Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Is the Hype around GDPR putting you at risk?

by The Gurus
January 29, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

Most information security managers are well aware of the need to comply with GDPR – the EU’s regulations on how organisations manage, store, transfer and delete customer data

Andy Barratt, UK managing director at cybersecurity specialist, Coalfire, examines how the intense focus on compliance with these new requirements, especially at board level, could be leaving some businesses at greater risk rather than less.

The implementation of GDPR next April will undoubtedly encourage firms to tighten security around the way they gather and handle data.

And rightly so. Data breaches are a real threat to businesses’ ability to operate, as well as to the trust that consumers and customers place in them.

But compliance is never the only risk that information security managers need to control and, as companies work to deal with these new regulations, there is a risk that they will become distracted from other potential threats.

There is even a chance that some criminals have already begun looking elsewhere for an easy target.

So what can managers do to ensure that delivering success in one area doesn’t become a recipe for disaster somewhere else?

Balancing resources

As any compliance deadline approaches, information security managers should have a plan in place on how they are going to ensure meet the new requirements in good time.

The challenge is to use what resources they have to execute those plans without neglecting any other areas of risk.

With finite budgets and pressure coming from your board of directors – many of whom are currently keenly aware of GDPR – it can be difficult to decide what work should take priority, and what can wait.

In this, the challenge is to meet the hard deadline of compliance without overlooking other everyday tasks like maintaining up-to-date security controls elsewhere.

Data hype

There’s no doubt that one of the reasons GDPR is being introduced in the first place is due to the huge hype that has surrounded data in recent years.

Cybercriminals have targeted data either by stealing it for their own purposes or, more commonly, by using the theft it to extort money from their victims.

But it is not the only way that cybercriminals can profit from attacking a business.

As data becomes more difficult to steal, point of sale systems could be one such area that could be ripe for attack.

Point of sale

When cash was king, one way for criminals to make off with large sums of money was an old-fashioned heist.

Targeting businesses with high value sales – such as jewellers’ shops – criminals would use the threat of violence to persuade staff to hand over thousands, or even millions, of pounds of goods.

In today’s world of ubiquitous electronic payments, the point of sale system is now all that stands between a potential criminal and their loot.

When a customer uses a credit card to buy an expensive Rolex watch, for example, staff place all their trust in their point of sale system: a green tick on a screen denotes the transaction has been authorised, so they hand over the goods.

If a cybercriminal can manipulate this system to show that green tick even when no transaction has taken place, they can trick staff into handing over very valuable goods without payment.

And because hacking a PoS system leaves very little signature, the businesses involved often won’t know that anything untoward has even taken place until payments fail to reconcile in the usual way several hours, or even days, later.

Winning over the board

But ensuring these systems remain secure against fast-developing threats while also complying with GDPR means juggling different priorities, even if those at the top of the organisation are initially only interested in one of them.

The first step is to recognise that GDPR creates an opportunity for those with an information security remit to win their board’s wider support.

With a little skilful encouragement, most directors can be persuaded that compliance and security are interwoven.

Those who are good at managing upwards will be able to use this newfound visibility among the C-suite to show the many very real risks that they handle every day.

By speaking their language and highlighting continuing security threats, a skilful manager can win their board’s backing, and manage their resources appropriately to cover all their priorities.

Conclusion

Negotiating with the leadership team might seem daunting for managers who, until now, have little experience of working in the spotlight of the board of directors.

But any success in complying with new regulations on time will be short-lived if it means that the risks taken elsewhere have left you wide open to the type of cybercrime that this regulation was designed to guard against.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Is the bright web more dangerous than the dark?

Next Post

UK Government demanding better cyber security to protect Critical Infrastructures

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol