Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Friday, 15 September 2017

VMworld Europe 2017 - General Session Keynote

I attended my second VMworld this year, which you may find odd as I rarely blog about virtualisation or VMware.  VMware is changing and security is now more apparent in the solutions and roadmap.  

On Tuesday 12th September, we had a General Session Keynote from Pat Gelsinger - VMware CEO.

The VMware vision was similar to the previous year, but there are new partnerships with telcos, moving the telco networks closer to cloud, as well as the growth of IoT.


Gelsinger talked about the mix of devices, applications, and platforms causing the core challenge.  There needs to be anywhere access for people to the applications, but it's complicated.  There is a mass of devices, applications, services and security.

He is only reiterating the challenges securities have been facing for a number of years, with the increase in Shadow IT, less complimentary but highly connected applications, and uncertainty of any associated security.


Workspace One is the solution, grown from AirWatch to supporting iOS, to work with many more operating systems, including Google Chrome.  


MDM (Mobile Device Management) solutions have had to grow into EMM (Enterprise Mobility Management) solutions, w here it's no longer just the management of the device, but also the applications, the content, the availability and in my world, the identity and security.

Gelsinger moved to security, highlighting the target has moved form just applications and data, to user infrastructure, including users and devices, but also cloud infrastructure of the network and compute, as these are seemingly under the control of the security team.




The gasps when some of the audience was shocked with this slide, where the security guys have been working with and understanding a number of different areas.  Security people know that security spend is increasing, but the cost of breaches are increasing even quicker.  As Gelsinger says, "your spending more and falling further behind", "something is broken" and "we the tech industry have failed you the customers".  "We need a new approach"



There needs to be move from infrastructure to secure infrastructure.  Security needs to be built in, not an after thought, as I have been saying for a number of years.  There needs to be an integrated ecosystem, leveraging quality solutions and products, where you do not excel.  All of this with cyber hygiene regime. 


I'm glad that a tech giant like VMware is embracing cyber security and embracing the areas, I believe are the most important.  The pillars of cyber hygiene are important for every environment.  

Least Privilege, Micro-segmentation, Encryption, Multi-Factor Authentication and Patching, have been evangelised by security experts for a number of years.  So great to these elements are now considered mainstream.


As expected the EU General Data Protection Regulation (EU GDPR) came up in the keynote, and of course VMware are able to support the regulation by securing the data, automating governance and secure operations.


Gelsinger introduced VMware AppDefense and how it helps the security challenge able to capture, detect and respond.


VMware approach is looking at the security challenges of a business, without the business itself becoming a security expert.

I think it's a very exciting time for a security person to be looking at VMware, and I'm glad I was at VMworld Europe 2017 to see this for myself.

For those unable to attend, the General Session is available to watch here: https://www.vmworld.com/en/europe/video/general-sessions.html (where I also got the screen grabs, as the photos didn't come out so well)

Friday, 26 May 2017

Exclusive Networks Takes GDPR Message on The Road [Link: CommsBusiness]

I was asked by our Distributor, Exclusive Networks and Vendor, Gemalto for a quote regarding a bus they were using to promote GDPR (General Data Protection Regulation).  This was published on the CommsBusiness website: http://commsbusiness.co.uk/news/exclusive-networks-takes-gdpr-message-on-the-road/

===========================================

Exclusive Networks and digital security company Gemalto are taking the GDPR message on the road. A refitted double-decker bus began its UK tour in York on 23rd May, finishing at Infosec in London on 6th June. The bus will be making stops at key regional centres where channel partners and customers can meet security experts from Exclusive Networks and Gemalto and hear how a six-step process can aid GDPR readiness and compliance.

According to Exclusive Networks’ vendor alliances director, Stuart Nairne-Clark “many partners are still confused and lack clear understanding on the whole GDPR topic and what it means for them and their customers. Because there is no silver bullet – it’s as much about people and process as it is technology – by coming aboard they’ll get first-hand guidance on what’s needed to become compliant. They will hear directly from Data Protection Officers, understand the essential legal requirement and see how the latest multi-factor authentication, encryption and key management tools aid GDPR compliance. Already large and small organisations from right across the commercial, public and charity sectors are booked on and given it’s such a comprehensive regulation we encourage all partners and their customers to sign-up. It’s the ideal setting to engage with compliance, data protection and encryption experts.”

Andrew Tang, service director – security, at reseller MTI noted that “being a GDPR Practitioner I appreciate there is no precedent for what is coming. Understanding both the regulation and its context is essential if partners are to work with their customers to build an effective GDPR strategy and plan. My customer meetings are now all GDPR related so having the bus clinic pass by the door of many customers, especially the 50% or so who are just beginning to get to grips with the subject, is invaluable. It is doubly invaluable when you consider the only technology set mentioned within the regulation is encryption, and that is something Gemalto does best.”

The Exclusive Networks and Gemalto GDPR Bus clinic will be stopping in York, Leeds (25/5), Chesterfield (26/5), Birmingham (30/5), Milton Keynes (31/5), Oxford (1/6), Reading (2/6), Alton (5/6) and London (6-8/6). Seats aboard the bus are pre-booked and partners can sign-up here. In addition, a survey is being conducted to gauge how far those affected by the regulation have progressed along the road to compliance.

Jason Hart, identity and protection CTO at Gemalto added: “With a year or so left until the regulation is enforced it is essential partners and customers cut through all the noise and understand what they need to do on their road to compliance. Plenty of reports show a general state of un-readiness and lack of understanding. By taking the issue on the road we can reach more partners and customers and get to explain how Gemalto’s data protection, encryption and identity authentication technologies are essential in securing compliance and avoiding crippling penalties.”

Tuesday, 6 December 2016

Cyber security in 2016 – why is it still not happening? [Link - ITProPortal]

I was asked to write an article reviewing the cyber security challenges for 2016, Here is the article that was published on the ITProPortal website: 

===================================

It's 2016, and businesses are generally still not taking security seriously.

Image source: Shutterstock/jijomathaidesigners

Perhaps the surprising, and damning, thing about 2016 in terms of security is that businesses are generally still not taking security seriously. Nobody wants to admit to being slack when it comes to cyber security, but the indisputable fact is that during 2016, many organisations simply didn’t show up, whatever they claimed.  

The basics are still not being done. Updates aren’t being applied, patching strategies are not in place, admin credentials are easy to find. Let’s be blunt, people are still trying to do security on the cheap, using, for example, free antivirus software.  This was most evident in the amount of ransomware that infected companies. 

A Trend Micro report claimed that 45 per cent of UK businesses were hit by ransomware this year. We believe the figure is much higher, closer to 60 or 70 per cent. 


Ransomware scourge


In the US, hospitals have paid massive amounts of money when their databases have been encrypted by ransomware. The Hollywood Presbyterian Medical Center paid a $17,000 bitcoin ransom for the decryption key for patient data. It was infected by the delivery of an email attachment disguised as a Microsoft Word invoice. In the UK some hospitals had to cancel operations.  

Hundreds of planned operations, outpatient appointments, and diagnostic procedures were put on hold at multiple hospitals across Lincolnshire.  The damage done by ransomware in 2016 is largely attributable to the infamous Locky and its many variants. It was first identified in February and made it to the top of the ransomware charts only two weeks later. 

It initially used malicious macros in Office documents to infect its victim’s computer, and these documents were distributed attached to spam emails. Locky has been through several versions since then. A new version was released on October 24, and less than 24 hours later yet another version was launched. It’s carried through phishing campaigns and the email subjects are centred on pay cheques, receipts, invoices, orders, or wrong credit card charges all of which are themes designed to fool recipients into opening attached files.   

Heads in the sand


In a sense it’s staggering that people are still falling for these tricks, given the exposure about ransomware dangers. There still seems to be a general mindset that ‘it will never happen to me’, when it clearly is happening to lots of businesses and individuals.  It’s frustrating because basic security measures offer protection. Being on the front line we tend to get a good sense of what is happening on the ground and it can be best summed up with the phrase ‘blind panic’ when a company is hit.  

But this lack of awareness, or ‘head in the sand’ scenario, is also playing out across other areas. Security in 2016 can also be defined by the large number of replay attacks that have taken place. Ransomware is included in this but it’s not exclusive. Yahoo is perhaps one of the biggest culprits. 

In 2012, a security breach exposed 450,000 usernames and passwords from a site on the huge web portal with the company failing to take even basic precautions to protect the data. Two years later it happened again with 500 million account details stolen.

Enormous DDoS attacks


Yahoo cried ‘state-sponsored actor’ in its defence but clearly it’s still not adequately protecting its customer data. This defence is usually code for ‘don’t blame us, it was a really sophisticated attack’. And Yahoo only came clean in 2016. These serious errors are clearly an illustration of some fundamental flaws at the online giant. Is it any wonder that it’s gone from an operation worth close to $100 million at its peak to today’s evaluation of $4.8 million? 

Another large 2016 security event, which ironically few noticed at the time, was the largest DDoS attack recorded, a whopping 540Gbps directed at public facing websites belonging to organisations affiliated with the 2016 Rio Olympics. These attacks were sustained, sophisticated, and actually started months before the Olympics began.  

These attacks were clearly aimed at the global stage and foreshadowed the equally massive IoT botnet based DDoS attacks which, in contrast, caught the attention of the mainstream media because they were launched from compromised everyday household devices such as internet connected video recorders and cameras.  

Plundering millions


The industry, at large has been warning about the parlous state of IoT security for some time, but it seems no one really wants to listen until an attack hits home and hurts bank balances.  

The Swift’s global payments network hack that resulted in $81 million being siphoned from Bangladesh central bank was also noteworthy due to the huge amounts of money involved.  Hackers also exploited the Swift system to steal a reported $10 million from an unnamed bank in Ukraine, while back in Bangladesh an eye watering $1 billion cyber theft was only stopped when an eagle-eyed employee spotted a typo. 

In an ironic way it’s almost fitting that a hack to see out 2016 was the attack on Tesco Bank. The company was forced to repay £2.5 million of losses to 9,000 customers in a heist described as ‘unprecedented’ by regulators. It may seem small when compared to the Swift system hacks but there’s worrying significance that the company apparently ignored warnings that its vulnerable software was being targeted by cyber criminals for months before the attack. What is just as shocking is that the bank didn’t even encourage two-factor authentication for its customers. 

How many more financial organisations are going to be nailed by cyber thieves before the message gets through? If the EU General Data Protection Regulation had been in force, which is due to come into effect in 2018, Tesco would have been hit by a fine up to £1.9bn. And who could say that Tesco and other organisations with terrifyingly lax cyber security wouldn’t deserve it?

Monday, 5 December 2016

Cyber-security in 2017 – brace yourself [Link - ITProPortal]

I was asked to gaze into my crystal ball and write a piece around the Cyber Security challenges for 2017.  Here is the article as it appeared on the ITProPortal website: 

=================================

If there’s one thing you can say with certainty about cyber-security in 2017, it’s that many companies are going to fail because they are simply not doing the right thing. Fundamental flaws still exist.

Image source: Shutterstock/jijomathaidesigners

It's about the business


Until the technical people lift their heads up and see that security and business are different sides of the same coin, we will inevitably see more damaging attacks. When security people learn to speak in the language of business they will begin to understand just where in the organisation they need to apply their expertise. 

This might be smart configuration options, cautious security policies, vigilance and a willingness to read server logs like some people read the newspaper in the morning to identify targeted attacks.  

Of course, this won’t stem the malware tsunami but it will help defend against it. Leading the malware charge in 2017 will be ransomware. Like 2016 it will be more of the same, with an important and fundamental exception; ransomware will be more sophisticated.

Advanced attack vectors


Encryption keys are becoming more complex while ransomware attack vectors are becoming alarmingly advanced. Ransomware can mount previously mapped drives, encrypt them, and then unmount them, reaching deeper into the network.  

However, the efficiency of ransomware as a tool for fraud will also be slowly undermined. One misconception about ransomware is that once the ransom is paid, the victim receives the keys to unlock their files. Increasingly we are seeing instances of this not happening. The fraudsters are simply taking the money and running.

Criminals dumbing down


As ransomware is now available as-a-service, it is reaching down into the lower levels of the criminal underworld and organised crime networks. The type of villain who uses the ‘service’ might have previously been involved with keeping crooked books for instance.

As such they can’t be bothered to send decryption keys which of course will erode the value of ransomware as victims increasingly refuse to pay the ransom.

IoT security


Another major area of concern is the security of IoT devices. It’s fair to say that the existing state of device security isn’t great. Some devices are managed by web consoles that don’t even have encryption. Some devices have passwords hard coded into them that you can’t change. It would be good to see manufacturers take some responsibility but this is unlikely as they operate with tight margins and are unlikely to take on tasks that eat into thin profits. 

If we’re lucky, we will see the emergence of pressure groups consisting of industry vendors and third parties who are no longer willing to sit back and watch major hacks unfold. 

Questioning machine learning


Another area to keep an eye on is machine learning. As with any new technology it’s usually proclaimed with a loud fanfare and over exaggerated claims that often fall just short of guaranteeing freedom for all and world peace. In terms of security, machine learning does promise a lot of potential but when you drill down some serious questions need to be asked.  

In 2017 we’re likely to see these questions put forward with some force, as it becomes apparent that machine learning in the security realm has flaws. For instance, how are the machines learning, are millions of good and bad results being fed into the machine to ensure accurate analytics and what kind of input is coming from security labs and research teams?  

These are important questions and with the advent of next-generation endpoints, such as mobile devices and laptops designed to respond to machine learning security in depth is vital to ensure success. If machine learning vendors can’t answer these questions with confidence, then you can expect to see machine learning and security take a dive.

Shock of GDPR


An area where you can expect to see panic break out is the European Union’s General Data Protection Regulations or GDPR as it’s more commonly known. At the moment UK organisations are displaying naivety towards GDPR which comes into effect in May 2018. Many are hiding behind Brexit and taking the view that the UK won’t be in the EU come May 2018 so GDPR won’t affect them. However, if a business operates in Europe, it will.  

To meet GDPR requirements, measures need to be put in place in 2017. Many companies have already finalised budget for 2017 but haven’t made any provision for GDPR. With no budget provision, there’s going to be an awful lot of flapping when companies realise that it’s nowhere near compliance ready. 

Big fines, big panic


GDPR also reaches up to the board and any data breaches can result in enormous fines of up to 4 per cent of revenue. This can and will translate in some cases, to fines that run into millions of pounds. Are executive directors aware that if they show negligence in protecting customer data they’re going to be hit really hard?  

In summary, it would be uplifting to say that we’re not going to see any more major breaches, that fundamental flaws will be addressed, that new technologies are going to change the security landscape for the better and everyone is set for GDPR. In reality, while we will see some positives we also need to prepare our businesses for more breaches and more hacks. 

Friday, 26 August 2016

Changing environments mean a fight to stay relevant [Link - Channel Pro]

While I was at the CyberArk Partner conference, I was asked to attend a roundtable to cover challenges we see in the UK marketplace.  Here is an article was written by Tim Goodwin, the EMEA Channel Director for CyberArk: http://www.channelpro.co.uk/opinion/10093/changing-environments-mean-a-fight-to-stay-relevant


========================================

UK resellers face a turbulent time, both currently and in the months to come. Against a backdrop of a changing threat landscape, new data regulations and the uncertainty following the UK referendum result, the opportunity to grow still remains, but channel partners and VARs will have to negotiate potentially treacherous waters to remain relevant for customers.

At a recent customer and partner EMEA event hosted by security vendor CyberArk, Kristian Alsing, a cyber security director at consulting firm Deloitte, together with panellists Andrew Tang from MTI and Hakan Cakar of NTT Com Security, examined these issues, the opportunities they present, and what approaches will be necessary to remain trusted partners for UK end users.

In the context of security, Alsing highlighted that there haven’t been any new crimes in the last thousand years. “People are still defrauding others, still stealing, still doing the things that humans have always done,” he said. “But what we do have that’s different is a connected world.”

The crime has now been decoupled from the location of the asset, explained Alsing, going on to detail what Deloitte are seeing. A notable trend is the service provider model being adopted within the organised crime industry - for example Hacking-as-a-Service for those who don’t possess this particular specialism - as well as the evolution of criminals, with who used to ‘just’ steal credit card details moving into much more complex and ambitious cyber heists.

Increased nation state involvement, malicious insiders and hacktivists form what Alsing referred to as the ‘threat actor’ environment. When combined with a very different looking end user, compared to the recent past, this creates some key considerations to understand for the UK channel community.

Organisations used to control their assets, whether that be money, data or anything else. With the huge use of outsourced and cloud services, plus the Internet of Things (IoT) and mobility, the risk for organisations is higher than it has ever been, because it is concentrated – people or data on a grand scale can be accessed from one access point. So it is critical to understand this in order to be credible for end users.

The panel also discussed how strong regulation in the Finance industry has led to the rising importance of cyber security within organisations (in many cases to c-level), as well as the sheer complexity of organisations driving security concerns. Acquisitions in particular were highlighted as a cause of security issues as legacy infrastructures and different approaches to security come together.

Both NTT and MTI addressed the perception that end users don’t necessarily really know how to separate what is important from the plethora of – sometimes mixed – messages from security vendors. Threats like ransomware were cited as helping people ‘get it’ as it is such a common threat.

An interesting part of the discussion involved education and the question of responsibility for it. There was a feeling on the panel that the industry (vendors and partners) shouldn’t sell a panacea to customers, but should instead concentrate  on finding out what is important to the end user on a case-by-case basis. Partners, with their huge reach, should be part of the education programme. Demand from end users in this area is what has driven NTT to invest in bigger security practices.

Unsurprisingly, the EU GDPR was highlighted as a driver for change. Alsing made the point that certain car manufacturers, decades ago, made safety a selling feature. At the time they were ridiculed, but now safety is very important for all mass-market vehicle manufacturers. In the same vein, data integrity, as enforced by GDPR, should be a partner opportunity.

Finally, the panel talked about Brexit, albeit in the context of what it would mean for the regulatory environment. Will it mean data protection reverts to the more ‘watered down’ form that we had before the EU version came along? The verdict was ‘probably not’; the UK had a leading role in designing the EU regulations.

Concluding, it was noted that collaboration would be the key to remaining relevant in a fast-changing UK. Vendors, partners and customers have to remain connected to maintain the right level of knowledge and expertise to meet IT and environmental challenges. This is the time to embrace change, not retreat into our shells.

Friday, 19 August 2016

The General Data Protection Regulation - A post Brexit positive for British enterprise [Link - SC Magazine]

Another proud moment for me, as I have another article published in SC Magazine about the General Data Protection Regulation (GDPR): http://www.scmagazineuk.com/the-general-data-protection-regulation--a-post-brexit-positive-for-british-enterprise/article/514976/

=======================

A month before the UK chose to leave the EU, The European Union's General Data Protection Regulation (GDPR) was signed into law. The act is designed to change the way businesses approach data protection from its 2018 enforcement date.

Replacing the EU Data Protection Directive, it has considerable scope in standardising and unifying data privacy requirements across member states and any business that markets to EU data subjects.

With strict guidelines around obtaining consent for data collection and individual profiling, alongside far more comprehensive definitions of data, non-compliance will trigger heavy fines - either €20 million (£17 million) or four percent of global turnover, whichever is greater.

Off the hook


If we exit the EU before the GDPR is enforced in 2018, technically the legislation won't apply. In practice, however, the international trading implications of the GDPR means the UK will need to broadly align its laws around handling EU citizens' personal information to maintain a close trading partnership with the EU member states.

So while those IT departments who believe GDPR stipulations impose a heavy burden might consider Brexit a handy escape route, the reality is this: Brexit aside, to continue as trading partners with the EU and remain in the European Economic Area, UK businesses will need to adopt a broadly similar framework of standards to protect EU citizens' information.

This is a positive thing, holding huge opportunity for UK business. The regulation's objectives and framework are vitally important in today's global digital economy. Meeting the new requirements will help protect UK businesses and citizens from much of the catastrophic damage caused from major cyber-attacks and mitigate many of the threats before they occur.

With only two years to meet compliance requirements and implement the changes to business systems and operations, now is the time to start the process of transforming the way businesses collect and use personal information and data.

Key considerations


Firstly, it's important to remember that the GDPR is a set of rules governing the security and management of any data that could be used to identify someone. Companies will have to immediately notify the authorities within 72 hours of any breach of an EU national's data to avoid a fine.

There's currently no UK requirement to do this and many don't due to the potential reputational impact. Recent examples, including TalkTalk's experience, demonstrate the potential damage to profit and trust following public data leaks.

To meet this requirement, businesses will need to deliver huge overhauls of their current systems to ensure breach protocols are compliant. The final draft won't be ready for some time, but companies should closely examine the current version to get up to speed.

From a technical perspective, the GDPR separates responsibilities and duties for both data controllers and processors. Controllers will only be able to engage processors that provide sufficient guarantees to meet the GDPR's standards of protecting data subjects' rights. For example.

Article 32 of the GDPR already outlines these responsibilities and provides specific suggestions for the type of security activities which might be ‘appropriate to the risk'.

Above all, it's worth remembering that from encryption of data to testing and assessing security systems – everything needs to be compliant with the GDPR's new code of conduct.

GDPR readiness


With just two budget cycles remaining until the act becomes law, it seems GDPR readiness is not a priority amongst European IT professionals – and there's a lot to be done.

As an immediate priority, a UK enterprise should start to get its systems ready and implement upgraded breach notification policies. To deliver this effectively, IT must start working with legal teams and other key departments to avoid the potential for heavy fines and get their operations data fit for a new era of global digital trade.

Wednesday, 20 July 2016

Gemalto hunts for partners for its encryption solutions as GDPR approaches [Link - CRN Magazine]

I was asked to give my opinion on our working relationship with Gemalto and GDPR by CRN and may comments were published: http://www.channelweb.co.uk/crn-uk/news/2465454/gemalto-hunts-for-partners-for-its-encryption-solutions-as-gdpr-approaches 

============================

MTI has been a partner with Gemalto for around eight years, and its services director Andrew Tang said that he has noticed the increased demand for the encryption products Gemalto provides in the run-up to GDPR.

"We have had a couple of organisations in the finance industry that have started asking us about how we can help them with their GDPR strategy. There are organisations out there that are on the ball, but more companies were in limbo because of the referendum," he said.

"People forget that when you look at all the different options, whether it's the Norway, Switzerland, Canada or Turkey models, they all have to adhere to EU regulation, which means GDPR in some fashion or another. It is still about education and evangelisation at the minute."



Monday, 11 July 2016

EU General Data Protection Regulation (GDPR)

Before I start on this blog piece, I have to make it clear that I'm not a lawyer and I have no legal training.  The blog piece below does not constitute as law, but these are areas I have researched and may make some assumptions along the way, especially with the uncertainty in the UK and it's relationship with the EU.


Data Protection Directive

The EU Commision were looking at replacing the Data Protection Directive.  So we are clear, an EU directive is a goal that the EU must achieve, but it's up to the individual countries to devise their own laws on how to reach the goal.

In January 2016, a draft form of the EU General Data Protection Regulation was released.  The difference between a directive and a regulation, is that an EU regulation is a binding act, that is applied in its entirety across the EU.

Why GDPR important?

GDPR is there to strengthen and unify data protection for individuals in the EU.  It addresses the export of personal data outside of the EU.

When will GDPR happen?

The regulation has now been released and enters into force on 25th May 2018


What is the impact of GDPR?

  • A Data Protection Officer is needed if an organisation processes 5000+ EU data subjects; or employs more 250+ employees
  • Mandatory disclosure of incidents within 72 hours to the national authority
  • Maximum fines of up to €20 million or 4% of worldwide revenue
  • “Right to be forgotten”: The data subject will have the right to retract consent, request data erasure or portability
  • EU Referendum has no impact to organisations – If you hold personal data on an EU citizen, GDPR still applies
  • Live May 2018 – Two budget cycles left

The Data Protection Officer

If the core activities of an organisation involves “systematic monitoring of data subjects on a larger scale”, or large scale processing of "special categories", such as racial/ethnic origin, political opinions, religious/philosophical beliefs, biometric data, heath/sex life or sexual orientation, then a Data Protection Officer is required.

The function is also there to advise on, and the monitoring of GDPR compliance, as well as representing the organisation when contacting supervising authorities.

Disclosure and Notification

The controllers are required to notify the appropriate supervisory authority of a personal data breach within 72 hours (at the latest) on learning about the exposure if it results in risk to the consumer. But even if the exposure is not serious, the company still has to keep the records internally.

According to the GDPR, accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, the EU’s term for PII is considered a breach.

The GDRP notification is more than just reporting an incident, there is a need to include categories of data, records touched, and approximate number of data subjects affected. This will require detailed intelligence on what the hackers and insider were doing.

There is a term known as "Dwell time", which is the period of time that someone malicious is on your network and systems undiscovered.  Most people are shocked to learn that this on average is 206 days (from Cost of a Data Breach Study: Global Analysis, Ponemon Institute, 2015)

Fines

The GDPR has a tiered fine structure, so a company can be fined up to 2% for not having their records in order, not notifying the supervising authority and data subject about a breach or not conducting impact assessments, while more serious infringements merit a 4% fine. This includes violation of basic principles related to data security and conditions for consumer consent. 

The EU GDPR rules apply to both controllers and processors that are in “the cloud”. So cloud providers are not off the hook when it comes to GDPR enforcement.

"Right to be Forgotten"

Individuals can request the erasure of their personal data without undue delay by the data controller in certain situations. 

Consent can be withdrawn and no other legal ground for processing applies. This topic has attracted a huge amount of interest, particularly following the CJEU decision in the Google vs. Spain case.

Alongside this obligation is one to take reasonable steps to inform third parties that the data subject has requested the erasure of any links to, or copies of, that data.

Outside of the EU

The law applies to your company, even if it markets goods or services in the EU zone.  If you don’t have a formal presence in the EU zone but collect and store the personal data of EU citizens, GDPR still applies and the extra-territoriality requirement is especially relevant to ecommerce companies.

Is GDPR still required now that Brexit may happen?

If Article 50 is initiated in July 2016 & UK exits July 2018; GDPR will apply from May 2018. Also the UK were instrumental to writing and strengthening the GDPR.  Receiving personal data from EU member states would need to demonstrate to the European Commission that the law provides an adequate level of protection through its domestic laws or international commitments.

Source: Absolute Strategy Research Ltd

As you can see from the chart above, with many of the options open to the UK, compliance with EU regulation is required in order to trade with Europe.  In my opinion, GDPR will be relevant to the UK, and will need to be in place with UK organisations holding data of EU citizens.

Adopting GDPR

I believe there are some steps that will need to be taken with all organisations that wish to comply with GDRP:
  • Locate the critical data for GDPR
  • Protect the data (and the applications that access it) through segmentation and/or encryption
    • If encryption is used, ensure the encryption keys are secured
  • Use strong Access Controls to servers holding the data, such as two factor authentication
  • Use DLP/Insider Threat technology to prevent data exfiltration
  • Monitor all exfiltration data channels, including web and email
  • Collate logs from the network, so they can be analysed
  • Secure domain and local administrator accounts
  • Penetration test the environment

Final Thoughts

GDPR goes live in May 2018, which means there are two budget cycles left to get the education, processes, workflow and technology in place.  One of those budget cycles are underway already, so if GDPR planning hasn't begun, start it now, so you'll be ready for next years budget.

Friday, 1 July 2016

General Data Protection Regulation – what you need to know [Link - MTI Bytes]

This is a blog piece for the company blog site around the new General Data Protection Regulation: http://blogs.mti.com/blog/general-data-protection-regulation-what-you-need-to-know

===============================================

Signed into law in May 2016, the European Union’s General Data Protection Regulation (GDPR) act will force change in the way businesses approach data protection when it is enforced in two years’ time.

The scope of the act, which replaces the EU Data Protection Directive, will increase significantly as it standardises and unifies data privacy requirements not just across member states, but for any businesses that markets to EU data subjects.

Carrying heavy fines for non-compliance, either €20 million or 4 per cent of global turnover, whichever is greater, the GDPR enacts stricter guidelines for getting consent for data collection, individual profiling and also contains more comprehensive definitions of data.

GDPR also enhances the current legislature around data security and breach notification standards, so it is imperative the compliance teams, CIOs and data protection officers take notice of these changes.

Breach notification

As part of the new rules set by the EU, companies must alert the authorities without undue delay and have up to 72 hours – where feasible – to provide notification of a breach of EU national’s data, or risk a fine for non-compliance.

Currently, UK firms are not under any such requirement to announce a data breach, with many choosing not to as the cost of doing so for a business can be enormous. For example TalkTalk and Carphone Warehouse saw their profits and trust in their brands fall dramatically following public data leaks.

This will be a significant change for many businesses, and will see current systems overhauled in order to ensure breach protocols are compliant with the new legislation. It will also apply to all UK firms trading in Europe, as any company that holds the personal details of an EU ‘data subject’ will have to comply.

The devil is in the detail and the final text of the new directive needs to be closely studied.

Getting technical

The GDPR also separates responsibilities and duties for both data controllers and processors – requiring controllers to only engage processors that provide sufficient guarantees to meet the GDPR’s standards of protecting data subjects’ rights.

Article 32 of the GDPR outlines these responsibilities. While it is similar to the Directive’s Article 17, the GDPR expands this by providing specific suggestions for the type of security activities which might be ‘appropriate to the risk’.

From encryption of data to testing and assessing security systems – everything needs to be compliant with the GDPR’s new code of conduct.

Looking forward

There are just under two years and in turn two budget cycles remaining until the law enforces the act, yet GDPR readiness is not a priority amongst IT professionals in Europe.

There is a lot to assess in that time, especially in terms of the security aspects of GDPR, so now is the time to be getting systems ready for compliance and for implementing new breach notification policies.

This will require working with legal teams and other branches of the business to ensure compliance is watertight to prevent heavy fines for businesses.