Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Proposed fines in Cyber Security Directive could hit businesses hard in the pocket

by The Gurus
September 10, 2020
in Editor's News
Share on FacebookShare on Twitter

Organisations could face fines running into millions if the EU’s proposed cyber risk directive is passed.

Proposed in early 2012 with amendments made this year, it would permit each European Union member state to fine up to two per cent of a company’s global revenue for data loss incidents.Dwayne Melancon, chief technology officer at Tripwire, said: “The new EU Directive has the potential to have a huge global impact because it applies to any organisation which operates in the EU, even if they are headquartered elsewhere in the world.
“Countries have been given two years to put the EU directive into place and organisations should be using this time to tighten their security programs; ensure that incident detection and response processes are in place and effective; and harden their systems, applications, and networks to reduce the risk of breaches.”
A survey by Tripwire and the Ponemon Institute of 1,320 IT security professionals found that over a quarter (28 per cent) of organisations do not have a formal risk management strategy applied consistently across the entire enterprise, while only 51 per cent assess risks, 58 per cent assess vulnerabilities and 58 per cent identify threats. Also, only 13 per cent said that they have regularly scheduled meetings with senior executives to discuss the state of the security risk with senior management.
Speaking to IT Security Guru, Robert Bond, notary public partner at Speechly Bircham, said that it is “frankly worrying” in terms in how businesses don’t have risk management, however the Cyber Security Directive is drafted by each member state who pass their own local law where businesses are in critical infrastructure areas.
He said: “The directive talks about fines up to two per cent of global turnover, but each member state will need to appropriate fines and the directive doesn’t mention any figure, but it does go parallel with regulation which does say two per cent and the key thing is when the EU passes regulation, it is binding on member state, but it means nothing until it is passed in a member state.
“The directive will saying it is up to each country to determine what to do if they are not complying with local law. Some will be complicated and others will be lax; with 28 member states that is 28 versions and 28 acts bound by regulation. In terms of the message it gets across, it does the right thing in highlighting that businesses are not focusing on it and businesses are not picking up on it, and it will have significant impact.
“The message is if businesses are not up to speed with hackers, it may cost for security and compliance but it will cost more if you do nothing.”
In terms of the sizes of the fines, American retailer and Asda parent Wal-Mart has a global revenue of $469.2 billion, so the fine would be as high as $9.384 billion, more than half of their profit for 2013. Meanwhile BP has a global revenue of $388.3 billion, so the fine could be as high as $7.766, which is over three quarters of their profit for 2013.
“The size of the fines connected with the Directive are so big they will definitely get the attention of CEOs and boards,” continued Melancon, “It is incumbent upon senior business executives to seek clear answers about security risks from information security leadership to ensure appropriate steps are taken to enable compliance with this directive before it takes effect.”
ShareTweet
Previous Post

China developing surveillance technology to monitor ethnic languages

Next Post

New cyberbullying bill to prohibit sending ‘intimate images’ without consent

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol