Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - GDPR Was Painful, But What Happens Now?
Articles

GDPR Was Painful, But What Happens Now?

ISBuzz TeamBy ISBuzz TeamJuly 2, 20184 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With the GDPR deadline now passed, the sigh of relief from IT departments up and down the country was almost audible. IT teams were thrown the challenge of working out what was needed to meet the GDPR guidelines as it was thought to be a security issue. It swiftly became apparent, however, that it was a people and process issue and not a technology one. So IT passed the buck on to the legal, HR and finance departments. But as companies gained a handle on the policies and procedures they needed it quickly became apparent the IT department would be required again.

Coming out the other side of the GDPR it is even clearer that it wasn’t a security play; this should have already been in place. IT was, however, an enabler to get the right business processes in place. IT departments have some excellent tools to help ensure the guidelines are met, but they can’t meet them in isolation. The GDPR is a business challenge for companies regarding how they process personal data, therefore ensuring ongoing compliance needs are viewed holistically – with people, process and technology.

The aftermath of the GDPR

With the GDPR now in place, many organisations are undergoing changes in the way they handle, record and store personally identifiable information (PII) data. For most, this will be a lengthy process and therefore arguably a lot of companies may not be compliant as of today. The key is to ensure businesses have an understanding of their personal data flow so they can work towards a GAP analysis and identify what is required to achieve compliance.

Mitigating the risk and being able to display a roadmap towards compliance are the most important elements if an organisationdoesn’t firmly believe it is fully compliant. Also, undertaking Government-backed schemes, such as Cyber Essentials and Cyber Essentials Plus, will highlight commitment towards data security.

The continuing business challenge

 The GDPR has been taken seriously by companies because it has serious consequences with significant financial penalties for infringement. However, the ongoing business challenge is how companies process data, and IT systems have a key role to play in enabling the safe and secure handling of relevant data.

Despite organisations sitting up and taking action, an anomaly still exists. Recent industry research found over half (58%) of SMEs think their businesses are at risk of financial loss from poor IT security and data compliance. The research, conducted by OnePoll for Ultima, also found a good degree of realism expressed by SMEs, with 41% acknowledging that spending money on IT security is not a priority, and just over half (55%) acknowledging that they could probably never fully protect their business from IT breaches.

Has the GDPR forced the hand of businesses to continue to change (especially SMEs) and invest in greater IT security to ensure ongoing compliance? It’s a watch and wait scenario. Along with the change in mindset about the GDPR solely being an IT problem, organisations should cease viewing IT security as expensive. There are many ways that firms can improve their IT security which don’t require large expenditure and can help avoid fines or financial loss due to data breaches, which can run into six-figure sums.

The GDPR deadline might have passed, but it is helping to force a business change which is still in progress. Embracing it as a good way of keeping data safe and ensuring compliance will help companies to view the painful process as being worthwhile. And not least, it will help ensure they avoid the more painful media attention and reputational damage which could come from non-compliance.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}