HRreview Header

Some HR and payroll systems could be affected by the Heartbleed bug

-

shutterstock_130285649

Security experts have advised that the Heartbleed computer bug risks extend beyond just websites and are warning UK SMBs to check that their HR and payroll software is not at risk. Using vulnerable OpenSSL code which may be found in some SaaS (software as a service) or online web platforms, the widespread bug could enable hackers to compromise systems undetected and collect sensitive personal and financial data and even the decryption keys themselves.

With HR systems holding personal information such as bank details, passport numbers and payroll information, companies need to ensure this data is secure. Paul Beaumont, Managing Director of Octopus HR, says: “It is vital to know that your software provider takes its responsibility to security seriously and invests accordingly. Octopus HR invests heavily in the security infrastructure around its system and has been unaffected by the Heartbleed bug which, whilst hitting the headlines now, has actually been around for the last two years.”

“While I’m pleased to say that Octopus HR has not been affected by this security flaw there may, however, be some providers whose software has been vulnerable to an attack. Organisations that use a SaaS HR system are strongly advised to check with their provider whether their HR system is hosted on servers having used any of the affected versions of OpenSSL. If it does, they have been, and still are, vulnerable to hackers.”

 

HRreview Logo

Get our essential daily HR news and updates.

This field is for validation purposes and should be left unchanged.
Weekday HR updates. Unsubscribe anytime.
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

 

“Companies whose providers are using OpenSSL will have been susceptible to an attack so all users with access to the system will need to change their passwords. However, it is important to check that the software provider has implemented all required security patches and revised their SSL certificates first or any new login details will also be at risk.”

Organisations can check to see whether their provider uses OpenSSL by pasting the URL used to login to the system (beginning withhttps://) into a free online tool.

Latest news

Middle East air disruption leaves UK staff stranded as employers weigh pay and absence decisions

Employers face complex decisions on pay, leave and remote working as travel disruption leaves British staff stranded in the Middle East.

Govt launches gender pay gap and menopause action plans to help women ‘thrive at work’

Employers are encouraged to publish action plans to reduce pay disparities and support staff experiencing menopause under new government measures.

Call for stronger professional standards to rebuild trust in jobs

Professional bodies call for stronger standards and Chartered status to improve trust, accountability and consistency across roles.

Modulr partners with HiBob to streamline payroll payments

Partnership integrates payments automation into payroll workflows to reduce manual processing and improve pay day reliability.
- Advertisement -

Jake Young: Strong workplace connections are the foundation of good leadership

Effective leaders are, understandably, viewed as key to organisational success. Good leaders are felt to improve employee engagement, productivity and retention.

AI reshapes finance jobs as entry-level roles come under pressure

Employers prioritise digital skills over traditional accounting as AI reshapes finance roles and raises concerns over entry-level opportunities.

Must read

Paul Russell: Soft skills – 8 focus areas for happier employees

If we want to keep our best people happy, then we need to think beyond the payroll and the purse. We need to think about hearts and minds.

Megan Peppin: We are all talent

I struggle somewhat with the term talent and have...
- Advertisement -

You might also likeRELATED
Recommended to you