Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Not Another GDPR Comment
News & Analysis

Not Another GDPR Comment

ISBuzz TeamBy ISBuzz TeamMay 21, 2019Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Experts Comments:  

Joseph Carson, Chief Security Scientist & Advisory CISO at Thycotic:

The EU GDPR has been positive for the Information Security industry as it has forced many companies to re-evaluate their cybersecurity posture and better understand the type of personal information they have been collecting on EU citizens.   

It means that companies who are regulated by the GDPR have improved their cybersecurity capabilities – incident response has been one of the areas which companies have significantly improved. We have also recently seen the first fines under the GDPR given to several companies, mostly related to consent or data minimisation, though many of the major data breaches are still under investigation and we will likely see the fines increase throughout 2019 and beyond.   

The GDPR is only the first step in helping regain control of personal information and the EU needs to continue improving. GDPR has been the founding regulation that other governments around the world are using as the standard for their own versions. For example, as the California Data Privacy Protection act, while not as strict, it is setting the new direction for protecting personal information and many others are following.

Mark Trinidad, Senior Technical Evangelist at Varonis: 

Over the past year, one of the biggest adjustments organisations have had to make for the GDPR is giving greater consideration to the data in their possession. Suddenly, they had to identify and plan for at-risk and sensitive data, as well as care enough to understand where data is stored, how it is processed, and who has access to it.  

While caring is the first step, data protection and security is a process, not a destination. With the GDPR, there has not been an “easy” button to push and many are still working to improve their GDPR practices. For example, companies are continuing to fall even farther behind in securing their data as the Varonis Data Risk Report found that, on average, 22% of folders are accessible to every employee. Discovering where all the sensitive at-risk data is stored and who has access to it can be eye-opening for organisations that did not care before. Therefore, implementing a comprehensive  plan to mitigate risk can be an uphill battle if an organisation simply does not know where to begin. 

The GDPR has acted as the first step to force global companies to change their thinking around data protection and the new California Consumer Privacy Act (CCPA) will be another when it comes into effect. 
Carolyn Crandall, Chief Deception Officer at Attivo Networks: 

Many organisations have been able to address Articles 32 and 25 of GDPR, but many still struggle with Article 33. Numerous organisations have difficulty identifying if an incident happened and if it happened, they have trouble modifying their strategy to report within 72 hours. Previous directives from the EU 95/46 made no specific mention of data breaches and GDPR now sets a clear directive as to what constitutes a data breach, how the incident is to be reported and the substantial penalties for not complying. This has required businesses to reassess their technology and processes in order to understand their ability to detect, audit, and report breaches in compliance with GDPR. Closing these gaps, in many cases, requires the adoption of new technology to ensure that the attack is not only detected but also understood in a way that can explain the magnitude of the breach and the corrective actions to contain it. Whether it be access to budget, skills shortages, or otherwise, a fair amount of organisations remain hard-pressed to comply with this article if faced with a breach today.

Ian Bancroft, Vice President and General Manager EMEA at Secureworks: 

“One thing that has quickly become apparent is the complexity around GDPR. Over the past 12 months we have seen more customers seeking external expertise when it comes to security controls and best practises. Businesses have realised that for the majority, GDPR requires expertise, resources and understanding beyond internal capability. However, any regulation that puts security at the forefront of the business agenda is a good thing.”   

“By holding organisations responsible, the regulation is reaffirming that businesses need to know their data, manage it, and build a strategy which protects every stakeholder from investors to the end user. Ultimately, regulations like GDPR are one of the key reasons behind the shifting role of traditionally non-strategic roles in the boardroom like the CFO, CTO and CSO. With the value of data growing exponentially, those who are directly responsible and impacted by data will increasingly find themselves consulted on how to use this asset effectively, and above all else, securely.” 

Colin Truran, Principal Technology Strategist at Quest: 

“Whilst those of us in the technology industry have been discussing GDPR at length over the last 12 months, espousing the benefits of having defined compliance processes in place, the first few weeks of the implementation of GDPR saw the gravity of the situation become impossible to ignore. A tidal wave of privacy policy update emails hit the inboxes of practically every member of the EU public, prompting varying degrees of confusion, frustration, and mockery in the media. For better or for worse, we’re now in a position where every individual, regardless of technical savvy, is more aware than ever about their right to digital privacy and the level of control they have over their Personally Identifiable Information (PII).   

“As more and more businesses are now looking to cover their backs and demonstrate varying degrees of compliance to their users, this new era of data privacy awareness could be more than many businesses bargained for when regulators such as the Information Commissioner’s Office (ICO) comes knocking. The total fines to date are around €56 million – which you would initially think is a lot, but actually, almost all of it comes from French data watchdog CNIL’s €50m fine for Google.   

“However, GDPR has not yet had that real wake up call that many thought it would. The fines to date have been well within budget, not insignificant, but not exactly life changing either. There is also a clear discrepancy between how data authorities in countries are applying it, so despite having a common set of rules it is not a level playing field.  With all that said, it is still early days where most of the breaches occurred before the GDPR was ratified into law.  Therefore, this year will be the decider if GDPR is an effective solution as it was intended or just another piece of bureaucracy that fails to have the desired effect.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}