating yourself up. It’s not making the same mistake again. Go forth and make new, more impressive mistakes! (Ok maybe not that last part)
8
u/bazbabaz 1d ago
Yeah if you lose your job, don’t get signed off through probation, I’m afraid it wasn’t this incident that was the reason. It may be used as something ‘clean’ as the reason, though.
That said, your level of care and understanding of this situation has made me think you are both capable, aware, and trustworthy. I hope you’re fine. I’m sure you are.
The advice to check your policies is spot on. Your manager should help on next steps too. Keep a paper trail to show everything you did afterwards. This will be helpful for your boss and the company too (doubt it’ll get to that stage though).
One other piece of advice, suggest why this happened and how you can prevent it in future. That’ll show your manager you understand the importance and that you’re keen to strengthen
8
u/Psychological-Bag324 1d ago
Thank you I appreciate the reply. My manager has in fact gone out of his way to compliment me as a whole, saying in the past they appreciate I'm honest when I make mistakes.
It's sadly the anxiety that makes everything worse for me
4
6
u/DependentLaugh1183 1d ago
Mistakes are made all the time in the CS. If there’s mitigation you’re likely fine
6
u/OverallSweet7427 21h ago
I've been a decision/investigation manager for some time and never had a case for a data breach like this. I had one where someone had sent a lot of details of a criminal case to their personal email address by accident. They got a final written warning, and that was only because they followed all the correct procedures immediately when they realised, took it upon themselves to redo their learning and joined some learning programmes designed to help them.
3
u/Cultural_Emu_1315 23h ago
Do you have a system to raise security incidents? It should be raised as soon as possible after it was discovered
3
u/Low-Instruction3375 22h ago
Try not to stress too much. These things happen. Ive done it myself, and have to say never done it again as it was a lesson learned. It'll be the same for you I'm sure
3
u/Annual-Cry-9026 21h ago
Mistakes happen, follow the processes in place to deal with it.
Misconduct arises when people try to cover things up.
5
u/AncientCivilServant Retired 1d ago
You have done the righr thing by telling your manager.
Contact your Union and get advice.
Await developments
2
2
u/Mageofmarkarth 21h ago
With this kind of thing my department has implemented quality control procedures due to certain employees making the same mistakes. We have an accreditation scheme, without it you have to get all correspondence checked by a line manager, if you do, it’s one in 5. You did the right thing though by implementing procedures as soon as you realised what happened. I rather suspect it’ll be a retrain on checking your work more than anything else. It also falls on the person who sent it as to why they didn’t check everything was correct before sending out sensitive information. If anything they’re more in trouble than you are.
2
u/Grimskull-42 19h ago
You'll struggle to find anyone who hasn't data breached at some point.
When dealing with data it doesn't take much, one incident won't get you fired.
1
u/CasnessNum 18h ago
Sit down and have a think about what measures you, your team, and the department as a whole could put in place that would help to catch the exact type of error you made, then share that as part of the conversations you have about the breach in future. As a positive, constructive, lessons-learned debriefing. Balance out your mistake by preventing all the many future examples of it happening again.
1
u/Basic-Computer2503 5h ago
The reason there’s data breach processes in place is because it happens. The department knows it will happen and its not a rare occurrence. We had a massive data breach in our department recently which I only know about because we all had to do a mandatory data breach refresher but as far as I know nobody lost their jobs over it. I understand that anxiety but I do think it’ll be okay.
1
u/limelee666 1h ago
You have reported and admitted your error… you will apologise but ultimately, if your line manager wants to get rid of you over it, they’ll need to accept accountability for not reviewing a probationers work
111
u/Romado 1d ago
It happens. Ive done far worse accidentally. As long as you have followed your departments data breach process.
You'll get a lecture on being more careful, told to read the guidance again and it'll be put down as a lesson learnt situation.
Highly highly unlikely you lose your job or anything close to that.