{"id":4928,"date":"2025-03-27T17:03:02","date_gmt":"2025-03-27T04:03:02","guid":{"rendered":"https:\/\/ostermanresearch.com\/?p=4928"},"modified":"2025-08-07T11:19:45","modified_gmt":"2025-08-06T23:19:45","slug":"misdirected-communications-2024-update-from-the-ico","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2025\/03\/27\/misdirected-communications-2024-update-from-the-ico\/","title":{"rendered":"Misdirected communications &#8211; 2024 update from the ICO"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"326\" data-attachment-id=\"4936\" data-permalink=\"https:\/\/ostermanresearch.com\/2025\/03\/27\/misdirected-communications-2024-update-from-the-ico\/misdirectedemail\/\" data-orig-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?fit=1100%2C350&amp;ssl=1\" data-orig-size=\"1100,350\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"misdirectedemail\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?fit=300%2C95&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?fit=1024%2C326&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?resize=1024%2C326&#038;ssl=1\" alt=\"\" class=\"wp-image-4936\" srcset=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?resize=1024%2C326&amp;ssl=1 1024w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?resize=300%2C95&amp;ssl=1 300w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?resize=768%2C244&amp;ssl=1 768w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?w=1100&amp;ssl=1 1100w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p>The most common <a href=\"https:\/\/ico.org.uk\/action-weve-taken\/data-security-incident-trends\/\" target=\"_blank\" rel=\"noreferrer noopener\">data security incident reported to the Information Commissioner&#8217;s Office<\/a> (UK) for October to December 2024 was &#8230; unsurprisingly, misdirected emails. The frequency of using email for communicating with others, the ease of stumbling when using type-ahead addressing in Outlook and other email clients, and the frenetic pace of much office work means that it&#8217;s just too easy to choose the wrong person. Of the total incident count reported to the ICO, 21% were of this type.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"472\" data-attachment-id=\"4930\" data-permalink=\"https:\/\/ostermanresearch.com\/2025\/03\/27\/misdirected-communications-2024-update-from-the-ico\/20250327icodatasecurity\/\" data-orig-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?fit=625%2C472&amp;ssl=1\" data-orig-size=\"625,472\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"20250327icodatasecurity\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?fit=300%2C227&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?fit=625%2C472&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?resize=625%2C472&#038;ssl=1\" alt=\"\" class=\"wp-image-4930\" srcset=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?w=625&amp;ssl=1 625w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?resize=300%2C227&amp;ssl=1 300w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/20250327icodatasecurity.png?resize=200%2C150&amp;ssl=1 200w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/figure>\n\n\n\n<p>There are email security add-ins that will alert users that something doesn&#8217;t add up in their communication, some of which <a href=\"https:\/\/ostermanresearch.com\/portfolio\/egress-human-activated-risk\/\" target=\"_blank\" rel=\"noreferrer noopener\">we&#8217;ve written about<\/a> in recent years. There should also be a necessary emphasis on training users to check and double check when adding someone to an email message or distribution list, but that&#8217;s not guaranteed to work in all instances.<\/p>\n\n\n\n<p>The cost of getting it wrong is reputational mainly, although the extent of that cost and ancillary costs will depend enormously on the contents of the misdirected communication. Banal stuff &#8230; not so much. Corporate IP, confidential data, and data subject to privacy regulations &#8230; much more so. Excel spreadsheets with customer information &#8211; yes, that&#8217;s a problem. Mitigation wise, it depends on the nature of the information that people are sending and receiving, and the personal \/ corporate \/ national implications of getting it wrong. The higher the risk, the more layered a mitigation approach should be. And for very high risk situations, choose your tools extremely carefully. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The latest data from the ICO (UK) on data security incidents, with misdirected emails in first place (for frequency). That&#8217;s unsurprising.<\/p>\n","protected":false},"author":384585,"featured_media":4936,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027195],"tags":[712027511],"class_list":["post-4928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-security","tag-cybersecurity"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/misdirectedemail.jpg?fit=1100%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1hu","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4928"}],"version-history":[{"count":8,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4928\/revisions"}],"predecessor-version":[{"id":5212,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4928\/revisions\/5212"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4936"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}