---
title: Stop shifting the blame onto third parties. That breach is still your firm’s responsibility
description: Stop shifting the blame onto third parties. That breach is still your firm’s responsibility
image: https://businessinsights.bitdefender.com/hubfs/travel-1758127_960_720.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security) [#Cloud Security](https://businessinsights.bitdefender.com/topic/cloud-security)

 By [**Graham Cluley**](https://businessinsights.bitdefender.com/author/graham-cluley) / Mar 20, 2017

# Stop shifting the blame onto third parties. That breach is still your firm’s responsibility

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/breach-firm-responsibility&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/breach-firm-responsibility&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/breach-firm-responsibility&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/breach-firm-responsibility&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/breach-firm-responsibility&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/breach-firm-responsibility&utm_medium=social&utm_source=facebook)

If it’s data that your customers gave you that’s breached, it’s your responsibility.

It doesn’t matter if your company hired a third-party to process the data on your behalf, or the data was stored on a web server managed by a third-party company you hired to handle it.  It’s your responsibility.

So, stop trying to shift the blame.

Yes, there’s no doubt that the third-party may have let the side down.  Maybe they didn’t have decent security in place, maybe they dropped the ball when it came to building the website securely or keeping up-to-date with patches.

But it was your company’s decision to hire them.

You trusted them with, for instance, your customers’ personal information.  Your customers trusted you to treat their data with the utmost care, and were probably never consciously aware that you would be sharing it with a third party in the first place.

I’m sorry to be so “tough love” about this, but these thoughts were high on my mind when I read about a recent security breach which has impacted some 43,000 people.

ABTA, the UK’s Association or British Travel Agents, issued a [statement](https://abta.com/news-and-views/news/data-security-incident-march-2017) last week revealing that a data breach had compromised the information of approximately 43,000 holidaymakers.

![abta-advisory.jpeg](https://businessinsights.bitdefender.com/hs-fs/hubfs/abta-advisory.jpeg?width=711&height=761&name=abta-advisory.jpeg)

According to ABTA, the breach occurred on 27 February 2017, and saw hackers exploit a vulnerability on abta.com, “which is managed for ABTA through a third-party web developer and hosting company.”

Most of the affected 43,000 holidaymakers find themselves in unpleasantly hot water because they had registered accounts on the abta.com website or filled in online forms to submit a complaint about an ABTA member.

As a consequence, thousands of people have had their email addresses, encrypted passwords (ABTA doesn’t tell us if the passwords were encrypted and hashed, the hashing algorithm that was used, or whether the hashes were salted - all of which would be useful to know) and contact details fall into the hands of hackers.

Furthermore, around 1000 files containing individuals’ personal identity information uploaded in support of complaints about travel agents were exposed.

In its advisory, and in its notification email to users, ABTA underlines that the affected web server was under the management of an unnamed “third party web developer and hosting company”.

That may be accurate but legally it’s not a way of wriggling out of the blame.

As an article in *Security Week* [points out](http://www.securityweek.com/travel-agent-association-breach-highlights-supply-chain-threat) - in the eyes of the UK’s Information Commisioner’s Office (ICO), the data controller (ABTA) retains responsibility regardless of the contracted third-party data processor (the web-hosting company).

![abta-email.jpeg](https://businessinsights.bitdefender.com/hs-fs/hubfs/abta-email.jpeg?width=711&height=677&name=abta-email.jpeg)

It should go without saying that if you are an ABTA member, or might have shared personal information with the ABTA website, that you should change your password – and ensure that you are not using the same password anywhere else on the net.

There is little you can do to prevent firms being more careful about who they entrust with your personal information, but you can – at least – attempt to lessen the impact when future breaches occur. 

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/one-in-three-investment-firms-have-not-yet-started-gdpr-compliance-projects?hsLang=en-us>

### [One in Three Investment Firms Have Not Yet Started GDPR Compliance Projects](https://businessinsights.bitdefender.com/one-in-three-investment-firms-have-not-yet-started-gdpr-compliance-projects?hsLang=en-us)

<https://businessinsights.bitdefender.com/law-firm-phishing-still-top-cause-of-data-security-incidents?hsLang=en-us>

### [Law firm: Phishing Still Top Cause of Data Security Incidents](https://businessinsights.bitdefender.com/law-firm-phishing-still-top-cause-of-data-security-incidents?hsLang=en-us)

<https://businessinsights.bitdefender.com/shielding-the-empire-the-advantages-of-a-prevention-first-cybersecurity-strategy?hsLang=en-us>

### [Shielding the Empire: The Advantages of a Prevention-First Cybersecurity Strategy](https://businessinsights.bitdefender.com/shielding-the-empire-the-advantages-of-a-prevention-first-cybersecurity-strategy?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Graham Cluley",
    "url" : "https://businessinsights.bitdefender.com/author/graham-cluley"
  },
  "datePublished" : "2017-03-20T14:05:00.000Z",
  "headline" : "Stop shifting the blame onto third parties. That breach is still your firm’s responsibility",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/travel-1758127_960_720.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/breach-firm-responsibility",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```