---
title: "TalkTalk data breach: CEO can’t actually talk about the hack!"
description: TalkTalk CEO Dido Harding appeared before the Culture Media and Sport parliamentary select committee to answer questions on the hacking of the company.
image: https://blog.wallix.com/hubfs/VISUELS_BLOG/iStock_000074014843_Medium.jpg
---

[![Wallix](https://blog.wallix.com/hs-fs/hubfs/LOGO_WALLIX_2024_black+orange-3.png?width=3108&height=827&name=LOGO_WALLIX_2024_black+orange-3.png "Wallix")](http://www.wallix.com/)

[![New Call-to-action](https://no-cache.hubspot.com/cta/default/514643/6f69a618-d11c-44ef-ad26-88703b7dcab4.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/6f69a618-d11c-44ef-ad26-88703b7dcab4)

# TalkTalk data breach: CEO can’t actually talk about the hack!

[› › › BACK TO THE BLOG](https://blog.wallix.com)

 \[fa icon="calendar"\] Dec 17, 2015 6:36:20 PM / by [WALLIX](https://blog.wallix.com/author/wallix)

![](https://blog.wallix.com/hs-fs/hubfs/blog-files/WALLIX.png?width=35&name=WALLIX.png)

- [Tweet](https://twitter.com/share)

![hack-breach-origin-access-traceability.jpg](https://blog.wallix.com/hs-fs/hubfs/VISUELS_BLOG/iStock_000074014843_Medium.jpg?width=640&name=iStock_000074014843_Medium.jpg "hack-breach-origin-access-traceability.jpg")  
On Tuesday **TalkTalk CEO Dido Harding** appeared before the [Culture Media and Sport](http://www.parliament.uk/business/committees/committees-a-z/commons-select/culture-media-and-sport-committee/) parliamentary select committee to answer questions on the recent [hacking of customer data](https://blog.wallix.com/bad-privileged-access-management-at-the-root-of-vtech-woes) from the company. The committee began by pressing Harding on who has responsibility for security at TalkTalk, her response was emphatically that security is a “board level issue” and that ultimately the buck stops with her. 

# Clear confusion about different types of IT security

---

 

One issue that was highlighted during questioning was the relationship between TalkTalk’s data and how it’s accessed by [third party suppliers](https://blog.wallix.com/aviva-revenge-hack-highlights-the-risk-from-third-party-vendors). This has already been the cause of a number of breaches, yet MPs did not ask deeper questions about the nature of these breaches and **how TalkTalk secures how third party suppliers access and use their data.**

[Jesse Norman MP](https://en.wikipedia.org/wiki/Jesse_Norman), who chairs the committee was interested in getting answers on the cause and nature of the hack, and he had done his research.  He speculated (as has been widely reported in the media) that this was an SQL injection attack and surely was preventable if the web servers hosting the SQL database were correctly secured. For many of us, these questions where the ones we were really interested in hearing an answer to. **What was the precise nature of this attack?** And why had TalkTalk not done a better job of preventing it?  Those of us who wanted those answers were disappointed. Harding immediately referred to the active police investigation and is therefore conveniently unable to give details on the hack. She was also very keen to make sure that the committee is aware that this attack was not simple, describing it as “multifaceted” and that the hackers managed to find “a needle in a haystack of haystacks”.

Cyber security is now TalkTalk’s number one risk (easy to say after you’ve been hacked) and spending on information security has risen in the company and will continue to rise. Harding outlined investments that had been made in DLP and encryption. But there was no mention of **improving access control** in any way. You would expect given the concerns around what hackers can do once inside and the clear issues raised by working with third parties that there might be more action in this area.

 

[![Get Access to our White paper : Managing your IT providers](https://no-cache.hubspot.com/cta/default/514643/5c8ff6a3-9ed7-409b-b67a-5917c4bf7d52.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/5c8ff6a3-9ed7-409b-b67a-5917c4bf7d52)

![WALLIX](https://blog.wallix.com/hs-fs/hubfs/blog-files/WALLIX.png?width=100&height=100&name=WALLIX.png)

#### Written by [WALLIX](https://blog.wallix.com/author/wallix)

### SIGN UP to receive our best articles!

## [![Get Access to our white paper : The Insider Threats Comic Book](https://no-cache.hubspot.com/cta/default/514643/21e4442a-b1c5-4e98-a7c1-54de89072624.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/21e4442a-b1c5-4e98-a7c1-54de89072624)

- Recent
- Popular
- Categories

### Lists by Topic

- [Preventing Insider Threat (91)](https://blog.wallix.com/topic/preventing-insider-threat)
- [Mitigating External Attacks (81)](https://blog.wallix.com/topic/mitigating-external-attacks)
- [Reaching IT Compliance (58)](https://blog.wallix.com/topic/reaching-it-compliance)
- [Controlling Third Party Access (33)](https://blog.wallix.com/topic/controlling-third-party-access)
- [WALLIX Products (29)](https://blog.wallix.com/topic/wallix-products)
- [Optimizing Cyber-Insurance (15)](https://blog.wallix.com/topic/optimizing-cyber-insurance)
- [Improving Cybersecurity (8)](https://blog.wallix.com/topic/improving-cybersecurity)
- [Cloud Security (4)](https://blog.wallix.com/topic/cloud-security)
- [Events (2)](https://blog.wallix.com/topic/events)

[![Get Access to our White paper : Major misconceptions about IT security](https://no-cache.hubspot.com/cta/default/514643/ce3632c6-744e-4bca-919e-6795f7c73b63.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/ce3632c6-744e-4bca-919e-6795f7c73b63)

### Posts by Topic

- [Preventing Insider Threat (91)](https://blog.wallix.com/topic/preventing-insider-threat)
- [Mitigating External Attacks (81)](https://blog.wallix.com/topic/mitigating-external-attacks)
- [Reaching IT Compliance (58)](https://blog.wallix.com/topic/reaching-it-compliance)
- [Controlling Third Party Access (33)](https://blog.wallix.com/topic/controlling-third-party-access)
- [WALLIX Products (29)](https://blog.wallix.com/topic/wallix-products)
- [Optimizing Cyber-Insurance (15)](https://blog.wallix.com/topic/optimizing-cyber-insurance)
- [Improving Cybersecurity (8)](https://blog.wallix.com/topic/improving-cybersecurity)
- [Cloud Security (4)](https://blog.wallix.com/topic/cloud-security)
- [Events (2)](https://blog.wallix.com/topic/events)

see all

#### About Us

WALLIX is a software company offering privileged access management solutions to help enterprises, public organizations and cloud service providers protect their critical IT assets including data, servers, terminals and connected devices.

#### More Links

- [Homepage](http://www.wallix.com/)
- [Blog](https://blog.wallix.com/)
- [Wallix](http://www.wallix.com/company/)

#### Contact us

\[fa icon="phone"\] [Get the right number](http://www.wallix.com/contact/)

\[fa icon="envelope"\] [sales@wallix.com](mailto:sales@wallix.com)

\[fa icon="home"\] [Find the right location](http://www.wallix.com/contact/)

#### Follow Us

<https://twitter.com/wallixcom><https://www.linkedin.com/company/wallix><https://www.youtube.com/channel/UCKT58VqricukJJxBTlLonAw>

 Copyright® 2026 | Wallix - Trace, Audit & Trust

\[fa icon="chevron-up"\]

![](https://googleads.g.doubleclick.net/pagead/viewthroughconversion/880438901/?value=0&guid=ON&script=0)