Microsoft CISO argues against "digital xenophobia"

Bret Arsenault hits out at geographic data compliance differences

Microsoft's CISO Bret Arsenault decried "digital xenophobia" this week, criticising the breadth and variety of regulations and compliance measures around handling data among different countries.

Speaking at Infosecurity Europe 2017, he said:"I worry more about the digital xenophobia we see where all data needs to live within a government boundary. I worry we may go too far with it.I monitor about 350 regulations worldwide and it's the pending future ones which are the hardest to see ... Creating separate rules in every country is not economically viable."

Advertisement - Article continues below

Microsoft has already promised to write GDPRcompliance into its cloud contracts, to help customers meet the European Union's incoming stricter data protection rules governing how organisations can use and store EU citizens' data, which will homogenise data protection rules throughout the EU when it appliesin 2018.

The tougher lawaims to bring data protection legislation into line with new, previously unforeseen ways that data is now used. This will replace the UK's current Data Protection Act 1998, which was enacted following the 1995 EU Data Protection Directive. The new legislation introduces tougher fines for noncompliance and breaches, and gives people more say over what companies can do with their data.

However, the UK will leave the EU after voting for Brexit, meaning it will likely have to draw up its own data protection laws - even if similar, companies will have to deal with any differentiations between the two. Meanwhile, data location has become an issue of growing relevance to companies looking to store their data in different geographies in light of Edward Snowden's revelations about the extent of US spy hacking.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Among others, Microsoft itself opened up UK data centres last September to tout its services to public sector bodies and less cloud-friendly industries like finance. Collaboration firm Box used its alliance with IBM to allow customers to choose to store their data in different countries, allowing those wanting stricter protections to store it in Germany.

Arsenault added:"The one dream I have is that we get rid of passwords." He hopes instead that users can place their trust in devices themselves via growing use of biometrics as a measure to replace traditional credentials, despitea study revealing thatmost Brits distrust biometric security.

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/software/video-conferencing/355257/taiwan-first-country-to-ban-zoom-amid-security-concerns
video conferencing

Taiwan becomes first country to ban Zoom amid security concerns

8 Apr 2020
Visit/security/cyber-security/355271/microsoft-gobbles-up-corpcom-domain-to-keep-it-from-hackers
cyber security

Microsoft gobbles up corp.com domain to keep it from hackers

8 Apr 2020