Northern Ireland Affairs Committee
Oral evidence: PSNI data breaches, HC 1791
Tuesday 5 September 2023
Ordered by the House of Commons to be published on 5 September 2023.
Members present: Simon Hoare (Chair); Sir Robert Buckland; Stephen Farry; Mary Kelly Foy; Sir Robert Goodwill; Claire Hanna; Carla Lockhart; Jim Shannon; and Bob Stewart.
Questions 41 to 161
Witnesses
II: Assistant Chief Constable Chris Todd, Police Service of Northern Ireland.
Examination of witness
Witness: Assistant Chief Constable Chris Todd
Chair: It is with pleasure that I invite Assistant Chief Constable Chris Todd of the PSNI to join us.
Assistant Chief Constable Chris Todd: Good morning, everybody.
Q41 Chair: Mr Todd, thank you very much indeed for joining us today. Do not feel like Daniel in the lions’ den. We understand entirely the circumstances whereby you are—somebody’s got to say it—on your Todd, but we are grateful to you for coming before us this morning.
You have asked, and I have agreed, to make an opening statement to the Committee. We will then have our questions for you. I am grateful for your attendance of the earlier session so that you could hear the depth of concerns of colleagues on this side of the table, but also the views of our previous witnesses. The floor is yours, sir.
Assistant Chief Constable Chris Todd: Thank you, Chair. Chair, members, thank you all for the invitation to be here today. I am grateful for the opportunity to address publicly this very serious matter with you.
You will of course be aware of the Chief Constable’s resignation yesterday, and that he had been due to appear before you himself. I am grateful for the words that you have shared with us this morning. I share my gratitude to Mr Byrne for the service and support he has personally shown me.
I would like to assure you that I am a member of the police service senior executive team. I am its senior information risk owner and gold commander for Operation Sanukite, which is our response to the recent data leak. This issue falls firmly within my professional portfolio. As such, I believe that I am well placed to answer the Committee’s questions today, notwithstanding the absence of the Chief Constable.
My senior colleagues and I are convinced of the importance of continuing the business of policing. In particular, we were determined to take this opportunity to publicly address this extremely serious matter with you here today. Thank you again for that opportunity.
As you know, the Police Service of Northern Ireland is currently responding to three recent data breaches. The most serious of these occurred on 8 August, when our response to a legitimate freedom of information request inadvertently shared details of every officer and member of staff in the organisation. This workforce dataset was visible on a third-party website for just under two and a half hours.
I want to start by apologising to all my colleagues and their families for what is clearly a shocking, industrial-level data breach. I am deeply sorry that this happened, and I am deeply sorry that this happened on my watch. I do not underestimate the impact that this has had on the personal and family lives of many of my colleagues. My primary concern, and that of the entire police senior executive team, remains the safety and security of our people. Nearly 4,000 officers and staff have now made contact with our dedicated emergency threat assessment group, which was established in the wake of this breach.
As you know, the police in Northern Ireland remain the target of a severe terrorist threat. Some of the information released, such as reference to surveillance and intelligence personnel, is considered highly sensitive. Although it was taken down quickly, it is our assessment that the data is in the hands of dissident republicans. They are likely to seek to use it to threaten, intimidate and attack us. Therefore, another key strand of our ongoing response is to investigate and disrupt those who hold this data and would seek to use it for criminal purposes.
This is a complex investigation, which has engaged specialists from a number of our security partners. To date we have made six arrests, and one individual has been charged with possessing documents or records likely to be useful to terrorists. Indications are that this is having a chilling effect on those who would seek to use the data to cause harm.
We have also increased our level of operational activity. Additional security and reassurance patrols have been taking place across Northern Ireland as part of our organisational response. I want to reassure the Committee that we are working around the clock to investigate this incident, communicate with our people, provide them with practical support and reassurance, and mitigate any risk to their safety and security.
I hope today to provide you with a sense of the significant steps we have already taken and are planning in reaction to this event. The independent review, jointly commissioned with the Policing Board, will be an important step as we move from our immediate response into the recovery, resilience and rebuilding phase. I hope this review will provide confidence to officers and staff, and assurance to the wider public that the causes of the data breach have been identified and addressed.
We are grateful to Assistant Commissioner O’Doherty and his team for their expertise and assistance. We are also grateful for the wider support of Government and other national agencies. This has been and will remain crucial throughout the rebuilding process.
I would like to conclude my opening remarks by paying tribute to the officers and staff of the police service. I want to thank them for their continued hard work, resilience and dedication. The business of policing never stops, and they have unflinchingly continued to serve the community through what has been an incredibly challenging period for policing in Northern Ireland. I am personally very proud to serve alongside them all.
Q42 Chair: Thank you for that heartfelt and sober reflection on what has happened and where we are. You mention the data being in the hands of dissident republicans. Are they the only hands that are likely to hold the information, or are there concerns about those involved with paramilitary activity on the other side—those who are no friends of the police, because most, if not all, their activity is of a criminal nature? They have as much to gain from a demoralisation and diminishment of the police presence in Northern Ireland.
Assistant Chief Constable Chris Todd: Indeed, Chair. It is our assessment that it is not just dissident republicans who have shown an interest in this. It is, however, important to highlight that the greatest threat to policing is from those groups. That is the intelligence assessment that has led to the threat level being set at “severe”.
It is also important to note that the dataset alone will not suffice to assist those who would seek to cause us harm—to launch attacks. It will help in the identification of individuals, of course, but the individual identification of officers and staff has always been of concern to us. The capability and capacity of those who seek to cause us harm have not been increased by this. It has, however, perhaps incentivised some people to try to exploit this to their advantage.
Q43 Chair: It would be helpful, for what it is worth, not to solely and singly reference dissident republicans in communications, if this is something that is causing concern across the police.
I will leave Claire Hanna and Sir Robert Buckland to deal with the minutiae and detail of the FOI situation, but in recent days we have had a picture painted, or a mosaic revealed, of tribal, feudal, war of the roses type antagonism between senior officers. The buck has been passed from one to the other, and scapegoating has been attempted. We heard in our earlier session about a mindset of management, rather than motivation and leadership.
We have heard of a force that is under-resourced, with people being over-worked in a very tense environment. That would possibly lead the layman to think that the PSNI as an institution is not fit for purpose. Overlay that with the certainly implied operational consultation or sign-off from politicians as to whether a chief can sanction one thing or another, and a board that appears to be semi-detached from operational decisions, though certainly consulted on operational matters from time to time. Is that a fair assessment, or have the media blown it out of all proportion?
Assistant Chief Constable Chris Todd: There are a number of elements in that, Chair. First, I think the media narrative can sometimes be unhelpful. Trust and confidence in the rule of law are important to stabilise any society, and in Northern Ireland that means trust and confidence in the Police Service of Northern Ireland. Anything that undermines that is always unhelpful. Fair commentary from the press is also really important, so that we can be held to account, do not become complacent, and are reflective in all that we do. It is healthy in that respect.
I do not recognise this as an organisation that is at war with itself, to use that phrase—not at all. I do not recognise that in the senior leadership team. I know there have been narratives to the contrary, but I have sat in rooms with the rest of my executive team having very collegiate and supportive conversations about how we can best lead the organisation forward through these difficult times, while that narrative is being played out elsewhere, contrary to what is happening in the room. The budget situation is undoubtably of concern.
Q44 Chair: So, to the best of your knowledge, it is a complete fabrication that the former chief effectively said, “Oh well, this was all to do with someone else—nothing to do with me. I am just the fall guy for it all,” and engaged in the most enormous amount of buck passing, as reported at the board meeting last week? Is there no truth in that whatever?
Assistant Chief Constable Chris Todd: I cannot comment on what was said in the board meeting last week. I was not privy to those conversations. I was not present during those conversations, and I was not serving at the time of the incident that they were discussing at that particular board meeting. I was present at the previous board meetings, which were particularly relevant to the data breach. We have had two emergency board meetings in respect of this, and I have seen nothing but a united front from the executive team on those occasions.
Simon Hoare: We will probably now turn to how the PSNI manages FOI requests. I suppose the kernel of that question is: how on earth did this happen?
Q45 Sir Robert Buckland: This is the first opportunity you have had to speak to a body of elected representatives, so it is important that we put on the record precisely what this document was, and what its nature was. As we understand it, it was an Excel spreadsheet with a number of fields and tabs—I think we are all familiar with the way that Excel works.
Can you explain for the record precisely what form this document was, with particularly reference to the absence of any password protections on all or part of this document? My understanding is that it had 345,000 pieces of data, covering not just police officers but people working for the service, which is 10,000 people. You can see where I am coming from, Assistant Chief Constable. Why on earth wasn’t this password-protected? Perhaps you can explain the precise nature of the document, and then help us with that issue.
Assistant Chief Constable Chris Todd: Certainly. On a point of clarity, although there were fields of data of the magnitude that you described, it relates specifically to just under 9,500 individuals; there were some duplications, for example, which accounts for that.
On the detail of how it actually happened, the dataset that was shared comes from one of our HR systems. It is an extracted dataset that is extracted on a routine basis. It is extracted once to minimise the effort, and it is used in a number of different ways—again, to be more efficient. Rightly or wrongly, that is the reality of how this happened.
Q46 Chair: Extracted by who?
Assistant Chief Constable Chris Todd: By colleagues in the HR department who are cleared and accredited to access that system. The system was never breached; the people who accessed the system were qualified and equipped to do just that—and only they could do that. It is best practice across industry, and recognised as such, that when looking to manipulate data in such datasets, you do not work within the system; you extract from the system, to protect the integrity of the core data, and that is what they did.
The reality is that it should never have gone beyond that point, but the practice of extracting in order to manipulate the data is commonplace in many places. The issue of password protection is one that undoubtedly the review team will examine in detail and will draw up some recommendations about, I would anticipate.
Q47 Sir Robert Buckland: They were not password-protected?
Assistant Chief Constable Chris Todd: No. Certainly, it wasn’t password-protected when it went out from that department, but the people who accessed it would have provided an audit trail through their own password to access the system.
Q48 Sir Robert Buckland: The original FOI question was how many officers serve at each rank, wasn’t it?
Assistant Chief Constable Chris Todd: Yes.
Q49 Sir Robert Buckland: Unfortunately, the answer threw everything at it, however inadvertent that might have been.
Assistant Chief Constable Chris Todd: The dataset that was extracted, as I said, was extracted once in order to be most efficient, and then would be used for a number of different queries. The query in question did not need the whole dataset.
Sir Robert Buckland: No.
Assistant Chief Constable Chris Todd: Again, whether extraction should be dealt with on an individual basis will be part of the review.
Q50 Sir Robert Buckland: That is what I wanted to ask you, officer. Really, this question begs quite a simple answer. It is a list of all the ranks in the PSNI, and then just a number next to each rank. For example, one next to chief constable; a few next to ACC. It then goes down the ranks—we know how it works—to detective officers and other officers. That was all that was needed. Why was that not the subject of a separately generated document? Is that what systemically does not happen?
Assistant Chief Constable Chris Todd: Ultimately, it was the subject of a separate document, but the problem was that the core data remained attached to it. The data that would have been shared would have been very limited and had no personal identifying data in there. It would have been very simple indeed. But the core data remained attached inadvertently.
Q51 Chair: It wasn’t done properly.
Assistant Chief Constable Chris Todd: It was not done properly, no.
Q52 Sir Robert Buckland: There was a shortcut taken. Surely you only answer the question that you are asked by FOI, which was how many officers there are of what rank. Surely it would have been better to do that in a separate table—it could even have been done on a digital side of A4—and away from the primary data. I have to ask the question: if it has happened here, has it happened on other occasions with data that is perhaps less sensitive—audit or accounting data—and that has just been sent out in a great slew along with the data that answers the primary question?
Assistant Chief Constable Chris Todd: There are two elements to that. First, has it happened before? The answer to that is yes, in other organisations, and we have become aware of that since, regrettably.
Q53 Chair: Sorry, has it happened with other organisations?
Sir Robert Buckland: In other organisations.
Assistant Chief Constable Chris Todd: In other organisations. We have been aware since this leak that there have been similar occurrences in other organisations.
Q54 Chair: In other police services?
Assistant Chief Constable Chris Todd: Correct. Chair, you picked on one particular service before and suggested that the impact would have been very different. Indeed, that is what has transpired in other places.
Sir Robert Buckland: Can I ask another question?
Assistant Chief Constable Chris Todd: Sorry, if I may interrupt, can I come back to the second point on whether it has happened before in our organisation? Notwithstanding the independent review, I did not want to lose any momentum, so I ensured that we cracked on with our own review immediately. We are being very careful to manage that alongside the independent review and the ICO investigation, but it was important that we understood where we had any vulnerabilities that we could immediately address, which we have done.
As part of the review, we have shared 501 submissions to the whatdotheyknow.com website, which is where the breach occurred. We have reviewed each and every one of those, and there have been no other similar issues. We have examined 766 URLs that linked to the use of spreadsheets on our public-facing website, and seen if there are any other vulnerabilities there: there were none. We have gone back through two years’ worth of FOIs published by a variety of means in addition to the ones I just mentioned, and again, we found no issues, so we are confident that, regrettably, as significant as this was, it was an isolated incident.
Q55 Chair: Can you very quickly walk us through this? Somebody submits an FOI request. Somebody looks at it and goes, “Yes, this falls within the regulations, so we are obliged to answer it.” How do you task the person to answer it who then signs off the answer and effectively ticks the box that says, “This answers it; it is good to go”? Walk us through that process as it existed at the time.
Assistant Chief Constable Chris Todd: That is a very important point, Chair, because we have already changed the process, recognising the vulnerability. The situation as it stood at the time was that a freedom of information request comes into our corporate information branch, in which sits the freedom of information team; they also deal with subject access requests, etc. They process the request, identify who is best placed to answer the question in layperson’s terms, and pass the request on to the department that holds the relevant data.
In this case it was an HR query, so it was passed to HR professionals who had access to the dataset—for reasons of security, as we have discussed, ironically. They then answer that query. A senior manager in that department signs it off; it is passed through our corporate communications department, so that they are aware of the nature of queries coming in—often they are related to journalists’ inquiries etc.
Q56 Chair: I will just pause you there for a clarification of terms. An application or request comes in. Somebody qualified in the rules and regulations of FOI requests says, “Ah, this is an HR one,” and they pass it to somebody in HR. Their involvement with the request then ceases, or they say to HR, “This is what we need to answer; please reply to us, and we will handle the transmission of the data.”
Assistant Chief Constable Chris Todd: That is correct, Chair, yes. After it has gone from the subject-matter experts—in this case, HR—through corporate communications, it returns to the FOI team and is then published by the FOI team. The measures that we have taken—
Q57 Chair: Should it not come back to the FOI team before it goes to corporate communications? That is trying to sort out the PR before you have worked out what the press release says.
Assistant Chief Constable Chris Todd: It is just for awareness; it is kind of a parallel process at that point.
Q58 Chair: Parallel, or next step? Your answer did not suggest parallel: it suggested a staged approach.
Assistant Chief Constable Chris Todd: It is for information purposes. They are not signing off the query; they are being made aware of the query.
Q59 Chair: So there could be the potential that they might issue something or put something into the public domain that ultimately will not be put into the public domain.
Assistant Chief Constable Chris Todd: Sorry, the—
Chair: Your corporate communications people.
Assistant Chief Constable Chris Todd: No, they would simply be made aware.
Q60 Sir Robert Buckland: So they do not see the material; they just—
Assistant Chief Constable Chris Todd: They do see the material, but the sign-off process would be from the senior manager in the department who is handling the query, and then the FOI team.
Q61 Sir Robert Buckland: Okay. How many pairs of eyes would look at material subject to an FOI or access request?
Assistant Chief Constable Chris Todd: In a query of that nature, about four or five people.
Q62 Sir Robert Buckland: Which begs the question why nobody spotted this glaring error.
Assistant Chief Constable Chris Todd: Yes. In the conversations this morning, initially, the term “human error” was used; I think in my first media conference I used that term. Now, I used that term purposely to differentiate between a mistake and an attack on our systems—I thought it was important to make that clarification—but when we examined it further, we could see that it had gone through a number of eyes and the mistake had not been rectified or identified, which suggests that we have systems and process errors that we need to address, and that is what we have done.
Q63 Chair: Is it a systems error? It does beggar belief that four people, one of whom is on a dedicated team—and corporate comms will see all of them, and then whoever it is farmed out to for an answer will see it—will all make the same mistake.
Assistant Chief Constable Chris Todd: It does, Chair, but equally, because it has happened once, I cannot rule out it happening twice. I need to change things, and that is what we have done.
Q64 Chair: I appreciate that, but if I was a betting man or a betting woman, the odds of four people not spotting such a glaring error would be very considerable. Would they not?
Assistant Chief Constable Chris Todd: In defence of those involved, I think it is important to highlight that it was not glaring to the naked eye, so to speak. That is part of the issue. The impact is obvious. The significance is obvious. But the fact that the core data set remained attached was not obvious to the naked eye.
Q65 Sir Robert Buckland: That is because it was in another tab?
Assistant Chief Constable Chris Todd: Correct, and the tab had been obscured.
Q66 Sir Robert Buckland: Can you explain precisely what you mean by that?
Assistant Chief Constable Chris Todd: I can. It was due to the way in which it was manipulated, regrettably, by those who were producing the data set. Those who are familiar with Excel will know that tabs appear at the bottom of the page.
If you manipulate the presentation of the tab you are working on, you can move it to the left, and it then overlays the other tab. That was the one that contained the core data, so it effectively put a sheet on top of another sheet, thereby obscuring it to the naked eye. As the document was opened, the result was presented, which was absolutely acceptable. The core data was not presented, and it needed further scrutiny—which should have happened—to identify the presence of that.
Q67 Sir Robert Buckland: That is a very important explanation. As the Chair said, it is the equivalent of having a desk full of papers, picking up too many sheets of paper and handing it over to the public domain. This does raise a question. The FOI request seems to not in any way compromise the sensitivity and importance of maintaining the confidentiality of the identity of police officers and staff. Why was that information not in the public domain anyway, available on a website, perhaps, so that the responder could have said, “Please go to the PSNI website, and you can find it all there”?
Assistant Chief Constable Chris Todd: Indeed, and we do have a strategy of doing exactly that. Some Members are aware that we have been subject to ICO inspection recently. We were under an enforcement notice for failing to meet the compliance requirements around submission times for FOI requests. We put in place processes to address that, and we have sustained a level of performance above 90% for 12 months now, often in the range of 95%. That has been very effective. In addition to dealing with the issues of being more efficient within the Department, we have looked at the strategy around FOI. To reduce the demand, we have sought to publish more information in the public domain.
Sir Robert Buckland: Very sensible.
Assistant Chief Constable Chris Todd: Unfortunately, this particular query, and the precise nature of the query, could not be answered with what was already in the public domain. So a new query was run. Again, I am sure the review team will examine the veracity of that and whether or not we should have been more robust and pushed back on the precise nature of the query.
Q68 Sir Robert Buckland: Yes, because I can imagine that in some parts of the service you have only got one or two individuals doing a particular type of role, and the danger is that it could lead to their identification. I agree with that. That is a common problem with FOI when you get numbers that are fewer than 10.
It is important, is it not, that in light of this efforts are to be redoubled to see how much material can safely be put into the public domain? It could shorten the work of FOI officers and speed up your responses, as it would be a quick referral to an existing website.
Assistant Chief Constable Chris Todd: Indeed.
Q69 Chair: Just before I turn to Clare, we heard in session one—this was said in various ways but in short it was the following: that it was a small, under-resourced team, in terms of both bums on seats and financial resource to support. You have referenced the enforcement notice. Is one of the issues that feeds into this breach a case of, “Look, we’ve not been good enough at responding to FOI requests. We need to improve our output, and damn well put our foot to the accelerator and just get more stuff out in a more timely fashion”? Therefore the speed has been maintained, which ticks one box, performance output, but at the expense of quiet, calm, sober reflection and review—somebody very senior checking.
I am not a data person, but even I know that, if you are looking at an Excel spreadsheet, there are things that sit behind it, and before you press send it is quite useful to look and see what those are. My children would laugh at me trying to claim to have any form of technological expertise, but has that been one of the problems—speed and output leading to the sacrifice of quality checking?
Assistant Chief Constable Chris Todd: I am satisfied, Chair, that in this case that was not a contributing factor, but it is an obvious question to ask.
Q70 Chair: What have you done to satisfy yourself that it is not a contributing factor?
Assistant Chief Constable Chris Todd: Well, by looking at the nature of this particular request. We do still struggle to service some requests within time limits. This was serviced actually quite easily, because the dataset that the query was run from already existed. That extract of HR data is done once a week for a number of purposes and was therefore already available, so that effort did not have to be replicated. That is what added to the speed in this occurrence—not any attempt to cut corners.
Q71 Chair: Would we be correct to therefore assume that the practice of keeping every bit of data surrounding the PSNI downloaded, on a regular basis, and then extracting the information to respond to individual requests from a core document on your desktops has now ceased? It might be an absolutely pain in the backside to do it, but when a specific request comes in, are you now, as Sir Robert intimated, extracting that specific dataset, but only that specific dataset, rather than drawing it down from a document, which can have occluded tabs?
Assistant Chief Constable Chris Todd: Correct. The particular data breach in itself was brought to my attention at 10 past 4 on the day in question. By 6 o’clock I was chairing a gold group with colleagues from across the organisation, including from very specialist areas, and some immediate actions were set within that gold group.
Those included effectively locking down in the way that you have just described. We recognised that that would be a frustration to some, but it was seen to be essential, and then we would seek to open it up once we understood exactly what we were dealing with and what further mitigation could be put in place. That is the very simple strategy that we took from the outset.
Q72 Claire Hanna: I have a few questions about the specific FOI and FOIs in general. What is the average time for a response to an FOI?
Assistant Chief Constable Chris Todd: Some 90%-plus are met within time limits.
Q73 Claire Hanna: The time limit is 20 days.
Assistant Chief Constable Chris Todd: Correct, yes.
Q74 Claire Hanna: Do you know what period within that 20 days they tend to be delivered?
Assistant Chief Constable Chris Todd: They vary. Some of them—obviously a small percentage—we do not meet within that time limit. Some of them go to the wire. This one was turned around with just a few days—I think it was about—
Q75 Claire Hanna: That’s my understanding: on average it is about 19 days, and this one was turned around in two days. You said that the dataset already existed, but is that a normal speed to progress through all those checks, bearing in mind that this was in holiday time as well?
Assistant Chief Constable Chris Todd: The reality of this particular instance is that the magnitude and impact are so serious, but the query that it resulted from was actually very straightforward. That is why it took only a few days to turn around.
Q76 Claire Hanna: I understand that the National Police Chiefs’ Council issued guidance in June, I think, about handling FOIs safely. Was that communicated to the various people who are supposed to handle FOIs in the PSNI?
Assistant Chief Constable Chris Todd: Again, that is something that the review team will no doubt be looking at, and possibly the ICO in their investigation—it has been brought to their attention. That circular in June was not brought to my attention as a senior information risk owner.
I have been speaking to colleagues in the National Police Chiefs’ Council to see whether there is something we can change in processes there. I handle a number of portfolios and regularly receive updates around those portfolios, whether it is firearms, public order and so on, which also sit within my remit. They go to practitioners but they also go to service leads such as myself. That enables me to reflect on what my team are dealing with, and to lean in when I see something of significance. I would like to think that on such an occasion I would have leant in.
Q77 Claire Hanna: I can understand how it happened—four people went through the document and did not see the behind tab, as you correctly say—but I do not understand how, within two hours of it being released, somebody has found that tab. That bit is very difficult to get your head around. Is the behind tab visible to the naked eye?
Assistant Chief Constable Chris Todd: Sorry—the disclosure of the tab or the disclosure of the incident?
Claire Hanna: The tab with the offending data breach within it. My understanding, from what you have said to my colleagues, is that essentially there was another tab overlaid. I think everybody understands that you can do that. But four people in your processes did not see it, but within two hours the person who leaked it did see it. Was the back tab visible to the naked eye? I do not understand how, if you could not see it without knowing it was there, they knew it was there.
Assistant Chief Constable Chris Todd: If you imagine a piece of paper that literally has a protrusion at the bottom as a tab, and on an Excel spreadsheet that is represented as a second tab, they were perfectly aligned, so you see one tab.
Q78 Claire Hanna: I understand that, but if they were perfectly aligned, how did somebody know to go and look behind it?
Assistant Chief Constable Chris Todd: To the left of that, for those who understand Excel, there is an indicator that a tab exists.
Q79 Chair: Hang on a minute. Somebody makes an FOI request—Mr John Smith of 32 Acacia Avenue—and they get their request answered, and they go, “Oh, hang on, this is frightfully interesting. I asked for how many officers, with each person in each rank, and they have answered that. I tell you what I am now going to do: I am going to look to see whether I can find a tab, or whether there is any other information that they have sent to me inadvertently.” I think Ms Hanna is right that that, of itself, slightly beggars belief—unless it took so damn long to download the response because they were downloading sheet after sheet after sheet. Did nobody just notice the size of the file?
Assistant Chief Constable Chris Todd: Regrettably not, no.
Q80 Chair: So not only did nobody did notice this hidden tab, but nobody noticed the size of the file. I think it was Sir Robert, or it might have been Ms Hanna, who said that the information requested was probably one side of A4.
Assistant Chief Constable Chris Todd: Indeed.
Q81 Chair: I am not falling into the typical politician’s trap of someone having to be blamed, and we have to go and tar and feather them or whatever it may happen to be, but this just now smacks of incompetence, doesn’t it?
Assistant Chief Constable Chris Todd: As you are aware, Chair, there is an independent review being carried out. They will look in the first phase—
Q82 Chair: I appreciate that, but in your opening remarks, ACC Todd, you said that you were the professionally charged officer, you were leading this and this was your area of operational expertise. Forget the individuals involved: if you were presented with this as a sort of blind case study, the word “incompetence” would surely flutter across the front of your mind.
Assistant Chief Constable Chris Todd: It is difficult for me to comment without impinging on the ongoing review, which will look at the behaviours and responsibilities of everybody involved, including myself as SIRO. I am choosing my words carefully. I guess if an individual misses something, you might immediately go to that conclusion, rightly or wrongly. When two people miss it, you may start to question that. In this case, where four have done, I think we need to look beyond incompetence, certainly on an individual human basis, and we need to look at the competence of the system and the process that has allowed that mistake to happen.
Q83 Chair: Do you have any concern that this was done deliberately?
Assistant Chief Constable Chris Todd: No.
Q84 Chair: And how have you established that?
Assistant Chief Constable Chris Todd: Just from the very nature of the actions that have led to this, the human reactions from the people who have been involved in this, and—
Q85 Chair: People who do things deliberately can be very good actors as well.
Assistant Chief Constable Chris Todd: There would need to have been a conspiracy across a number of people for that to be the case, and that is beyond the realms of what is more likely than not, I would suggest, Chair.
Q86 Claire Hanna: I have heard that the PSNI receives more FOIs than the whole rest of the Northern Ireland civil service combined. Do you know whether that is true?
Assistant Chief Constable Chris Todd: I have heard that anecdotally. I can’t provide any data myself to substantiate that; we don’t have access to the data across the other organisations. There is police data that is publicly accessible through the National Police Chiefs’ Council site. We do receive more FOIs than similar services, so those of a similar size and format. As a comparison, we receive about a third of the number that the Metropolitan police receives, and obviously the Metropolitan police is substantially more than three times the size of the Police Service of Northern Ireland.
Q87 Claire Hanna: It would be interesting to try to find that out. What is the resource implication? How many people are employed dealing with FOIs?
Assistant Chief Constable Chris Todd: It is a small team. Forgive me, I don’t have the figures in front of me. It is about 20 people in total. One of the things that we have done immediately in response to this incident is we have looked at the structure of that team. We have looked at the role responsibilities within that team, and we have put in place a quality assurance team at the point at which the submissions exit the team and the organisation. The qualifications of those individuals will give them an improved understanding of the legal implications of what they are dealing with, and also some technical resource within there, so that any—arguably, this was a very straightforward technical issue, but nevertheless we can’t be complacent about what the next threat or vulnerability might be, so there will be some technical resource in there to ensure there is a more robust analysis of everything that leaves that team in the future.
Q88 Claire Hanna: Do you look at that with both a technical data lens and, I suppose, a purpose lens? I am not suggesting that we police them, so to speak, but it seems to me that there is a process where it gets flagged up.
In general, I think any of us who are journalists or politicians that use FOIs, you are trying to get to a certain thing. Is that a process where people go, “Hmm, what is this person trying to ascertain from me? Are they generally doing a school project about the number of—” Do you apply that sort of critical lens about what the purpose of the request might be? I am not suggesting in any way that there are nefarious purposes behind this request, but is that a way that you can maybe evaluate where you need to be particularly secure?
Assistant Chief Constable Chris Todd: Yes, there is, and that is the reason why among them is our corporates comms department. Our corporate communications department have sight of the FOIs so that they can see if there are any trends developing around natures of request or any specific requests that are clearly looking at a particular issue, which maybe we need to be alive to and prepare to respond to.
Q89 Claire Hanna: On the impact, how many referrals have been made to the PSNI support unit about individuals and their concerns about their data?
Assistant Chief Constable Chris Todd: It was, as of this weekend, 3,954. I think my colleagues earlier mentioned the RAG status that we afford to that. Some 857 of those individuals were categorised as red in our status.
Q90 Chair: That is about a third of the overall data breach. You said about 9,500, wasn’t it?
Assistant Chief Constable Chris Todd: Of the number of people who have referred in in total? Yes, it is slightly more than a third, and then probably about a quarter, less than a quarter, within those who would be in the RAG status of red. It is important to highlight that that is not necessarily a heightened risk to the individual; it is the speed at which we need to speak to that individual and assess further.
Q91 Claire Hanna: Briefly, and then I will hand back over, some of it is about people’s general confidence and security about themselves, and how insecure this has made them feel. That is why we are concerned about their belief in the organisation’s ability to deal with it. You did say on the day of the breach that there is nothing at the moment to suggest there are any immediate security concerns. What gave you the confidence to say that?
Assistant Chief Constable Chris Todd: That was the intelligence assessment at that time, and clearly we have been monitoring ever since then. Subsequently we did highlight, as I did today, that we do believe it is in the hands of those who would seek to cause us harm, so we are continuously assessing.
We are also assessing that the robust pursuit of those who would seek to cause us harm—the arrests we have made and the prosecution of those for whom we can demonstrate such alleged activity—is having an impact on those who potentially have access to it. In layperson’s terms, it is making them think twice about that: the risk of prosecution compared with the value it affords them.
Q92 Claire Hanna: Finally, I appreciate that there have been arrests, but do you believe that those who have the information and have ill will accessed it within the two hours it was online or have they accessed it subsequently because it was circulating on WhatsApp or whatever?
Assistant Chief Constable Chris Todd: It is very difficult to say. We have looked at the traffic across the website within those two and a half hours.
Q93 Claire Hanna: How many hits?
Assistant Chief Constable Chris Todd: The total number was in the region of about 300.
Q94 Claire Hanna: On this page, on this FOI question?
Assistant Chief Constable Chris Todd: Correct.
Q95 Claire Hanna: Have you mapped that against general?
Assistant Chief Constable Chris Todd: We have. Two hundred of those would be individual cases, because some would be duplicates and repeated access and so on; about 100 of those are ones that we can assess more quickly than others; and then a very small number of those are ones that have caused us further concern. We have contacted each of those individuals and made them aware of the risks they carry if they maintain access to the dataset. Where we see evidence of potential criminality, we will relentlessly pursue those individuals, as we have done.
Q96 Claire Hanna: Are they traceable by IP or do people have to log in? Are they traceable? If I went on to access that page, do I have to log in with a password or whatever?
Assistant Chief Constable Chris Todd: To the original website?
Q97 Claire Hanna: To the original website.
Assistant Chief Constable Chris Todd: No, it is a publicly available website. Your IP address would obviously be identifiable.
Q98 Claire Hanna: Is that how you have contacted the people who accessed it?
Assistant Chief Constable Chris Todd: Suffice it to say, we have.
Q99 Chair: Mr Farry wants to come in and Ms Lockhart does as well, so let me shorten a question I was posing to you, just to get a very clear answer.
We are where we are. An Excel document, in response to an FOI request, is released. Four people who deal with these things on a very regular basis, one of whom has it as their sole job to deal with FOIs, do not notice the hidden tab, do not check to make sure there is no additional information and do not notice the size of the file. It goes out into the public domain. Within two and a half hours, somebody who has made the FOI request—we do not know who that is; it could be somebody who is very skilled in these matters or it could just be a member of the public who was asking for a school project or whatever—somehow or another found the occluded tab and all the data.
You have sought to assure us that you are absolutely confident that this was effectively human error—let us just use that as a working title—and that you have no concerns at all that this was not a deliberate breach of data. I am finding it hard as a layman to understand why four people did not spot, in what would have been quite a period of time for the compilation of the response to the FOI request, what the recipient spotted in two and a half hours. I am not writing the latest plotline for “Line of Duty”, but it strikes me as stretching credulity just a little bit too far.
Assistant Chief Constable Chris Todd: Which particular aspect, Chair?
Chair: You were very certain and very speedy to answer that you had no concerns that this was anything other than human error/cock-up, rather than it being leaked deliberately and the person who was receiving it being tipped off that this additional information would be provided because it might be considerably useful to them and/or their organisation or colleagues.
In essence, I am asking you to assure this Committee and therefore the wider Northern Irish public on the record that the investigation has already concluded and there was no, for want of a better word, conspiracy, and that this was not a deliberate leak of data.
Assistant Chief Constable Chris Todd: An investigation is ongoing into how the leak happened, which may present further information—obviously, I cannot rule that out—but the initial assessment was very clear that there was no malintent in any of the individuals who were engaged in any way in this breach. Once the breach happened though, the value of the data became apparent to others who were then able to access it. That is where the risk is presented. In the same way as any asset that was left on the street by accident—
Simon Hoare: Or on the top of a motor car.
Assistant Chief Constable Chris Todd: Indeed. Then the intent of the individual is not in question. The intent of the person who then secures that asset is what is important to us, and this is no different.
Q100 Chair: Should we be surprised, concerned, angry, or possibly all three that this should happen in a service that should need no lessons with regards to the sensitivity of the climate and the environment in which it polices and does the work that it does? All data is important but in a Northern Irish context it is important double-plus.
Latterly, the PSNI have appeared to be rather cavalier with regard to data. It is sort of Mr Bean that someone should stick something on the top of a car and drive off. You might do it with your shopping list or a bag of frozen peas that you stopped off to buy. The public are right to be worried, are they not, and your officers and support staff have a double right to be very worried?
Assistant Chief Constable Chris Todd: We should all be concerned whenever there is a single breach of any of our assets—absolutely. They should all absolutely be taken very seriously, as all of these instances are. I would not say that there is a cavalier attitude—absolutely not. I think the response we have put in place is demonstrative of that—that we are taking this very seriously and have acted very quickly in order to address it.
Q101 Chair: That is hoovering up the mess after it has been made. There seems to be a worrying trend within the PSNI of an ability to create data breach messes. Correct me if I am wrong—if I am I will stick my hands up—but that does not seem to be as much of an occurrence in other constabularies across the United Kingdom. Am I wrong?
Assistant Chief Constable Chris Todd: I would suggest that the scrutiny of other constabularies is very different; indeed, I am aware of incidents in other areas that are very similar to our own major data breach but that have drawn very little attention. That does not diminish the seriousness of our issue and what we are dealing with. I think the fact that we immediately put measures in place to ensure that this does not happen again was vital.
Equally, we identified how it had happened very quickly and put measures in place to stop it happening immediately. Then we commissioned an independent review almost immediately, because we could not be complacent that we had found everything and we wanted fresh eyes. We purposely went outside of the organisation and the existing bodies to bring in those fresh eyes, because we are subject to scrutiny on a regular basis.
We have annual audit reports and inspections from the ICO; we were subject to an enforcement notice for 18 months, and we had a separate widespread voluntary inspection from the ICO. These issues were never identified by any of those bodies so we have gone to new bodies and asked, “Can you please look and see if there is anything else we are missing?” because we absolutely cannot afford for this to happen again.
Q102 Chair: That is laudable, and thank you for sharing that with us. But the broad supposition is that this breach—I am talking about the extensive data breach—is the result of human error. Unless someone creates a special programme to recalibrate the human psyche and our behaviours and so on, everything is going to be subject to human error. One can never say, “It’s never going to happen again.” It is about minimising the opportunities where we can. Are you going through a process of refreshing and rationalising who is able to access, within the organisation and from within the organisation, the whole set of data that the PSNI holds?
Assistant Chief Constable Chris Todd: Yes, we are. This incident is very specific to freedom of information requests, but we are addressing every dataset that leaves the organisation and is shared across the organisation. We are rewriting our service instruction and providing accompanying guidance to go with that. That is drafted and hopefully will be ready to share very soon. Until we have that, we have locked down many of our systems to ensure that data is not shared. That is causing frustration among some of our partners.
Q103 Chair: Yes, I’m sure, but it is the right thing to do. Turning briefly to cost, this may be outwith your sphere of expertise, but what is the PSNI’s assessment of the financial cost of mitigating the impact of this incident? In the medium to longer term, what is the cost reputationally to the PSNI in terms of recruitment and retention, and what potential negative impact might that have on community safety, community policing and evidence of criminality on the streets of Northern Ireland?
Assistant Chief Constable Chris Todd: Some of that, Chair, is very difficult to quantify, as I am sure you appreciate. In terms of recovery costs and what we would ideally like to do in order to address this—be that a universal offer to all our staff regardless of the individual threat, through to the very specific threat that some people may face—we estimate that is somewhere in the region of £24 million to £37 million.
Q104 Chair: So £24 million to £37 million.
Assistant Chief Constable Chris Todd: Correct.
Q105 Chair: And that excludes or includes the potential individual claims for compensation for a breach of data?
Assistant Chief Constable Chris Todd: It excludes that, so litigation would go beyond that.
Q106 Chair: I appreciate it would be a ballpark figure, but what would the assessment of that be?
Assistant Chief Constable Chris Todd: The ICO will run its investigation. It may take some action; I can’t predict what that might be, but in terms of individual litigation, we naturally will plan for that eventuality. I would estimate that it could be in the region of £150 to £180 million.
Q107 Chair: So we are talking in ballpark terms of an unexpected expenditure of round about £230 million to £240 million?
Assistant Chief Constable Chris Todd: Potentially.
Chair: Potentially.
Assistant Chief Constable Chris Todd: This is all potential, of course, as a worst-case scenario.
Chair: That is a worst-case scenario. Existing budgets clearly could not sustain that in any way, shape or form.
Assistant Chief Constable Chris Todd: As my colleagues mentioned, we already have a funding gap of about £50 million.
Q108 Chair: So what, if any, representations have you been making to the NIO, or indeed directly to the Treasury, with regard to new moneys?
Assistant Chief Constable Chris Todd: We are naturally sharing all these considerations with our partners in the Department of Justice and the Department of Finance. That is our port of call as a devolved Administration.
Q109 Chair: But we do not have a devolved Administration. So they have a budget that we fixed yesterday, which, as colleagues across the House referenced, was deemed to be insufficient. Ms Lockhart, correct me if I am wrong, but it was something like a 1.5% reduction in the budget for the DOJ. So there is no new money in Stormont even if it were sitting, and Stormont not sitting obviously does not help. So who writes the cheque for this?
Assistant Chief Constable Chris Todd: We are very alive to those considerations, Chair. We are obliged to work with the Department of Justice and the Department of Finance in the first instance, and no doubt our colleagues in those Departments will be—
Q110 Chair: But their civil servants are hamstrung on this. They have no Ministers to give them political guidance. There is no opportunity for a combined political response to this from within Stormont, so it has to be over the road at the Treasury or at the NIO, doesn’t it?
Assistant Chief Constable Chris Todd: Regrettably, Chair, that is not within my gift to resolve.
Q111 Chair: No, that is not in your gift to resolve, but there is only one organisation that can sign the cheque, which is HMT, isn’t it?
Assistant Chief Constable Chris Todd: I hope our colleagues in the Department of Justice and the Department of Finance will help us in that regard.
Q112 Carla Lockhart: I want to go back to your information about the spreadsheet and how data was stored. Can you walk me through that? Assuming those dealing with the FOI had access to people’s personal details, would that not normally be stored within a human resource system? Would that system not ordinarily be a locked system, or is it so antiquated that, actually, anyone in the organisation can access it?
Assistant Chief Constable Chris Todd: You are exactly right and that is exactly what happened: the people who accessed it were HR professionals, so they are trained and accredited to access that system—and only them and other accredited individuals. The data is not manipulated within the system, though, because that potentially corrupts the system, so the data is extracted from the system. It was HR professionals who extracted the data from that system, because they have access to it, and it was the extracted data that was worked upon, again by the HR professionals, who are cleared to do that.
Q113 Carla Lockhart: We all know, in our sphere of work, the importance of GDPR and of ensuring that people’s details are protected. It beggars belief that human resource professionals, who are trained in this, would extract 10,000 lines of details and then forward them on. Were they forwarded on to other officers to then deal with?
Assistant Chief Constable Chris Todd: The extraction is a practice that you will see replicated in many places. An organisation of 9,500 people has a lot of HR matters to deal with on a daily, weekly basis. This was just one query, but access to that data is there for many reasons. It is not unusual for individuals within that department to be accessing that data. It is their job to do that.
Q114 Carla Lockhart: But it is about where it went to after that.
Assistant Chief Constable Chris Todd: Yes, it should not have left.
Q115 Carla Lockhart: How did it get to the FOI department, who then published it?
Assistant Chief Constable Chris Todd: It should not have left, and that is the issue around the failure to identify that that source data remained attached.
Q116 Carla Lockhart: My colleague Ms Hanna has highlighted the timescale, and I have to say that rings alarm bells again in my head. I know from whenever I submit FOIs that quite often it is right to the last moment before you get the response. Actually, you normally get a response saying, “We are still working on collating this information. We will get it to you in due course.” It seems really bizarre that this was dealt with in two days. Was there an assessment done of who had made this or what the background to it was?
Assistant Chief Constable Chris Todd: As I said before, the significance of the breach is recognised. If any of us could wind back the clock, we would, because you cannot underplay the seriousness of this. But the simplicity of the query was what allowed it to take place within that timescale. The data had already been extracted for other reasons, so it was available. Nobody had to go looking for it. It was available and therefore the query was a simple one, and it was run in a relatively short timeframe.
Q117 Carla Lockhart: Someone did have to go looking for it. Ultimately, this FOI jumped the queue. As we have heard, there are many FOIs coming into the department. Dealing with this one was potentially taking someone off other FOIs. Again, I am still not totally sold on this two-day thing, because, as I say, it normally takes a lot longer. In relation to the data being realised online, at what time were the PSNI made aware of it and when was it removed?
Assistant Chief Constable Chris Todd: I was made aware at 10 past 4.
Q118 Chair: May I interrupt? Can you give us the audit trail, because I think this will help all of us. You were made aware at 10 past 4. You chaired gold command, I think you said, at 10 past 6.
Assistant Chief Constable Chris Todd: Yes.
Chair: We don’t need to know the name of the individual, but how were the PSNI notified, when were they notified, and what was the gap between the PSNI body corporate being told that there was a data breach and them telling you?
Q119 Carla Lockhart: And not just you being notified. I would assume someone beneath your role was notified. Take us right from exactly when the PSNI were informed that this had happened.
Assistant Chief Constable Chris Todd: Unfortunately, I won’t be able to do that. That may be something that the review team will be able to get to the detail of.
Q120 Chair: No, sorry. That’s not good enough.
Assistant Chief Constable Chris Todd: It is not that I am withholding anything, Chair. I cannot answer that question at the moment.
Q121 Chair: I am not seeking to do Ms Lockhart or me down when I say that I do not think it is a rocket science question. We are asking for a very basic audit trail. You have been able to tell us that the gold command met at 6.10 under your chairmanship, that you were told two hours beforehand that there had been a data breach, and that from receipt of the answer to the FOI request, the recipient—or A.N. Other—had uncovered something that four people had not.
How was the PSNI informed and how did it deal with the information—that is, how did it get from “Hello, switchboard?” to “Chris? You’re the responsible officer here. We’ve got a real problem.” Walk us through that. If you cannot do that now, Mr Todd, I think we would like to have it in writing by the end of the day, because that seems to me a fairly basic question that one would expect you to be able to answer.
Assistant Chief Constable Chris Todd: Well, let me try to answer, Chair, and then perhaps you can draw your conclusions. It is more complex than perhaps is first apparent. The information was loaded to the site in that afternoon. That site is of such a nature that you can subscribe to it and set up notifications if you are interested in particular areas. There will be people who have set up notifications to say that they are interested in PSNI FOIs. They will receive a notification. They will come from a range of backgrounds. What happens is word of mouth then starts to circulate, and it will be a lot of mouths.
Q122 Chair: I do not want to be curmudgeonly on this and I am sorry to be boring, but professional people charged with an FOI request miss something—human error. It is posted. Somebody notices it. They may be very au fait with Excel and all the rest of it, but four people who deal with it on a daily basis do not notice it and one person does. Did word of mouth tell the PSNI? No. Somebody must have noticed. Was it somebody within the PSNI who said—I won’t use the words they might have used—“Oh, dear! We’ve posted something that we shouldn’t have”?
Assistant Chief Constable Chris Todd: Exactly that.
Q123 Chair: So it was somebody from within who noticed.
Assistant Chief Constable Chris Todd: I was informed by a colleague and took action immediately. The first colleague to identify this is very, very difficult for me to identify.
Q124 Chair: I am not asking you to, but this is helpful. So somebody from within the organisation notices that there has been a data breach. This was not the PSNI responding to a well-meaning member of the public saying, “Oh, I think you’ve put some stuff online that maybe you shouldn’t have.”
Assistant Chief Constable Chris Todd: That is correct.
Q125 Chair: So this is somebody from within the organisation. Is this somebody from within the organisation who would have previously handled the data of that response to the FOI?
Assistant Chief Constable Chris Todd: The first person to identify it? I honestly can’t tell you who that person is.
Q126 Chair: As I say, I mean—was it PC O’Neill out on the beat, who suddenly looked and went, “Oh, God almighty! I’d better call back to HQ,” or was it somebody either with HR, within corporate comms or within your FOI team who noticed that the error had been made?
Assistant Chief Constable Chris Todd: The attention was brought to me by people within my team. I can’t tell you—
Chair: That’s within the FOI team?
Q127 Carla Lockhart: Sorry Chair, but how were they informed? Did they note it or was it—
Assistant Chief Constable Chris Todd: I am not trying to be difficult here; I just can’t give you information I don’t have, Chair. People within the organisation were talking about the presence of this because they were alarmed, so there were a number of people—
Claire Hanna: I think it is about the initial point. I think we have all been in organisations where, if something like that did happen, WhatsApp groups would light up, but I suppose it is about the point at which, again, somebody found the hidden tab and then alerted. That is the concern, not even the lapse and how long it took for the emergency brake to be deployed—although yes, I think we do need to know about that—but the fact that it seems to be that it was on the website and everybody looking at it seemed to be able to find the hidden tab.
Q128 Chair: Claire, you are right, but it distils to this, does it not—and I think this is germane to Ms Lockhart’s point: that the commissioner, when assessing an organisation’s response to FOI requests, does not go, “Oh, well, you answered the easy ones within three and a half minutes of receipt, but the difficult ones were this”. They do not triage that. It is, “A request is a request is a request”. There is no compartmentalisation of them, as I understand it: really really tricky and easy peasy “What did you have for breakfast?” or whatever. So, a very simple piece of information is requested—“How many people are serving in each rank within the PSNI?”—and that is answered within two days.
Now, I cannot presuppose, and I would not believe it to be true, that the FOI request was the only one that the PSNI was dealing with. You will have had others that were complex, as easy, easier, or whatever. Four professionals handling this, one of whom is part of the specialist team dealing with FOIs, did not notice a very significant data breach through a hidden tab on an Excel sheet, the file of which is going to be considerably larger than the A4 piece of paper that would have really been required. None of them noticed, but, within two and a half hours, somebody else within the organisation—somebody within the organisation—did.
Now, what I am trying to get a handle on, and we are not asking for a name, rank and number, is, was it somebody within the HR team, was it somebody within corporate communications, was it somebody within the FOI-handling team, that team of 20, which you referenced a little while ago, or was it just an officer—I don’t use “just” pejoratively—or somebody else in the employ of the PSNI, who may very well have also subscribed to an alert thing for information, managing to find the hidden data that four people hadn’t?
You must be able to answer, as I say, without rank and number—
Assistant Chief Constable Chris Todd: Putting it in those terms, Chair, then yes, it is the latter.
Q129 Chair: So it is somebody from within the FOI team?
Assistant Chief Constable Chris Todd: No, someone within the organisation.
Chair: No, no, we have established that.
Assistant Chief Constable Chris Todd: Sorry, I am struggling to understand what you are seeking to achieve here.
Q130 Chair: What we are now trying to establish is, was it somebody who had previously handled this request and its response?
Assistant Chief Constable Chris Todd: No, it was not.
Q131 Chair: Right. Was it somebody within any of the teams who would have been involved in handling the request and the response, but had not been specifically charged or involved with answering it, or was it somebody within the PSNI who is not part of corporate communications, who is not part of the FOI team and who is not part of HR?
Assistant Chief Constable Chris Todd: As I say, Chair, the latter, but I cannot tell you who that first individual was.
Chair: You must be able to say—
Assistant Chief Constable Chris Todd: I am telling you it is the latter, Chair.
Q132 Chair: So that could be anybody within the PSNI. You have clarified that it was not anybody who had handled the request, so we have excluded them. What we are now trying to get an answer to—having established the fact that it is not one of them, but it is somebody within the PSNI—is, “Is it somebody within the PSNI’s human resources team? Is it somebody within the PSNI’s corporate communications team? Is it somebody within the PSNI’s FOI handling response team? Or is it somebody in the PSNI who is not part of any of those three silos?” It could be a police constable, a detective sergeant or whoever, but they are not involved in that bit of the administration of the PSNI.
Assistant Chief Constable Chris Todd: I am struggling to give you the forensic detail that I think you are seeking to achieve, Chair, because there was common talk within the organisation by the time it came to me, so who the first person was is very difficult to identify. There is an independent review team that has been established to look into the detail forensically—
Q133 Chair: So who told you?
Assistant Chief Constable Chris Todd: And there is an ICO investigation, and they are tasked to potentially look at the forensic detail, so I can’t present you with that information. The important thing is that within two and a half hours, it came to my attention and I dealt with it.
The person who told me was somebody on my corridor or in my department. If I start working back through everybody, then I am doing the job of the review team and the investigation team. As gold, I have not done that, Chair, so I can’t present that information to you today.
Q134 Chair: You have not done any form of investigation.
Assistant Chief Constable Chris Todd: I am satisfied that there was no mal-intent by those responsible—
Chair: That is not my question.
Assistant Chief Constable Chris Todd: I am satisfied that the person who made the request had no mal-intent.
Chair: Again, Mr Todd, that is not my question.
Assistant Chief Constable Chris Todd: Once the error was identified, it came to my attention within two and a half hours and I responded immediately.
Q135 Chair: All of which we have established. What we are now trying to establish is this. I understand if you say, “Look, we do know, but we are not in a position to tell you, because this is subject to” whatever. We can always go into private session if you wish. It may be, “We do know, but I cannot tell you at this precise moment in time”, “I don’t know, and we are trying to find out”, or “We don’t know, and we are not interested in trying to find out who first of all identified the breach; we are focused on how to stop such breaches happening again, and on analysing the robustness of our response to the data breach, of itself.”
What I am keen to hear, and what I think Ms Hanna and Ms Lockhart are keen to hear, relates to that two-and-a-half-hour gap between you picking up your phone and looking at a WhatsApp message, or somebody coming to you along the corridor and saying, “Chris, something awful has happened,” and you pressing the “gold command in two hour” button. What I am trying to get to is what happened in that window between publication and notification.
We have established that it is somebody within the organisation of the PSNI; we are still trying to establish whether it is somebody within any of the three silos who would have been dealing with the request, either in terms of registering it, answering it or responding to it.
Assistant Chief Constable Chris Todd: Let me try and answer it this way then, Chair. Believe me, I am trying to help as much as I possibly can here. I am not sure of the purpose we are seeking to achieve here, but let me try and help.
There is an independent review team who will look at these questions, and they have not reported back yet. There is an ICO investigation that will look at these issues; they have not reported back yet. We have our own criminal investigation to see who was seeking to use this information for malicious intent. We have made good progress in that; I mentioned earlier that we cannot go into the detail around that. The answer to your question will probably come from a combination of those strands of investigation, which I am not able to share with you.
Q136 Chair: So the answer to the question is, “It’s a legitimate question, Mr Hoare, that you’re asking. There is an investigation going on. We will know the answer to it, but we don’t know the answer yet.”
Assistant Chief Constable Chris Todd: Correct.
Q137 Chair: Thank you. But we do know that it was from within the PSNI—rather than a journalist, for example, who has logged on to the website and who may subscribe for notifications, suddenly calling up as a concerned citizen and saying, “I think somebody needs to check on this.”
Assistant Chief Constable Chris Todd: Correct. As I said before, we were not responding to a call from the public and we were not responding to an alert within the teams responsible: we were responding to information within the organisation.
Q138 Chair: Are we right to be concerned therefore that the professionals charged with the compilation, the signing off and the publication did not notice it but A. N. Other did?
Assistant Chief Constable Chris Todd: We should all be concerned about this for a variety of reasons that we have discussed, yes.
Chair: Ms Lockhart.
Q139 Carla Lockhart: Thank you, Chair. In relation to the audit trail, can you clarify that you were made aware of it at 4.10 by someone from within the organisation, as the Chair has forensically examined? We are still no further forward in terms of the rank. You then called gold command at 6—
Assistant Chief Constable Chris Todd: At 4.10, I was made aware. My first action was to have the data taken down.
Q140 Carla Lockhart: So it was removed at 4.10?
Assistant Chief Constable Chris Todd: No, we sought to remove at 4.10. It took until 4.47 before it was taken down. We had to identify the website, we had to identify the responsible person within the website and we had to negotiate with them to act without any court order, for example. Thirty-seven minutes later, we were able to achieve that.
Q141 Carla Lockhart: Do you feel that PSNI could have acted more quickly, given the chatter between some officer recognising this, coming to you and then removal?
Assistant Chief Constable Chris Todd: I am satisfied with the response from the moment I was made aware. Whether I should have been made aware sooner—it will probably come to the point that the Chair and you have identified—will be identified through the strands of investigation that are ongoing.
Q142 Carla Lockhart: In my mind, and obviously it is subject to investigation, as soon as an officer was made aware of or found this, it should have been escalated to you immediately.
Assistant Chief Constable Chris Todd: I would agree.
Q143 Carla Lockhart: Such is the magnitude of this issue. From within the organisation, there is a massive question about why it was not escalated to your senior role much more quickly than it actually was. I know that will all come out in the wash with regards to the investigation.
If rank and file PSNI officers now have concerns about how their data was held and published, how can the general public have confidence about their data? If someone rings 101 tonight with some highly sensitive information, how can they be confident that the PSNI will not do exactly the same thing with it?
Assistant Chief Constable Chris Todd: That is a really relevant question and it is a key tenet of my strategy to rebuild trust and confidence internally within the organisation, so that our people trust us to hold their data, and externally, so the public trust us to hold their data, and our partners that we work with.
All the measures that we are putting in place through the review, the examination and the implementation of lessons that are learned from that will hopefully go some way towards that. Being transparent and humble about the errors that we have made, and demonstrating to people that we absolutely want to not just fix this but improve on the systems and processes that we had in place before, I hope will go some way to rebuilding that trust and confidence. I know that it will not be a quick fix.
Q144 Carla Lockhart: I think of my constituency of Upper Bann, which obviously has a small nucleus of people who want to drag us backwards, but there are people who put their head above the parapet and contact the PSNI with information that is extremely sensitive and could be harmful to them if it was known that they had been in contact with the PSNI. It really does damage that line of communication from the general public, because hearing what they have heard today from this session, they will fear that all of that data could be made available through human error. Again, it goes back to the system.
Assistant Chief Constable Chris Todd: I would come back to the point I made earlier: we have already implemented a review of what has been made available. We have found nothing in those 501 publications on the website, we have found nothing in those 766 URLs on our own public-facing website, and we have found nothing in the last two years’ worth of FOIs. That should provide some assurance, but that does not minimise the impact of what has happened here.
We are not being complacent that that is sufficient, and hence we have an ICO investigation and an independent review to try to find any further hidden vulnerabilities. We will be in a better position at the end of this. My aspiration is that we will be the most secure police service.
Q145 Carla Lockhart: You quoted the figure of 890-odd officers who have been red flagged. Can you walk us through that triage process, and perhaps why it has taken so long? What is the next step for those officers? Is that 800 of the 3,000-odd who have come forward with concerns, or is 800 the police’s assessment of the entire 9,000?
Assistant Chief Constable Chris Todd: That is 857 within the 3,954 who have been referred into the emergency threat assessment group. Every member of staff in the organisation has been contacted by their line manager, and I know that you and other Members have received information that some of that was difficult at times. On day one, senior colleagues, including myself, were speaking to people on the phone, and other colleagues were doing that specifically with purpose. I had some individual conversations, but they carry the credit for the hard work that was done in the first day or two.
It was soon evident that we could not sustain that level of contact, so we were then reliant on individual line managers to pick that up for us. Throughout an organisation of 9,500 people, we absolutely need everybody to lean in. It took some time for some line managers to contact all their people—holiday period, absences and so on. We have worked very hard to emphasise the importance of everybody doing that—not just looking to your team but looking to where your peer is absent and looking after their team as well.
We got there, and everybody in the organisation—I have sought this assurance—is being fed back up to the command team, to that level. Every step in that chain has given me the assurance that everyone has been spoken to. The people who are absent from work and unable to access systems are being spoken to in person. Those who are unable to access their data through the portal that we have produced—we now have a portal so that an individual can access the one line of data and see exactly what was breached—are having hand-delivered letters, so that they also have direct access to the very precise nature of the data. That all helps with their own personal assessment of their vulnerability.
Then we have the assessment team, which deals with those people who either have been referred in through contact with their line managers or have individually suggested that they have some concerns. They range from some people who might initially be in the red status, which means we need to speak to them very quickly, and when we speak to them, we find that everything is in place that needs to be in place, and they immediately come back down to green, to those who might need the highest level of assurance.
One end of the spectrum, as we discussed earlier, is those who are SPED—so, they effectively have to move house. We have not had anybody in that category as yet, but that is something that policing in Northern Ireland has had to deal with on a regular basis, as you will no doubt be aware.
Q146 Carla Lockhart: Post the fallout from it, what is the financial situation in relation to access to support for the 800, be it extra security measures, SPED or whatever? We heard in the previous panel, which I am sure you heard, about the snarl-up in the NIO with regards to getting some of those measures paid for and procured. What is your assessment of that? Have you made any further representations? I may be doubling up here, but have there been any conversations with the NIO or the Secretary of State around the financial fallout from this, to ask this Government to actually support the police service, which is an absolutely dire state of affairs at this point?
Assistant Chief Constable Chris Todd: The Secretary of State has been well briefed, and the NIO is well briefed. The gold groups that I chair have representation from a range of partners, including the NIO. They sit on the gold group and are engaged in all the conversations we have, which includes all these measures and the financial implications of that.
The home security elements—I mentioned before about the total recovery costs—could be somewhere between £24 million and £37 million, depending on what is achievable. The home security alone would range somewhere between £7 million and £11 million, potentially, for that range of options that we described earlier. In terms of how we fund that, I am afraid that it is back to the conversation we had earlier, where we are presenting this in a coherent way to our colleagues in the Department of Justice and the Department of Finance and asking that they support us by whatever means they can.
Q147 Carla Lockhart: In all likelihood, with the ICO, there could be financial penalties as well in relation to the breaches.
Assistant Chief Constable Chris Todd: Potentially. That is a matter for the ICO. They share advice around how they deal with these things, which is publicly available. You will no doubt be able to access that and see the way they respond to public sector organisations, recognising that this is public money, ultimately. However, I cannot speak on their behalf and where they will fall on this particular incident.
Q148 Chair: I am conscious of time. Dr Farry.
Stephen Farry: I would quite like to take the same time everyone else took, Chair, including yourself.
Chair: No, I was not trying to—
Carla Lockhart: I still have one question, Chair.
Chair: Let Carla finish with her questions and then we will come to you. You can have as long as you wish.
Q149 Carla Lockhart: It is a comment, but it has a question attached to it. While you are responsible for the data and the breach, there is a lot of concern out there in relation to all that has gone on, be it the numerous breaches, the Ormeau Road incident or the Bobby Storey funeral incident.
There is a real perception out there—it is not just a perception, I do not believe, anymore—that there is two-tier policing. It is at an all-time low in relation to the PUL community and the political interference that has been evidenced through the recent investigations. What, as an organisation and as a senior leadership team, are you doing to try and restore that confidence in policing?
