[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOqTVFqmBrrNrvXWwp00nl0PB7mwEv4MSd01ZFyi7ruY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"4f82066f-432b-4d36-a71b-2909b4b17136","permanent-tsb-fined-277k-for-social-engineering-failures-and-late-breach-notifications","14ef2900-0f13-496d-a060-bcfcbe3d635d","Permanent TSB Fined €277K for Social Engineering Failures and Late Breach Notifications","Permanent TSB failed to implement adequate security controls to defend against social engineering attacks, leaving customer accounts and personal data exposed to compromise. The bank's lack of robust human-layer defences — such as staff training and identity verification protocols — allowed attackers to manipulate processes and access sensitive information. Compounding the breach, PTSB failed to notify the Irish Data Protection Commission of three separate data breaches in a timely manner, a direct violation of GDPR's 72-hour notification requirement. This case illustrates that technical controls alone are insufficient; organisations must also invest in people, processes, and regulatory obligations to protect personal data effectively.","**Immediate actions:**\n- Deploy mandatory social engineering and phishing awareness training for all customer-facing and back-office staff.\n- Establish a clear, tested data breach notification procedure that ensures DPA reporting within the GDPR-mandated 72-hour window.\n- Introduce multi-factor authentication and enhanced identity verification for all customer account interactions.\n\n**Long-term improvements:**\n- Embed a formal Security Awareness programme with regular simulated social engineering exercises and measurable performance metrics.\n- Appoint a dedicated Data Protection Officer (DPO) with authority to oversee breach detection, escalation, and regulatory reporting processes.\n- Conduct periodic third-party audits of security controls mapped against GDPR Article 32 requirements.\n\n**Detection & monitoring measures:**\n- Implement anomaly detection on customer account access patterns to flag unusual activity indicative of social engineering compromise.\n- Maintain a centralised incident register to ensure all potential personal data breaches are assessed, documented, and escalated in real time.\n- Establish automated alerting thresholds that trigger an internal breach response team when suspicious account activity is detected.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 32 – Security of processing","GDPR Article 33 – Notification of a personal data breach to the supervisory authority","GDPR Article 34 – Communication of a personal data breach to the data subject","NIST SP 800-50 – Building an Information Technology Security Awareness and Training Program","NIST IR-6 – Incident Reporting","NIST PR.AT-1 – Awareness and Training (CSF)","CIS Control 14 – Security Awareness and Skills Training","CIS Control 17 – Incident Response Management","ITIL Service Operation – Event and Incident Management","ISO\u002FIEC 27001 Annex A.6.1.3 – Contact with authorities","ISO\u002FIEC 27001 Annex A.16.1 – Management of information security incidents","published","2026-07-06T14:20:40.663981+00:00","2026-07-06T14:20:40.576+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DPC_(Ireland)_-_IN-22-7-3&diff=52069&oldid=0","dpc-ireland-in-22-7-3-e20a89","DPC (Ireland) - IN-22-7-3",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]