Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

GDPR to Put a High Price on Security Breaches

by The Gurus
March 20, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

By Ronald Sens, EMEA Director, A10 Networks

Security breaches are already costly; not just financially, but in terms of brand damage, customer dissatisfaction and downtime. For companies that do business with residents of the European Union (EU), the financial fallout from a security breach is about to get much more expensive. That’s why it’s imperative for organisations to get ready for GDPR now, so they’re not playing catch-up.

What is the GDPR?
With the introduction of the General Data Protection Regulation (GDPR), the EU is enacting a set of mandatory regulations for businesses that go into effect soon, on May 25, 2018. Organisations found in non-compliance could face hefty penalties of up to 20 million euros, or 4 percent of worldwide annual turnover, whichever is higher.

Simply put, GDPR was enacted to give citizens and residents more control over their personal data and puts strict data handling rules in place governing “controllers” that collect data from EU residents, and “processors” that process the data on behalf of controllers, such as cloud providers.

The GDPR is not just applicable to businesses in the EU, it applies to the data of all EU citizens, regardless of where it’s stored. That means if a citizen of the EU has data stored with a company inside the U.S., then GDPR applies.

Under the GDPR, data controllers must report a data breach to the supervising authority within 72 hours of becoming aware of the breach. From there, individuals must be notified if an adverse impact is determined, and the data processor must notify a controller without undue delay after becoming aware of a personal data breach.

Neither the processors nor controllers, however, must notify data subjects if anonymised data is breached – meaning if the controller has implemented encryption and other measures to protect data. The regulation, however, broadly defines a data breach as:

“a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.”

GDPR also gives consumers and individuals more power. Article 17 of the GDPR is the “right to erasure,” which is more commonly known as the “right to be forgotten.” Article 17 empowers individuals to request that a data controller erase all their personal data without delay and at no cost. It means all data, such as files, records, backup and archived copies – all of it.

The GDPR lights a fire under organisations to implement stronger security measures to protect their networks and data and, in the event of a breach, report it swiftly. It also makes it a legal obligation to configure security systems to put data privacy and consumer protection first.

Prepping for GDPR
So how do companies ensure their systems and their customers’ data are protected when the GDPR takes effect? As with most security recommendations, it’s about having a battle plan in place well beforehand.

Gartner recommends a good starting point for GDPR prep is to create two new roles dedicated to data protection: One who acts as a contact point for the data protection authority and data subjects, and the other a data protection officer to ensure processing operations maintain compliance.

From there, companies should be proactive and transparently demonstrate accountability for all processing activities, examine how data flows across borders within the EU and outside of it, and ensure they have systems in place notify individuals and authorities should a breach occur and to comply with the right to be forgotten should an individual ask for their data to be erased.

It’s also imperative that companies have systems in place to prevent breaches in the first place. Notification is not required for breaches involving anonymised data, but companies should examine their encryption solutions to ensure their private data is and remains private.

Tools That Can Help Protect Your Data
A dedicated decryption can ensure encrypted data is decrypted for visibility and inspection, in a secure decrypt zone, and companies can opt to bypass certain types of traffic that should remain encrypted and anonymised such as personal data as policies dictate. That gives organisations the benefit of decryption services, while still complying with GDPR.

Companies can also institute stronger identity hygiene practices to ensure attackers aren’t attempting to crack into networks to steal data. Simple steps like multi-factor authentication, and swiftly depreciating expired employee accounts can help ensure access is only granted to authorised personnel.

Analytics solutions, can help by enabling companies to quickly and accurately detect security anomalies. Having an understanding of how applications are performing in real-time and their security posture could alert an organisation in the event of a breach or an attempted data theft.

ShareTweet
Previous Post

Cyber Threatscape Top 10: Phishing emails deemed number one threat by UK businesses

Next Post

UK police forces spend £1.3m on cybercrime training in three years

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol