Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

GDPR and how to avoid the fines

by The Gurus
January 18, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

Cyber-attacks and privacy threats are now a high-profile concern across all sectors. With 2018 just around the corner and The General Data Protection Regulation (GDPR) coming into effect on 25 May, 2018. Small and middle-sized businesses (SMBs) need to be prepared for this new regulation. In order for SMBs to comply with GDPR its decision makers and key people in the organisation need to be aware that the law is changing. Also, they need to appreciate the impact this is likely to have within the organisation. Furthermore, SMBs that hold data on EU citizens have a responsibility for the protection of the data they store. This data needs to be stored systematically and protected from theft and misuse.

 

SMBs also need to be able to meet GDPR data subject’s rights which are as follows:

  • to be informed about data processing
  • to access their data
  • to rectify or delete their data
  • to take their data to another organisation

 

How can they avoid the fines?

 

Data retention is also an important factor. SMBs can avoid the fines by deleting data after a certain time has expired, for example personal data collected in connection to a product purchase and associated warranty. In addition, there are other types of data that needs to be restored for a minimum, amount of time. Such as certain financial data. This means that SMB’s need to know where personal data is stored and able to respond to data requests in a timely manner.

 

 

What should they be doing?

 

Smaller and medium-sized organisations have to ensure they approach data protection by ‘design and default’. At a high level it means that companies must secure their systems and processes to ensure data does not leak out or is easily hacked. It requires that data protection is designed into the development of business processes for products and services. This requires that privacy settings must be set at a high level by default, and that technical and procedural measures throughout the entire data processing lifecycle complies with the regulation. Additionally, organisations need to implement mechanisms to ensure that personal data is only processed when necessary for each specific purpose.

 

Furthermore, SMBs need data storage that is both easy to access and manage and also has privacy and protection designed into its foundation.

  • If they plan to store data in-house, their business will be both the data controller and data processor. As a result it will be fully liable to the repercussions should any of this data be hacked or the regulations breached

 

  • If they plan to use a public cloud or hybrid-storage solution, it is the responsibility of the business to ensure that it and the third-party provider are GDPR compliant

 

  • Password protection – Devices and files and/or folders that contain personal data should be protected by passwords. They should only be accessible to users who have the permission to access and/or process the data

 

  • Encryption – data should always be encrypted whether stored or transferred

 

  • Physical protection from theft / loss – devices that store personal data should have physical protection such as a Kensington lock or keys for NAS and hard drives in a server, or similar

 

  • Anti-virus software to ensure that data isn’t infected with malware such as ransomware

 

  • Firewall protection

 

  • Backup and Restore –backups should be automated and carried out daily so in the event of data loss the most recent copies of personal data can be retrieved

 

  • Centralised storage should be preferred over local storage on PCs, laptops or external or portable hard drives. These devices are more prone to theft and unauthorised access. It’s also extremely difficult to control who has access to them and the data on them

 

Anything different from what the larger corporations are doing?

 

Unlike most large organisations, Some SMBs are adopting a ‘wait and see’ approach. They believe that GDPR mainly addresses and affects big corporations that collect and deal with huge amounts of personal data, such as social networks, cloud providers or search engines. Many of these organisations are waiting to see what happens when a peer company falls foul of the legislation.

 

Therefore, this approach is potentially damaging given that the threat of insolvency or even closure as a result of GDPR penalties is very real. GDPR applies to all companies; no matter how big they are or how much their turnover.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

One Identity Acquires Balabit to Bolster Privileged Access Management Solutions

Next Post

75 per cent of IT executives lack control over password security in their organisations

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol