Therefore in what was seemingly Scotland’s most high profile criminal investigation involving the control, and misuse of funding, money and assets linked to Scotland’s governing party, the Scottish National Party – sources have now claimed those tasked with investigating allegations of fraud linked to the SNP and it’s former Chief Executive Peter Murrell, now convicted and jailed for the theft, embezzlement of over £400,000 of party funds – may well have been profiled by parties with an interest in limiting the scope of the Police investigation and evidence consideration, advice obtained from outside elements contracted into Operation Branchform.
A Freedom of Information request, and subsequent response from Police Scotland – places Scotland’s national Police service in the position of refusing to confirm or deny claims from insiders and legal sources that officers and others linked to the Branchform investigation, were profiled to an extent the information gathered may well have been used by interested parties within the investigation to influence how the consideration of evidence and where it led during the Branchform progressed, or at times slowed, then allegedly in certain instances came to a halt on the orders of prosecutors.
Claims by insiders and whistleblowers tell an interesting alternative to the unbelievable, almost fictional accounts in parts given by the same media-dealing prosecuting authority & Police service which rigged cases against the Rangers Administrators, yet took five years to claim there was not enough evidence to prosecute a collection of financiers, lawyers & individuals linked to the judiciary in the £400 Million Heather Capital Fraud.
An alternative version by insiders reveals instead how parts of evidence and claims were only followed up to a certain degree, how the Crown Office system of ‘independent Crown Counsel’ often known for their ability to rip out swathes of evidence and material often coincidentally protecting high profile figures from charges and trials did their usual and excluded damaging material linking to the highest politicians in Government, and how what was billed as an expected Criminal Trial exposing industrial scale of theft, fraud & dishonesty at the heart of political power in Scotland, ended in a whimper of a guilty plea at the last minute and comments in sentencing which to be honest, read to any experienced [and unafraid for their continued employment] fraud investigator about as straight as a roundabout.
Police Scotland even dragged out exemptions in relation to National Security, and Terrorism laws to refuse to confirm or deny claims made to journalists in relation to the internal workings of Operation Branchform, as noted in the lengthy FOI response from Police Scotland which is republished below, in text format and in original PDF format here: 26-1631 Response
Your recent request for information is replicated below, together with our response.from July 2021 to the date of this FOI request
I would like to make a Freedom of Information request for information contained in
the numbers of incidents (and details contained in) of any reporting, logging, complaint raise awareness of, or similar from Police Officers and staff employed by or contracted by Police Scotland - that their work emails & communication methods or other were hacked, compromised or accessed by others known or unknown
If any of the above involved investigations with an operational designation - such as "Operation Branchform" and "Operation Newbiggin"
and if any incidents were reported to Police Scotland's anti corruption unit and if so, what action if any was taken
In terms of section 18 of the Act, I am refusing to confirm or deny whether the information sought exists or is held by Police Scotland.
Section 18 applies where the following two conditions are met:
- It would be contrary to the public interest to reveal whether the information is held. Confirmation or otherwise would prove valuable to those with criminal intent as this information could be used to identify and take advantage of any potential vulnerabilities in the police systems, consequently increasing the risk of cyber-attacks Force wide.
- If the information was held, it would be exempt from disclosure in terms of one or more of the exemptions set out in sections 28 to 35, 38, 39(1) or 41 of the Act. In this instance, the following exemptions are considered relevant:
• Section 34(1)(b) - Investigations
Information is exempt information if it is held by Police Scotland for the purposes of an investigation which may lead to a decision to report the circumstances to the Crown
Office and Procurator Fiscal Service (COPFS) to enable a determination on whether criminal proceedings should be instigated.
• Section 31(1) - National Security and Defence
• Section 35(1)(a)&(b) - Law Enforcement
• Section 39(1) - Health & Safety
The security of the United Kingdom is of paramount importance, and we will not disclose information if it would impact on National Security.
Information is exempt information if its disclosure under the Act would substantially prejudice the prevention and detection of crime and the apprehension and prosecution of offenders by adversely impacting on the operational effectiveness of Police Scotland.
Information is also exempt information if its disclosure under the Act would, or would be likely to, endanger the physical or mental health or the safety of an individual.
Disclosure of information relating to invasive cyber security incidents (especially the extent to which they were effective) would highlight any perceived vulnerabilities in systems essential for day-to-day operations, enabling criminals to make an accurate assessment of the capacity of the Service to deal with a variety of any such incidents.
The release of such thorough and specific information would undermine the operational integrity and security of integral police systems by giving those with criminal intent (including terrorists) the opportunity to compromise or exploit these systems to their own benefit, resulting in a loss of sensitive police data or denying the Police Service access to critical infrastructure systems.
As such, to release this would present a real and significant risk to policing operations, public safety and the ability of the police service to efficiently prevent and detect crime.
The above are all non-absolute exemptions and require the application of the Public Interest Test.
Whilst I accept that investigations concerning cyber security would be of significant interest to the public, investigative details will only ever be disclosed by Police Scotland where there are overwhelming public interest considerations for doing so.
That said, there can be no public interest in disclosing information which relates to police investigations outwith the associated criminal justice processes, thereby prejudicing those processes (and the Force’s future law enforcement at large).
On balance, it is considered that the public interest lies in maintaining the section 34(1)(b) exemption given the need to protect the integrity of the investigative process and any final determinations made by the COPFS.
Furthermore, while it can also be suggested that there is a public interest in openness and transparency as regards the security arrangements Police Scotland has in place for protecting its fundamental policing processes, this must be balanced against the strong public interest in maintaining the security and effectiveness of the systems used to do so.
I would contend that the need to ensure the effective conduct of the Service in relation to the prevention and detection of crime, and the public safety considerations involved in the delivery of operational policing, clearly favour non-disclosure of the information.
Technological information is of great value, and, in this instance, it can be argued that the disclosure of any such information would provide limited additional public understanding while simultaneously creating a substantial risk to cyber security - it is therefore reasonable to expect Police Scotland ensure all information held is managed effectively, and where necessary, are cautious of the level of detail released to the public.
On balance, the public interest in withholding the information on this occasion outweighs the public interest in disclosure.
This explanation should not be taken as indicative or conclusive evidence that the information you have requested does or does not exist.
and information contained in the processes used by Police Scotland for staff & Police Officers and contractors to log, report, complain or raise awareness of any such incidents of email and communications hacking, or accessed by others known or unknown
Firstly, I can advise that under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, a personal data breach must promptly be assessed to determine whether it is likely to result in a risk to the rights and freedoms of individuals - where this threshold is met, a notification to the Information Commissioner’s Office (ICO) must be made without undue delay and, where feasible, within 72 hours of Police Scotland becoming aware of the breach.
Where the breach is likely to result in a high risk to individuals’ rights and freedoms, a notification to the affected individuals must also be considered.
This reporting timescale requires security incidents to be managed in a timely manner, including early containment, evidence gathering and documented risk assessment.
For this reason, staff are advised that it is essential to promptly detect, contain and assess any data breach for potential risks to both the Police Service of Scotland and individuals’ rights and freedoms. The practices used to ensure this include (but are not limited to) using the designated email address to report phishing, reporting incidents direct to the ISO via the Information Security Reporting Form and referring to the relevant guidance/ Standard Operating Procedures (SOPs).
In this case, I can refer you to the Information Security Standard Operating Procedure, which outlines how all staff, contractors and partners (i.e. anyone with access to police information or premises) protect the confidentiality, integrity and availability of Information Assets and Information Systems.
Moreover, these precautions behaviours are further embedded and strengthen by an annual Data Protection Refresher Course, Cyber Exercises (i.e. simulated cyber-attack exercises to test the organisation’s incident response capabilities, improve readiness, and identify any areas for improvement) and Cyber Awareness Courses.
For awareness, there are currently six courses out in rotation, which includes:
• Cyber Fundamentals - this course covers what to watch out for at work and how to keep yourself safe against common threats.
• Phishing Awareness - this course covers what a phishing email is, how to spot them and how to report them.
• Physical Security - this course covers the measures taken by Police Scotland to protect operations through denying access to buildings, restricting permissions to certain activities and establishing secure work environments.
• Security Incidents - this course covers cyber security incidents that have already taken place within Police Scotland and highlights what you can do to avoid a repeat scenario.
• Password Management - this course covers how to create and improve the security of your chosen password.
• Device Security - this course covers how to handle and protect sensitive information on your devices.
• Social Engineering - this course covers some common social engineering techniques, and guidance on how to stay safe.
ENDS
Clearly, Police Scotland feel strongly in the matter and they cannot admit or deny any of these events as referred to in the FOI request occurred.
However when the Freedom of Information disclosure, and denial was put to sources for their own consideration, their responses indicated that not only did it appear officers were indeed profiled by interested parties linked to the Branchform investigation, it could also not be ruled out informants from within policing passed information to organisations and persons of interest in Operation Branchform which allowed external elements to the investigation to be aware of the pace and direction of evidence gathering, and key events before they even occurred.
Operation Branchform became a matter of interest to journalists in ways perhaps not to the liking of the investigating authorities and those who were being investigated.
For example, on a very similar, almost identical case of systemic and determined acts of fraud, carried out within a governing political party with an almost stasi like grip on controlling a nation’s public authorities, institutions and organisations – a few individuals were tasked with making numerous purchases of just about anything which comes to mind – stationery, confectionery, watches and jewellery, vehicles, property, crypto assets and more – with the sole intent of these purchases and overly unaccountable lifestyles being used as a cover to later be held up for detection, prosecution and finally a day or two in court for headlines as the smokescreen to a much larger multi millions fraud which enabled governing party members to enjoy lifestyles, assets and undetectable offshore finances in a manner which could not be explained by their official salaries and expenses claims.
A journalist colleague who was not connected to the investigation we worked on, but was shown some of our material and files received from case participants said at the time – should be looking for four hundred million, not the twenty or thirty million mentioned in a civil recovery case – which itself collapsed after prosecuting authorities and certain legal figures who wanted the case halted, intervened in the background and saw to it the civil recovery case collapsed.
Another issue raised with us in relation to Operation Branchform revealed sweet deals with media orgs, after a media colleague produced an audio clip revealing their enquiries with Police media assets seeking an agreement to gain access to evidence in relation to the charges against Peter Murrell, post guilty plea and trial – resulted in a demand and agreement for not seeking access to the Nicola Sturgeon interview and materials – which are now being sought for release via Freedom of Information requests to Police Scotland
Police Scotland, and the Crown Office are for now curiously blocking release of the full Police Scotland interview with Nicola Sturgeon after she was arrested on a Sunday after a Police Scotland visit to the house filled with items purchased with ‘stolen’ SNP funds, the address being the same residence she shared with her then husband, Peter Murrell.
No comments:
Post a Comment