Back to all lessons
Awareness Lessons
5 months ago

Italian Consulting Firm Fined €85K for Poor Password Security and GDPR Violations

Ambrosetti S.p.A. was fined €85,000 by Italy's data protection authority for multiple GDPR violations following a breach affecting 62,000 individuals. The company stored passwords in plain text and weak formats, failed to notify affected individuals within required timeframes, and negligently assumed external contractors were monitoring security without proper oversight. This case demonstrates how poor password management practices combined with inadequate incident response procedures can lead to significant regulatory penalties and reputational damage.

Tactical Insight

Immediate actions

  • Implement strong password hashing (bcrypt, Argon2) for all stored credentials
  • Audit and remove any unnecessary stored passwords or credentials
  • Establish clear GDPR notification procedures with defined timelines

Long-term improvements

  • Deploy comprehensive data protection policies covering password storage and retention
  • Implement regular security audits of third-party contractor activities
  • Create automated breach notification workflows to ensure regulatory compliance

Oversight measures

  • Conduct quarterly reviews of password storage practices across all systems
  • Establish formal agreements with contractors defining security monitoring responsibilities