Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Veritas Study: Organisations worldwide mistakenly believe they are GDPR compliant

by The Gurus
October 6, 2017
in Editor's News
Share on FacebookShare on Twitter

A study from Veritas Technologies, a leader in multi-cloud data management, has found that organisations across the globe mistakenly believe they are in compliance with the upcoming General Data Protection Regulation (GDPR).
 
According to findings from The Veritas 2017 GDPR Report, almost one-third (31 per cent) of respondents said that their enterprise already conforms to the legislation’s key requirements. However, when those same respondents were asked about specific GDPR provisions, most provided answers that show they are unlikely to be in compliance. In fact, upon closer inspection, only two per cent actually appear to be in compliance, revealing a distinct misunderstanding over regulation readiness.
 
“With the EU’s General Data Protection Regulations (GDPR) less than one year away, organisations around the world are deeply concerned about the impact that information non-compliance can have on their brand and loyalty of their customers,” said Jason Tooley, Vice-President, Northern Europe, Veritas.
 
The findings from the report show that almost half (48 per cent) of organisations who stated they are compliant do not have full visibility over personal data loss incidents. Moreover, 61 per cent of the same group admitted that it is difficult for their organisation to identify and report a personal data breach within 72 hours of awareness – a mandatory GDPR requirement where there is a risk to data subjects. Any organisation that is unable to report the loss or theft of personal data – such as medical records, email addresses and passwords – to the supervisory body within this timeframe is breaking with this key requirement.
 
The findings in this report suggest that organisations that think they are already compliant with the GDPR should revisit their compliance strategies. Failure to meet GDPR requirements could attract a fine of up to four percent of global annual turnover or €20 million, whichever is greater.
 
Tooley added: “The results today show that more education is needed on the tools, processes and policies to support information governance strategies that are required to comply with the GDPR requirements. Creating an automated, classification-based, policy-driven approach to GDPR is key to success and will enable organisations to accelerate their ability to meet the regulatory demands within the short timeframes available.”
 
 
The former employee threat
 
Restricting former employee access to corporate data and deleting their systems credentials helps to stem malicious activity and ensure that financial loss and reputational damage are avoided. Yet, a staggering 50 per cent of so-called compliant organisations said that former employees are still able to access internal data. These findings highlight that even the most confident organisations struggle to control former employee access and are potentially susceptible to attacks.
 
Challenges exercising “the right to be forgotten”
 
Under the GDPR, EU residents will have the right to request the removal of their personal data from an organisation’s databases. However, Veritas’ research shows many organisations that stated they already are in compliance will not be able to search, find and erase personal data if the “right to be forgotten” principle is exercised.
 
Of the organisations that believe they are GDPR-ready, one-fifth (18 per cent) admitted that personal data cannot be purged or modified. A further 13 per cent conceded that they do not have the capability to search and analyse personal data to uncover explicit and implicit references to an individual. They are also unable to accurately visualise where their data is stored, because their data sources and repositories are not clearly defined.
 
These shortcomings would render a company non-compliant under the GDPR. Organisations must ensure that personal data is only used for the reasons it was collected and is deleted when it’s no longer needed.
 
Demystifying GDPR responsibility
 
Veritas’ research also found that there is a common misunderstanding among organisations regarding the responsibility of data held in cloud environments. Almost half (49 per cent) of the companies that believe they comply with the GDPR consider it the sole responsibility of the cloud service provider (CSP) to ensure data compliance in the cloud. In fact, the responsibility lies with the data controller (the organisation) to ensure that the data processor (the CSP) provides sufficient GDPR guarantees. This perceived false sense of protection could lead to serious  repercussions once the GDPR is enacted.
 
“Organisations who actively focus on development of a culture of data confidence will have a clear business advantage. Customer and supplier confidence in the use of data is critical to improved customer engagement, greater personalisation and ultimately service quality. This allows organisations to turn GDPR from being a regulatory challenge to being a business differentiator,” Tooley commented.
 
“The complexity created through the management of data across multiple cloud and on-premise environments is accentuating the challenge and will inhibit an organisation’s ability to remain compliant in the face of the GDPR articles. For every organisation that’s currently struggling to make sense of the GDPR’s provisions, it should immediately seek an advisory service to audit its levels of preparedness and create a smooth and accelerated path towards total compliance.”
 
The GDPR is intended to harmonise data privacy and protection mandates across European Union (EU) member states. It requires organisations to implement the appropriate protection measures and processes to effectively govern personal data. The GDPR will take effect on May 25, 2018 and will apply to any organisation – inside or outside the EU – that offers goods or services to EU residents, or monitors their behaviour.
 
For information on how Veritas Technologies can help your organisation become GDPR compliant visit https://www.veritas.com/gdpr.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

IT teams and the C-suite must work together to deliver comprehensive cyber-security, says EACS

Next Post

Winners of Security Serious Unsung Heroes 2017 announced!

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol