Some HR and payroll systems could be affected by the Heartbleed bug

-

shutterstock_130285649

Security experts have advised that the Heartbleed computer bug risks extend beyond just websites and are warning UK SMBs to check that their HR and payroll software is not at risk. Using vulnerable OpenSSL code which may be found in some SaaS (software as a service) or online web platforms, the widespread bug could enable hackers to compromise systems undetected and collect sensitive personal and financial data and even the decryption keys themselves.

With HR systems holding personal information such as bank details, passport numbers and payroll information, companies need to ensure this data is secure. Paul Beaumont, Managing Director of Octopus HR, says: “It is vital to know that your software provider takes its responsibility to security seriously and invests accordingly. Octopus HR invests heavily in the security infrastructure around its system and has been unaffected by the Heartbleed bug which, whilst hitting the headlines now, has actually been around for the last two years.”

“While I’m pleased to say that Octopus HR has not been affected by this security flaw there may, however, be some providers whose software has been vulnerable to an attack. Organisations that use a SaaS HR system are strongly advised to check with their provider whether their HR system is hosted on servers having used any of the affected versions of OpenSSL. If it does, they have been, and still are, vulnerable to hackers.”

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

“Companies whose providers are using OpenSSL will have been susceptible to an attack so all users with access to the system will need to change their passwords. However, it is important to check that the software provider has implemented all required security patches and revised their SSL certificates first or any new login details will also be at risk.”

Organisations can check to see whether their provider uses OpenSSL by pasting the URL used to login to the system (beginning withhttps://) into a free online tool.

Latest news

Sustainable business starts with people, not HR policies

Why long-term success depends on supporting employees, not just meeting ESG targets, with practical steps for leaders to build healthier organisations.

Hiring steadies but Gulf crisis threatens recovery in UK jobs market

UK hiring shows signs of stabilising, but rising global uncertainty linked to the Gulf crisis is weighing on employer confidence and delaying recovery.

Women ‘face career setback’ risk with flexible working

Female staff using remote or reduced-hour arrangements more likely to move into lower-status roles, raising concerns about bias in career progression.

Jo Kansagra: Make work benefits work for Gen Z

Gen Z employees are entering the workforce at full steam, and yet many workplace benefits schemes are firmly stuck in the past.
- Advertisement -

Union access plans risk straining workplace relations, CIPD warns

Proposed rules on workplace access raise concerns about employer readiness and operational strain.

Petra Wilton on managers struggling with new workplace laws

“Managers are not being given the tools they need to fully understand how the rules of the workplace are changing.”

Must read

Martin Corry: Best practices for UK Right to Work checks – minimising risk and maximising efficiency

Effective Right to Work compliance is a strategic imperative for HR teams across diverse sectors, even in volatile business environments.

Jason Andersen: How can AI change the face of employee recognition?

AI is taking employee recognition to the next level. It’s transforming how organisations recognise their peoples’ efforts, results and career milestones.
- Advertisement -

You might also likeRELATED
Recommended to you