London Daily

Focus on the big picture.
Saturday, Feb 22, 2025

Bank of England audio leak followed loss of key cybersecurity staff

Bank of England audio leak followed loss of key cybersecurity staff

Exclusive: former employees say at least 20 security staff were reassigned or left in past year
The Bank of England restructured its security department and lost multiple senior employees in charge of protecting some of Britain’s most critical financial infrastructure shortly before it suffered a major breach, the Observer can reveal.

After the central bank admitted that hedge funds had gained early access to its market-moving press conferences via a backup audio feed, multiple former employees contacted the Observer to warn that the Bank was struggling with the departure of key staff responsible for protecting it against external threats.

The sources said at least 20 of the Bank’s staff tasked with information security had left or been reassigned elsewhere within the bank within the past year, raising questions over the protection of the nation’s payment systems and other critical infrastructure vital for the British financial system. The Observer was able to verify 13 of these departures using information from social media and other sources.

The revelations come at a sensitive time for the Bank as it prepares for the handover of power in March from Mark Carney, the outgoing governor, to Andrew Bailey, the current chief executive of the Financial Conduct Authority.

Threadneedle Street has also played a central role in efforts to improve the safety and integrity of the financial system since the 2008 banking collapse, including warning the industry to improve its cyber and information security operations. It is responsible for key parts of the nation’s critical infrastructure, including the payments systems that carry every bank transfer made in Britain, the wages of millions of people, cheques, and payments between businesses of all sizes. On an average day in 2018, the Bank’s real-time gross settlement system (RTGS) settled transactions worth £651bn.

According to the former employees, the Bank’s chief information security officer and two deputies have left in the past year.

Multiple former employees described the organisation as beset by budget cuts before Carney’s departure, against a backdrop of concerns over cost efficiency. They said there were problems with staffing given the departures and low staff morale.

Much of the disquiet stemmed from a move to dismantle the Bank’s “security and privacy” directorate, the people said. The team, part of the central services division, previously had oversight over cyber, personnel and physical security matters, as well as privacy. Staff and responsibilities were instead spread across other parts of the organisation.

It is understood that many of the people now sit under the Bank’s technology, security and risk directorates, in a move designed to make the organisation safer. The Bank has about 70 cybersecurity professionals.

A Bank of England spokeswoman said: “The Bank operates the highest standard of information security and is confident in our ability to recognise cyber threats and defend our systems appropriately. Earlier this year, the Bank completed a review of its central services target operating model and, as part of that, reinforced the arrangements for first- and second-line information security. This change was fully supported by the Bank’s audit and risk committee.”

The Bank admitted late on Wednesday night that it had suffered a security breach, with a provider of a backup audio feed of the governor’s market-sensitive press conferences selling early access to unnamed investors without its knowledge. Those investors could have used the few seconds’ advantage to profit.

It was alerted to the breach by the Times newspaper, conducted a rapid internal investigation and passed the matter to the FCA. The City watchdog has confirmed it is investigating the issue, and it is understood that Bailey will recuse himself from all discussions of the matter to avoid any suggestion of a conflict of interest.

The Bank’s chief operating officer, Joanna Place, is the most senior manager responsible for physical and information security, and faced calls to resign from a former member of the Bank’s monetary policy committee, Danny Blanchflower, following the breach. Place, who was appointed in July 2017, reports directly to the governor, and has an equal status to the Bank’s deputy governors.

Multiple sources said the Bank was under pressure to cut the budget of the central services division, which was managed by Place. They said the government spending watchdog, the National Audit Office, warned in December 2018 that the Bank needed to deliver better value for money.

Place told the Commons’ public accounts committee in January that the Bank did not “have any gaps in cybersecurity”. However, her chief information security officer, Cameron “Buck” Rogers, resigned little over a month later. Multiple other security experts followed him.

A spokeswoman for the Bank said Rogers resigned on 23 February and that Place was not aware he was going to quit when she gave evidence on 21 January.

At the hearing, Meg Hillier, the Labour chair of the committee, expressed surprise at Place’s answer, given the difficulties other public-sector organisations had with recruiting and retaining cyber security staff, and asked again if there were any vacancies.

Place responded: “Offhand, I do not know whether we have any vacancies, but we do not have a problem with recruiting and we do not have a problem with retention in cyber, either.”

There was widespread unease within the Bank following her testimony, multiple sources said, and in the months after her appearance the cybersecurity function suffered the outflow of staff.

The public sector struggles to retain staff in cybersecurity roles because of intense competition from the higher-paying private sector. However, the reputation of the Bank and its important role in protecting financial stability are attractive for potential candidates, and the sources said they believed it was in the public interest to shed light on the problems it was facing.

A Bank of England spokesperson said: “The incident relating to the misuse of a backup audio feed from the Bank’s press conferences by a third-party supplier, which the Bank has referred to the Financial Conduct Authority for further investigation, was not a cyber security issue.”
Newsletter

Related Articles

0:00
0:00
Close
UK Prison Officer Sentenced for Inappropriate Conduct with Inmate
Good News: Senate Confirms Kash Patel as FBI Director
Officials from the U.S. and Hungary Engage in Talks on Economic Collaboration and Sanctions Strategy
James Bond Franchise Transitions to Amazon MGM Studios
Technology Giants Ramp Up Lobbying Initiatives Against Strict EU Regulations
Alibaba Exceeds Quarterly Projections Fueled by Growth in Cloud and AI
Tequila Sector Faces Surplus Crisis as Agave Prices Dive Sharply
Residents of Flintshire Mobile Home Park Grapple with Maintenance Issues and Uncertain Future
Ronan Keating Criticizes Irish Justice System Following Fatal Crash Involving His Brother
Gordon Ramsay's Lucky Cat Restaurant Faces Unprecedented Theft
Israeli Family Mourns Loss of Peace Advocate Oded Lifschitz as Body Returned from Gaza
Former UK Defense Chief Calls for Enhanced European Support for Ukraine
Pope Francis Admitted to Hospital in Rome Amid Rising Succession Speculation
Senate Republican Leader Mitch McConnell, at the age of 83, Declares His Retirement.
Whistleblower Reveals Whitehall’s Focus on Kabul Animal Airlift Amid Crisis
Politicians Who Deliberately Lie Could Face Removal from Office in Wales
Scottish Labour Faces Challenges Ahead of 2026 Holyrood Elections
Leftwing Activists Less Likely to Work with Political Rivals, Study Finds
Boris Johnson to Host 'An Evening with Boris Johnson' at Edinburgh's Usher Hall
Planned Change in British Citizenship Rules Faces First Legal Challenge
Northumberland Postal Worker Sentenced for Sexual Assaults During Deliveries
British Journalist Missing in Brazil for 11 Days
Tesco Fixes Website Glitch That Disrupted Online Grocery Orders
Amnesty International Critiques UK's Predictive Policing Practices
Burglar Jailed After Falling into Home-Made Trap in Blyth
Sellafield Nuclear Site Exits Special Measures for Physical Security Amid Ongoing Cybersecurity Concerns
Avian Influenza Impact on Seals in Norfolk: Four Deaths Confirmed
First Arrest Under Scotland's Abortion Clinic Buffer Zone Law Amidst International Controversy
Meghan Markle Rebrands Lifestyle Venture as 'As Ever' Ahead of Netflix Series Launch
Inter-Island Ferry Services Between Guernsey and Jersey Set to Expand
Significant Proportion of Cancer Patients in England and Wales Not Receiving Recommended Treatments
Final Consultation Launched for Vyrnwy Frankton Power Line Project
Drug Misuse Deaths in Scotland Rise by 12% in 2023
Failed £100 Million Cocaine Smuggling Operation in the Scottish Highlands
Central Cee Equals MOBO Awards Record; Bashy and Ayra Starr Among Top Honorees
EastEnders: Four Decades of Challenging Social Norms
Jonathan Bailey Channels 'Succession' in Bold Richard II Performance
Northern Ireland's First Astronaut Engages in Rigorous Spacewalk Training
Former Postman Sentenced for Series of Sexual Offences in Northumberland
Record Surge in Anti-Muslim Hate Crimes Across the UK in 2024
Omagh Bombing Inquiry Concludes Commemorative Hearings with Survivor Testimonies
UK Government Introduces 'Ronan's Law' to Combat Online Knife Sales to Minors
Metal Detectorists Unearth 15th-Century Coin Hoard in Scottish Borders
Woman Charged in 1978 Death of Five-Year-Old Girl in South London
Expanding Sinkhole in Godstone, Surrey, Forces Evacuations and Road Closures
Bangor University Announces Plans to Cut 200 Jobs Amid £15 Million Savings Target
British Journalist Charlotte Peet Reported Missing in Brazil
UK Inflation Rises to 3% in January Amid Higher Food Prices and School Fees
Starmer Defends Zelensky Amidst Trump's 'Dictator' Allegation
Zelensky Calls on World Leaders to Back Peace Efforts in Light of Strains with Trump
×