Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 13 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Gurus Desperately Peddling Rubbish?

by The Gurus
September 6, 2017
in This Week's Gurus
Share on FacebookShare on Twitter

Next May the GDPR comes into force.  No wait, that sounds wrong.  Surely it’s the GDPR regulations.  But if I call it that, I’ll get hate-mail from the people who complain when I write about PIN numbers.  So we’ll stick with the GDPR for now.
The entire security industry seems to have been shaken up by the impending GDPR.   C-level people are frantically trying to work out the implications and obligations for their companies.  Half of LinkedIn’s membership are promoting themselves as GDPR experts when in reality, hardly anyone understands it.  Recruitment companies are posting adverts seeking candidates with 5 years’ GDPR experience, because the clients asked for it in the job description and no one dared tell them that no one has it.
Gaining an unbiased understanding of GDPR without spending thousands on lawyers and consultants is frustratingly difficult.  The definitive document is of course the official regulation as published by the European Parliament.  You can download it from the internet for free.  But it runs to hundreds of incomprehensible pages.  A lawyer acquaintance of mine explained why the document is so awful.  It’s designed to be used as the input for systems and people across the EU who have to translate it into meaningful legislation for their own country.  Think of it almost as a program script rather than a human-readable document. Those unintelligible phrases may mean nothing to you, but are the bread and butter of civil servants who turn EU rulings into local laws.
There are plenty of better sources of GDPR guidance around.  The UK’s own Information Commissioner’s Office (the ICO) has lots of useful stuff on their web site.  But even the introduction to their official overview states that “this is a living document and we are working to expand it in key areas”.  Translation: we have no idea either but we’re doing our best.
Organisations across the EU and the UK (might as well get used to saying it like that now) are rushing to understand GDPR and to adopt it.  Which is a good thing.  But one man’s compliance is another’s box-ticking.  I’m currently seeing lots of interest from potential customers of my security awareness training who are simply doing it to tick another box on the GDPR compliance checklist.  I worry that they won’t take it seriously, and that they’re doing it for the wrong reasons.
Remember the cookie laws?  Those EU-wide regulations which said that visitors to websites had to explicitly opt in to receiving cookies on their device?  The industry quickly worked out a loophole, which added a pointless question to every website and achieved absolutely no increase in data privacy whatsoever.  No one really wanted the rule, and the industry did as little as possible in order to comply with it and then pushed it out of their minds.  I sincerely hope that GDPR doesn’t end up the same way.  Its intentions are good, but it requires more than grudging compliance and box-ticking if you, and your business, hope to get anything useful from it.
 

Tags: Cybercybersecuritygdprsecuritysmarttech
ShareTweet
Previous Post

Real life consequences of cyberattacks: the exception, or soon to become the norm?

Next Post

One fifth of large British businesses surveyed have ‘no idea’ whether corporate policies are sufficient to comply with the EU GDPR

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol