Story image

Bring on the fines: Survey finds most companies won’t be ready for GDPR

26 Apr 2018

One month to go until the new EU General Data Protection Regulation (GDPR) legislation comes into force and it looks as though most companies won’t be ready.

WinMagic today released the findings of research that shows only 51 percent of companies say they have all the systems in place that will allow them remove EU citizen data from servers upon request - including backups - in accordance with GDPR.

What is concerning is the 21 percent of businesses that still don’t have any systems in place.

WinMagic says in many cases companies lack the systems and process required to ensure compliance with the new legislation that affects all companies around the world holding and processing EU citizen data. Non-compliance can lead to fines of €20 million or 4 percent of turnover, not to mention the catastrophic reputational damage that can occur from a data breach where non-compliance has heightened the risks for citizens.

“Whilst companies have made general improvements in their preparations for EU General Data Protection Regulation, the survey suggests that most will not be fully compliant with the regulation when it comes into force,” says WinMagic chief operating officer Mark Hickman.

73 percent of businesses believe GDPR will change the way their business will operate to meet compliance, however, WinMagic says there are a number of key areas where they will fail to meet the requirements of the legislation:

  • 25 percent admitted that systems were only part implemented, and would not allow the automated removal of citizen data from back-ups
  • Just 48 percent of data is geo-fenced so that it cannot be accidentally, or intentionally, moved out of the legal jurisdiction under which it should be
  • 49 percent of ITDMs admit not always conducting security audits of the storage locations their data processing and storage partners use

Another problem uncovered by the research is the failure to encrypt data, with 20 percent of companies lacking continuous encryption for personally identifiable information across their cloud and on-premises servers, despite appropriate levels of encryption and anonymisation being a requirement for GDPR compliance.

WinMagic says continuous encryption can be complicated to implement in modern environments where infrastructure and data span both cloud and on-premises servers, leading to hidden data and a fragmentation of governance that leaves companies non-compliant and at risk of heavy fines.

If a data breach occurs, it’s all about how fast businesses can respond to control the spread and abuse of data by cybercriminals. GDPR requires companies to report data breaches to the relevant regional authority within 72 hours of discovery, yet 41 percent of ITDMs believe they could not achieve this today.

WinMagic says that perhaps more concerning is that many companies lack the tools that will identify a breach ever occurred or the data taken:

  • 33 percent lack confidence and 6 percent have no confidence that their systems would automatically identify a breach triggered by an external source.
  • For internal breaches, 34 percent lack confidence and 6 percent have no confidence that their systems would automatically identify a breach event.
  • Just 55 percent believe they can precisely identify the data exposed by a breach.

“Whilst many will have sought the necessary authorisations from EU Citizens to store their data and use it for marketing etc., they will lack the processes and protections demanded by the legislation to ensure compliance and protect personally identifiable information with which they have been entrusted,” says Hickman.

“Effective control and management of the IT infrastructure spanning on-premises and cloud service providers for security and specifically encryption, will be a critical component in meeting the legislative requirements and minimising the risks to consumers.”

Enterprise cloud deployments being exploited by cybercriminals
A new report has revealed a concerning number of enterprises still believe security is the responsibility of the cloud service provider.
Ping Identity Platform updated with new CX and IT automation
The new versions improve the user and administrative experience, while also aiming to meet enterprise needs to operate quickly and purposefully.
Venafi and nCipher Security partner on machine identity protection
Cryptographic keys serve as machine identities and are the foundation of enterprise information technology systems.
Machine learning is a tool and the bad guys are using it
KPMG NZ’s CIO and ESET’s CTO spoke at a recent cybersecurity conference about how machine learning and data analytics are not to be feared, but used.
Popular Android apps track users and violate Google's policies
Google has reportedly taken action against some of the violators.
How blockchain could help stop video piracy in its tracks
An Australian video tech firm has successfully tested a blockchain trial that could end up being a welcome relief for video creators and the fight against video piracy.
IBM X-Force Red & Qualys introduce automated patching
IBM X-Force Red and Qualys are declaring a war on unpatched systems, and they believe automation is the answer.
Micro Focus acquires Interset to improve predictive analytics
Interset utilises user and entity behavioural analytics (UEBA) and machine learning to give security professionals what they need to execute threat detection analysis.