Assistant Chief Constable Chris Todd: We absolutely recognise that trust and confidence in policing is damaged by incidents such as this. Trust and confidence in policing is crucial for trust and confidence in law and order and for the stability of the society that we all want to live in. It is absolutely a priority for the police service. In terms of the other incidents that you mentioned, I am not in a position to comment on those personally. I am well aware that with the resignation of the chief constable yesterday, my colleagues in the executive team are meeting this morning, the Policing Board will no doubt be liaising with my colleagues and I will be picking up those conversations as soon as I return from here today to see how collectively we as an executive team can work in the next days, weeks, months and years ahead.
Chair: Dr Farry.
Q150 Stephen Farry: Thank you, Chair. Good afternoon, ACC Todd. I will be relatively brief, Chair, but I want to follow up on a number of issues that have been raised by others, just to seek some clarification.
In no particular order, going back to the issue around the excellent TheyWorkForYou website, in terms of the traffic for this particular dataset, how do the numbers of people looking at it differ from what would be the norm for other FOIs that go up, including FOIs from the PSNI?
Assistant Chief Constable Chris Todd: That is a very interesting question, actually, and unfortunately it is not one I can answer. You will appreciate that there are some privacy issues around analysis of public websites now. There are very specific circumstances here where we have been able to do some work, which has been helpful. I purposely have not gone into the details of how we have achieved what we have achieved there, but suffice to say—
Q151 Stephen Farry: What I am particularly interested in is who was accessing it. The number surely is anonymised and is something that can be shared—
Assistant Chief Constable Chris Todd: It would be information that would be retained by the website host, so it would not be immediately available to myself.
Q152 Stephen Farry: Given that they are very keen on transparency, they may be keen to share that. It is a two-way issue.
Assistant Chief Constable Chris Todd: They may.
Q153 Stephen Farry: This may actually be a slightly helpful question on the issue. My understanding of the data breach itself is that the ICO requires FOIs to be published in what it terms a format that cannot be manipulated. In theory, if this very simple piece of information that was the official request was turned into a PDF, the risk would be eliminated for the other tabs. On reflection, is this something that the wider public sector and Government need to reflect on in how FOI works? What is the public interest rationale—the other way of looking at it—in ensuring that the data is provided to an inquiry in a format that cannot be manipulated?
Assistant Chief Constable Chris Todd: That is a good point. The immediate action we took was to limit every publication to—for want of a better phrase—a flattened PDF so that there was no data in there that could be manipulated. You are correct: that is contrary to the guidance from the ICO itself and the legislation supporting this, which says that it should be in a machine-readable format. The easiest machine-readable format that most people can access is Excel, but it is not limited to Excel. The systems that we use naturally export into Excel rather than other formats, so the effort required to rectify that is considerable.
One analysis that I asked for in relation to a submission that would ordinarily be presented by way of spreadsheet said that if it was manipulated to a PDF, flattening each element of it would have equated to almost a 1,000% increase in effort for that one submission. It is very easy to say, and that is exactly what we did, but the implications are also significant.
I am aiming to achieve a graded effect where we will simply publish flattened PDFs where necessary. Where we have to share data in a more readable format, particularly with trusted partners, we will come to an arrangement that provides sufficient safeguards and mitigation to enable us to do that. Certainly, for public FOIs the starting point will be flattened PDFs.
Q154 Stephen Farry: In terms of how this was assembled, is there an issue with what I suspect was a relatively junior member of staff doing the actual work in assembling the original FOI response before managers looked at it? That person presumably had access to the entirety of the names of the entire PSNI workforce. Is there a protocol inside the organisation on who, at what rank and level, can access that level of sensitive data?
Obviously, you want to trust everyone, and I am not suggesting that this person was untrustworthy in any way whatsoever, but that is surely a risk. For example, you have seen some extreme situations where some junior clerks in the US intelligence services have actually gone and leaked massive tranches of US intelligence, and people asked, “How on earth does someone at that level in an organisation have access to that broad breadth of information?”
Assistant Chief Constable Chris Todd: The rank and grade is not necessarily an indicator of what somebody should access: their vetting and clearance would determine that. That is often role-dependent rather than rank or grade dependent, but certainly the people who have access to that data should be only those who are suitably cleared and accredited.
Q155 Stephen Farry: There is also a need-to-know issue as well, because it goes beyond that issue. You need a high bar for that level of information being shared in an organisation, even for an FOI compilation.
Assistant Chief Constable Chris Todd: Correct.
Q156 Stephen Farry: Without necessarily going into specifics, can you confirm if accountability/disciplinary processes are underway in relation to those individuals involved in the other breaches identified over the summer months?
Assistant Chief Constable Chris Todd: To be clear, you are talking about this particular breach and the—
Stephen Farry: The other ones.
Assistant Chief Constable Chris Todd: Newton Abbey and the laptop on the vehicle.
Stephen Farry: Yes.
Assistant Chief Constable Chris Todd: They are all subject to ongoing parallel investigations.
Q157 Stephen Farry: In terms of the impact on officers, are you in a position to tell us how many officers have resigned from the PSNI since the data breach? Obviously, we are not a full month through yet, but how many have tendered their resignation in this period?
Assistant Chief Constable Chris Todd: My colleagues earlier referenced the 28-day period for resignations. What we hope to achieve here is an exit interview for everybody that leaves, and to specifically address this issue. Some of those have not yet worked their way through that 28-day cycle—I think today is probably 28 days from the day of the breach—but we know of one resignation so far when someone has specifically referenced the data breach as a factor.
Q158 Stephen Farry: Have there been other resignations since that period? Put another way, has there been any noticeable spike in the number of resignations, even if at this stage they have not given a reason? Has there been an uplift in the level of resignations since the data breach?
Assistant Chief Constable Chris Todd: No, not in terms of resignations. The other indicators that we are monitoring are things like sickness levels. We have seen an increase in sickness levels over the last period. It went up very slightly—only one up on the previous week—but 54 of the people who are currently sick are identifying the data breach as an impact factor, which is up five from the previous week. So there is a slight increase there.
Q159 Stephen Farry: You also set out a very challenging figure in terms of what this might ultimately cost the public purse over all the different components. Obviously, that is going to be spread out over a period of time; it is not going to all hit the organisation at once. But do you have a sense of what is likely to hit in this current financial year—to give a sense of the immediacy of the crisis—setting aside the other pressures that the organisation is under financially?
Assistant Chief Constable Chris Todd: The immediate impact would be the recovery costs. That is something that I absolutely want to see delivered within this year. Ideally, I would like to deliver something tangible to all of my colleagues today, if it was in my gift to give—be that a universal offer around personal security measures regardless of threat. But I have to work through the processes. Certainly, that recovery cost needs to be within year, and that is £24 million to £37 million.
Q160 Stephen Farry: I respect that this is probably a better conversation to be had in private with the federation, IPSA and others, but in very broad terms, is that something that is likely to happen on an individually assessed basis for every single person, or is it possible to do it on more of a block categorisation basis? That may make the process move a little bit quicker.
Assistant Chief Constable Chris Todd: Our established practices, processes and policies enable us to deal with specific threats and needs. If there was somebody who was subject to an identified threat, we would deal with that, and our budget allows us to deal with that. For example, we have a budget that enables us to deal with the number of people who need to be SPED potentially every year. That is built into our grant, or the way in which we use our grant. This would be beyond that.
Personally, I would like to see exceptional circumstances recognised in this case and something to offer all our colleagues, because the perceptions become reality, and the impact on all our colleagues is notable. I know that a lot of people are feeling frustration, anxiety and anger as a result. We owe it to all our colleagues to do whatever we can in these circumstances. I have to caveat that, however: I cannot promise what is not within my gift to give.
Q161 Stephen Farry: To help your case, I invite you to elaborate a little on the funding mix that the PSNI receives. The vast majority comes from the block grant, but there is also the additional security funding, which is a discrete package that has been flatlined for the past number of years. There is recognition of a residual NIO/UK Government responsibility, with certain elements of counter-terrorism being reserved, rather than being in the devolved space. The key threat here is a terrorism threat, which is deemed to be a national security issue for the UK Government. To what extent is that factor playing into how you approach this and in how you talk to the NIO about how this is to be addressed?
Assistant Chief Constable Chris Todd: That is clearly part of the conversation. As you say, the additional security funding is very specific to the NIO. It is something that is dealt with year in, year out, at different times of the year. No doubt we will be refreshing that regardless. I am hopeful that there will be conversations that are specifically relevant to the impact of this data breach that will influence some of that. Again, that is not grant funding, but ASF, as you articulated.
Chair: Assistant Chief Constable, thank you for your time. We appreciate the huge amount of work going on within the organisation. It is good of you to have taken the time to fly over and to absent yourself from that important work in order to answer our questions. We are grateful to you for that. We look forward to keeping over the detail as this evolves and, hopefully, as those questions get answered as quickly as possible so as to restore—as Mr Hart and others have suggested—trust and confidence from the general public and the confidence of those who work under the banner of the PSNI that they and their families are safe, and that due diligence is being followed.
Thank you for your time, and we wish you well with your work. Doubtless, we will hear from you or someone else from the PSNI in the not-too-distant future. In the meantime, thank you very much.