Awareness Lessons
5 months ago
Italian Consulting Firm Fined €85K for Poor Password Security and GDPR Violations
Ambrosetti S.p.A. was fined €85,000 by Italy's data protection authority for multiple GDPR violations following a breach affecting 62,000 individuals. The company stored passwords in plain text and weak formats, failed to notify affected individuals within required timeframes, and negligently assumed external contractors were monitoring security without proper oversight. This case demonstrates how poor password management practices combined with inadequate incident response procedures can lead to significant regulatory penalties and reputational damage.
Tactical Insight
Immediate actions
- Implement strong password hashing (bcrypt, Argon2) for all stored credentials
- Audit and remove any unnecessary stored passwords or credentials
- Establish clear GDPR notification procedures with defined timelines
Long-term improvements
- Deploy comprehensive data protection policies covering password storage and retention
- Implement regular security audits of third-party contractor activities
- Create automated breach notification workflows to ensure regulatory compliance
Oversight measures
- Conduct quarterly reviews of password storage practices across all systems
- Establish formal agreements with contractors defining security monitoring responsibilities