現在の状態
関連調査
2- Capita がアウトソーシングのサイバーリスクを公共サービスの説明責任の試金石にした
Capita はリスクと説明責任のケースです。2023年のサイバーインシデントは、サプライヤーの侵害が民間のアウトソーシンググループ内のシステムに影響を与えた場合でも、公共サービスの問題に変わる可能性があることを示しました。問題は、Capita が不正アクセス、サービス中断、データ流出後にシステムを復旧したかどうかだけではありません。問題は、市民、年金加入者、従業員、地方自治体、公的機関、受託者、民間顧客、規制当局、投資家が、どのアウトソースされたサービスが影響を受けたか、どの個人データがコピーされたか、誰が誰に通知すべきか、運用管理が説明責任を伴わずに公的機関から移されたかどうかを理解するのに十分な証拠を見ることができたかどうかです。
主要記事公開日 2026-07-15 - Capita made outsourcing cyber risk a public-services accountability test
Capita is a risk and accountability case because its 2023 cyber incident showed how a supplier compromise can become a public-services problem even when the affected systems sit inside a private outsourcing group. The issue is not only whether Capita restored systems after unauthorized access, service disruption, and data exfiltration. The issue is whether citizens, pension members, employees, local authorities, public agencies, trustees, private clients, regulators, and investors could see enough evidence to understand which outsourced services were affected, which personal data had been copied, who had to notify whom, and whether operational control had been moved away from the public body
主要記事公開日 2026-07-15
