Data protection law unclear to companies
By Rene Millman,
The law over data protection is unclear and is preventing organisations from dealing with the scale and complexity of the problem, according to a security expert.
In the light of the story carried by IT PRO yesterday in which Information Commissioner Richard Thomas told chief executives that they would have to act now to prevent data breaches, experts said many companies are shying away from the problem.
"They are hiding their heads in the sand, hoping that they won't be the next victim of a high profile breach," said Steve Hurn, chief executive of database security company Secerno. "However, storing huge volumes of data on a system without using the appropriate database security technology is akin to operating without a firewall or anti-virus technology - it's a case of when a security breach will happen, not if."
He said that companies can mitigate risk by only allowing employees access to the data needed to carry out their job.
"A company wouldn't make its payroll details accessible to anyone outside of its payroll or finance departments, so why make other equally valuable data available to those that do not need access to it?" said Hurn.
Hurn said that one area often overlooked by companies was that they very rarely monitor access to sensitive data by systems administrators.
Ross Paul, Product Management director at Websense said that by 2010 he expected around 80 to 90 per cent of data breaches to be unintentional, accidental or the result of poor business processes. He also said that data leaks are mostly invisible.
"Whether unintentional, intentional or malicious in nature, the ramifications of information leaks can be significant," said Paul. "For many organisations, losing customer information isn't the only risk; intellectual property, merger and acquisition plans, product launch dates, distribution strategies, and other confidential information pertinent to the day-to-day business must remain secure in order to sustain a competitive advantage."
He said that leaks not only cause monetary loss but also the organisation's reputation would suffer as a result. There would also be regulatory concerns as well.
"The difference with data breaches is the scale of the impact for both businesses and the general public," he said. "If an employee sends out customer details or the company forecast ahead of the official announcement, the impact goes far beyond IT and HR. The Board and regulatory bodies such as the FSA would want to know as this is something of direct and immediate relevance to the business."
Others believe that the organisations are not recognising the importance of managing personal data.
"Good business practice is central to making an organisation compliant-ready, alongside industry specific regulation and internal policies," said Symon Blomfield, cheief executive of secure IM company Presence Networks. "Likewise, it is essential to include comprehensive monitoring to ensure all content is recorded, in the event of an investigation like we have seen today - or to satisfy an auditor examination."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Data Protection Analysis & Insight
The Digital Economy Act: Is it doomed to never happen?
As a further delay hits part of the implementation of the Digital Economy Act, is this just a small hiccup, or is the Act being rendered toothless already? Simon Brew takes a look.
- Does the government want to snoop on your data?
- Have ISPs finally lost the DEA fight?
- Google and privacy: What’s the problem?
- Striving to solve the security skills crisis
- Erase and rewind: the EU and privacy
- 2011: The year in news
- Are the cookie laws crumbling already?
- How the Data Protection Act's death will punish the UK economy
- Cloud computing: Worth the risk?
Latest Data Protection Reviews
Sophos Endpoint Security and Data Protection 9.7 review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Hutchison denies it will pull plug on Three UK
- EMC World 2012: Tucci declares Documentum is here to stay
- ICO: Fines for cookie law breakers
- EMC World 2012: EMC talks up cloud, security and big data
- Dell PowerEdge R820 review
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- CIO: Career is over?
Latest News Videos in Data Protection
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





