Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Reducing The Compliance Burden
Articles

Reducing The Compliance Burden

ISBuzz TeamBy ISBuzz TeamJune 15, 2016Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The compliance landscape has changed significantly in the last few years. Not only are IT security threats continually evolving, but so are regulations related to compliance and security protections. With the whole technology sector moving at such a fast pace, new challenges are inevitably going to emerge. We live in an age where IT security isn’t just about protecting files, but ensuring infrastructure is secure as well. Recently, Christopher Frei, Director General at the World Energy Council, described cybersecurity as one of the major issues “keeping energy leaders awake at night.” The case for maintaining compliance now goes further than protecting data from cybercriminals.

At the same time, legislatures have tried to regulate and better protect citizens. In Europe, the most recent landmark piece of regulation was the General Data Protection Regulation (GDPR). Among the most critical reforms of 2015, the GDPR still needs to be ratified by the European parliament, but the terms of the data protection rules further highlight the importance of maintaining compliance, as the regulations would introduce sizable fines for failure to properly protect information.

For most organisations, protecting customer data and information systems as part of compliance policies is a core requirement; however this work can sometimes be a heavy burden. The focus of any business must be driving revenue, and maintaining this and compliance can be a significant challenge. Actually examining how compliance can make a minimal impact on productivity will help to reduce its burden throughout an organisation.

Functionality, Automation and Visibility

Organisations can look to manage productivity by introducing security tools that are easy to use. In fast moving environments, staff will look to the quickest and easiest solution. Security tools therefore must not only meet regulatory requirements but also the ease-of-use needs of the frontline staff. This means IT and compliance teams can have more trust in their colleagues, and reduce any ‘policing’ burden.

A further benefit of making tools more functional is the role it can play to empower whole teams to play a key role in maintaining compliance. Introducing compliance training and making employees feel responsible for protecting their own silo will help spread the burden of maintaining compliance across an entire organisation, not just with IT, auditors and senior management.

At the same time, the burden can be further reduced by introducing some level of automation into processes. For example, ensuring that every file distributed arrives at the right place at the right time can be accomplished with automated, secure information exchanges that are fully compliant. This removes the opportunity for human error, and has little effect on productivity, reducing the compliance liability on members of the staff. We’ve already seen many organisations implementing automatic encryption into emails. This particular technology allows companies to share documents and data over email while keeping the files within a secure protected system. Management can sleep safe in the knowledge that every external contact is automatically encrypted.

From speaking to leading CIOs, we’ve found that a major concern for them is visibility. The moment data leaves an organisation’s IT system, its location can be very difficult to track until it reaches its final destination. People involved in compliance policy want to know whether security could have been compromised, where data is being stored, and who can access it. Particularly when IT systems are complex and disparate, tracking individual files in transit can be challenging.

Consequently, achieving full visibility can be a huge step towards reducing issues related to compliance and may improve security at the same time. From a management perspective, teams can see exactly how information exchange practices are being implemented and flag potential non-compliance problems before they happen. In addition, greater visibility can help to develop an understanding of bottlenecks and can lead to initiatives to lessen the burden further.

Legislative and practical requirements for compliance and IT security are likely to continue to pose challenges. The new GDPR calls on a proactive approach to privacy; we’d expect to see more organisations look to implement technology that focuses on this by design. Ultimately, maintaining compliance may always be a significant task, but investment in the right tools and technology can go a long way to maintaining productivity. Ensuring everything is functional, automated, and visible is where the focus should be for organisations across all verticals.

[su_box title=”About Peter Merkulov” style=”noise” box_color=”#336588″][short_info id=’73426′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}