Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - The Importance Of Long-Term Compliance And Tackling Data Sprawl, And The Impact GDPR Will Have On Company Culture
News & Analysis

The Importance Of Long-Term Compliance And Tackling Data Sprawl, And The Impact GDPR Will Have On Company Culture

ISBuzz TeamBy ISBuzz TeamMay 12, 20186 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With just two weeks until GDPR comes into force, IT security experts commented below.

Importance of long-term compliance 

Rob Price, Pre-sales Consultant at Snow Software:

“At this stage, and with the deadline for compliance just a matter of weeks away, varying states of readiness remain at-large across the business community. Some organisations are already years into their compliance journey, whilst others are only now realising the scale of the task that lies before them in order to meet the deadline.

In recent months, the overwhelming sentiment of the media furore around the General Data Protection Regulation (GDPR) has been focused on how companies can become compliant in time for deadline day on 25 May 2018. Instead, it should be analysing and scrutinising how those companies striving to become compliant intend to maintain the required standards once the deadline has passed.

With this in mind, establishing enterprise visibility should be at the heart of any organisation’s approach. Companies’ efforts need to be anchored around how they can create a cost-effective and precise strategy to handle and adapt to evolving compliance rules and demands over time.

There is now a burning need to closely examine those databases that have been central to the digital estates of many companies for many years. With new databases, processes and products being created every day, impacting upon every step of an organisation’s journey to become compliant, comprehensively scrutinising already entrenched systems is essential.

The majority of organisations beginning their journey to compliance understand the importance of identifying the location of personal data repositories, meaning that their focus is on systems such as SAP, Oracle databases and middleware like Marketo and Salesforce. But these large systems often represent just a fraction of the systems that process personal data. Like an iceberg, the vast majority of applications are often effectively invisible, unconsidered by the GDPR team and include SaaS applications purchased by business units with little to no involvement by IT.

As the digital estate continues to rapidly evolve, looking beyond the deadline date by conducting an extensive assessment of company software – both old and new – will be paramount to avoiding any penalties down the line – be they legal or financial.”

Impact on company culture

 Rob Price, Pre-sales Consultant at Snow Software: 

“Though having a watertight process and the performing of rigorous technological checks may be two key components to ensure compliance, instilling the right culture will be critical to guarantee that employees adhere closely to what’s required of them.

Typically, the road to compliance can be portrayed as too technical, which can, in turn, lead to a breeding ground for misinformation. Instead, organisations should be focusing on improving employee understanding, instilling a culture of the foundational tenets of compliance, and, given the harsh realities of today’s cyber climate, providing constant reminders of the importance of protecting data. Only then can they move on to establish concrete processes, which is where self-assessment and the identification of gaps comes into play.

Some basic steps like setting up a cross-functional data governance team, made up of the data protection officer (DPO), IT leaders and business leaders from a range of functions including Compliance, Legal, HR, Customer Service, and Marketing is a solid starting point. These are the individuals who can help the importance of customer data protection become woven into the fabric of a business model.

By repeatedly emphasising the importance of data protection, CIOs will set themselves, their teams and their organisations up for success. And, positioning data privacy front and centre will enforce a company culture that can truly help to deliver GDPR compliance collectively.”

Controlling data sprawl and recognising enterprise accountability is key to GDPR compliance

Chris Mayers, Chief Security Architect at Citrix:

 “The GDPR will do far more than strengthen data privacy rights. The regulation will set a high bar for responsibility and accountability – and not one that every business will meet.

Ensuring data privacy processes and systems are in place – from privacy by design to privacy by default – requires an organisation to know exactly where their data is and who can access it. Yet many are losing sight of data, spread across multiple systems and shared with multiple partners, while also struggling to scale up to store and control the huge influx of personal customer data they receive today.

Businesses must recognise that more centralised application and data storage environments will make it easier to meet technical compliance goals. This centralisation can be achieved in various ways, from introducing unified access controls across on-premise and cloud services with single sign-on to rolling out centrally-managed virtual workspaces. However, it is done, controlling data sprawl and recognising enterprise accountability around data privacy will be key to GDPR compliance.”

How do businesses actually protect their data?

Elodie Dowling, Corporate VP, EMEA General Counsel at BMC Software:

“With two weeks to go until GDPR many organisations are placing a great deal of emphasis on the technical aspect of GDPR, but the road to compliance involves more than technology and state of the art.  Organisations must break compliance down into three phases – people, process, and technology.

Organisations should be focusing on instilling a culture of compliance. Only then can they move on to establishing concrete processes, which is where self-assessment and the identification of gaps comes into play. From there, organisations can turn their efforts to constructing a roadmap to compliance.

Technology is the third component and this is where discovery is crucial. How can customers become truly compliant if they don’t know what’s in their data centres, who has access, what other devices are active and vulnerable, where their sensitive information is stored and how they should be maintaining their devices to ensure they meet auditor standards?

Only by relentlessly examining internal processes can customers discover how their devices storing data are configured, how they’re connected, where any vulnerabilities sit and then piece together a plan to remediate those vulnerabilities and correct them. Data is constantly in flight so in order to transfer it in a secure way, it must be archived to protect it from the recovery implications contained within the GDPR.”

The importance of tackling fundamental challenges, such as data sprawl 

John O’Keeffe, VP EMEA at Looker:

“The 25th May will mark a significant milestone for businesses across the globe – when organisations managing EU citizen data will need to be compliant with GDPR, or risk punitive measures to the tune of up-to €20 million. Yet, as revealed in this survey, many businesses are still not ready.

“Many are still tackling fundamental challenges – such as data sprawl – in which masses of data is left dispersed, uncategorised and disordered. Because of this, businesses can easily lose track of what data is being stored, how it’s managed and whether it’s robustly safeguarded. Ensuring these data ‘swamps’ are cleaned, organised and filtered should be the first port of call for CIOs.

“Once organisations have clean data ‘lakes’, they can continue the process of data analytics to drive business outcomes. But – if they want to maintain their compliance with GDPR – leveraging tools that don’t extract the data is key. Data analytics should enable positive business change, not start the data sprawl process all over again.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}