Badmouthing Data Loss Prevention (DLP) is Fashionable Is DLP Really Dead? I recently came across several digital security vendor sites who describe themselves as a “DLP alternative.” Perusing through their pages, I came across comments such as “DLP … Read More
pii
GDPR and CCPA, An Update
A look at the compliance picture 3 months into the international year of privacy
Now that we’re a few months into 2019 it’s worth taking another look at the impact of recent sweeping privacy bills, in particular the EU’s General Data Protection (GDPR) regulatory regime, and California’s looming GDPR-inspired Consumer Privacy Act (CCPA).
GDPR has been in effect since May of last year, while CCPA comes into effect on January 1st, 2020. In both cases there have been significant developments.
Approaching a year of GDPR
One of the biggest questions swirling around GDPR in the run-up to its launch was how aggressively regulators would pursue and punish infractions – particularly given some of the ambiguities around how it’s tougher provisions could be enabled technically.
Well now we know, as well-known companies start to feel the EU’s wrath in the aftermath of cybersecurity breaches.
In the UK, cell phone retailer Dixons Carphone suffered a cyber-attack in 2018 that compromised some 1.2 million customer records, including names, as well as postal and email addresses. Under GDPR, companies face hefty fines if they fail to comply with provisions for handling customer data. For Dixons Carphone that could have meant a maximum penalty of 20 million EURO USD, however it appears they will face a smaller £500,000 fine in this case as the breach occurred before GDPR had come into force.
Regulators are understood to be looking for more high-profile test cases however, and it appears they could be spoiled for choice as GDPR has also had the effect of forcing breaches out into the open.
A recent study by global law firm DLA Piper has shown that over 59,000 personal data breaches have been reported across Europe since GDPR arrived. UK organizations have been hit by over 10,000 data breaches. Germany reported 12,600 breaches while the Netherlands had the top spot at 15,400.
The stumbling block for many seems to be GDPR’s requirement for identification and protection of Personally Identifiable Information or (PII). Companies that have been able to map where its PII is located, understand how it is used, and maintain a detailed library of data assets, may have actually benefited from new GDPR-driven efficiencies. This is both from having its data organized and catalogued, as well as minimizing fines and other losses from data breaches.
CCPA gets tougher – before its even come into force
The California Consumer Privacy Act is making its presence felt on the national legislative agenda even before it lands on New Year’s day 2020. Like GDPR, CCPA requires organizations to protect the personally identifiable information it holds on individuals.
But CCPA’s protections are even more stringent. For example, a host of biometric information is covered, as is any record of an individual’s browsing history or other interactions with a company website or app. Companies don’t have to be based in California or have a physical presence there to fall under the law. They don’t even have to be based in the United States.
CCPA’s wide-ranging requirements seem to have kicked off a biometric bandwagon at the state level, as more and more legislatures move to regulate the collection, use, and retention of biometric data.
Other States
In addition to CCPA’s arrival in 2020, Illinois , Texas , and Washington already have biometric privacy laws in place, while Arizona, Florida, and Massachusetts have recently proposed laws that will address biometric privacy. Washington State has also passed a new Washington Privacy act that borrows heavily from both the CCPA and GDPR. Other states are likely to join in.
Class Action Targets
Meanwhile legislators in California are already trying to make CCPA tougher. Under a proposed amendment to the law introduced in February, companies that gather and store personal data could find themselves the target of class-action lawsuits at the state level if they fall foul of CCPA’s provisions. Another proposal calls for data brokers to register with the California privacy authority, and for companies to disclose the value of their user data.
That opens up the possibility of user-driven lawsuits against the likes of Facebook, Google or Amazon for cash damages if they are found to have broken the law. Backed by the California Attorney General, the measure would turn up the heat on companies operating in the still emerging digital economy, and likely influence the shape of new federal regulations being considered by Congress.
Learning the lessons of GDPR?
Perhaps another link between GDPR and CCPA is the level of readiness companies report in the run-up to implementation. The tech and security press were running stories like this one on a regular basis prior to GDPR’s day zero, signalling fears about a compliance crash-out as a large percentage of organizations seemed blasé about the impending deadline.
In that sense a recent study by security vendor TrustArc has a ring of deju vu about it, suggesting that more than 80% of US businesses affected by CCPA are still not prepared.
The adoption of the US National Institute of Standards and Technology (NIST) cybersecurity framework or CSF is seen by many to be a stepping stone that will make CCPA compliance easier.
President Donald Trump issued an executive order in May of 2017 instructing all federal agencies to use the CSF. Italy, Israel, and Japan have also adopted the CSF in legislation, while companies that have implemented it include Microsoft, Boeing, Intel, and JP Morgan Chase.
What is the Right to erasure – right to be forgotten?
What is the Right to Erasure (‘right to be forgotten’) of the EU GDPR? The fast approaching General Data Protection Regulations (GDPR) of the European Union is the most comprehensive set of laws to hit the world of data … Read More
Insider Threats, preventing data exfiltration
The digital economy is undergoing remarkable transformation and security is being compelled to evolve as organizations embrace services that are more dynamic in nature. The things organizations do to grow, innovate, and drive performance change the cyber risk landscape every day.
Business leaders today are realizing that the digitalization is fundamentally enabling sharing of information across a multitude of platforms, not necessarily protecting it. They recognize that they are essentially at the mercy of their own employees and third parties associated with them to handle crucial business sensitive information.
On the other hand, cyber security incidents, including breach and disclosure of intellectual property, customer data, other sensitive data (e.g., GDPR, PII, PHI, PCI), are increasingly pervasive in today’s business environment. Data is one of a organization’s most vital asset and the cyber risks associated with data is crucial for any organization. According to a 2017 Insider Threat Report, out of all the potential cyber threats in the wild, insider threats is one of the most prevalent threats and associated incidents have risen due to economic conditions and insider access accorded to non-approved third parties.
So, fundamentally who is an insider threat? Any employee who has the potential to harm an organization for which they have inside knowledge or access. The past several years have seen some of the history’s most high-profile data breaches. The extent of data loss across the organization is incrementing year by year and so are the associated challenges in protecting the data.
The Ponemon Institute’s 2017 Cost of a Data Breach study estimates that in the US, the cost per record of a data breach is $201 per record (including many factors, direct and indirect). Those costs jump to $215 per record in the case of malicious attacks, or incident involving third parties. Obviously, this can add up to hundreds of thousands, or millions, depending on the amount of sensitive data involved.
But what the various cost analyses of cyber incidents don’t take into account is that malicious attacks are increasingly aimed not at the theft of sensitive data, but the serious disruption of operations, the elimination of data, or theft of intellectual property or information that can permanently impact market share and competitive advantage.
Recent attacks demonstrate that we need to change the game
There are multiple types of insider incidents seen across industries. The GTB perspective is that organizations cannot succumb to thinking of themselves as passive victims of cyber crime. However, we need to take stock of the fact that, it is our own relentless leveraging of technology, which create gaps that cyber criminals exploit.
To manage the risks arising from internal threats from a cyber risk perspective, though, means that it has to be taken on as a business problem. Executives do not need to suddenly become cyber security experts, but need to lead the discussion with an emphasis on:
- Focus on risk mitigation versus compliance requirements: Many organizations are heavily focused on addressing audit and regulatory findings, but the solutions implemented often do not help reduce risk and address threats that the company faces.
- Build and maintain a comprehensive inventory of sensitive assets and data: Many organizations don’t know where their data is. It’s very difficult to appropriately protect data if you don’t know where it is collected, stored, used, and transferred both inside and outside the organization.
- Focus on implementing solutions to protect data and monitor for data loss at the “data layer”: Many organizations are not effectively implementing critical capabilities such as Data Loss Protection (DLP) solutions, encryption and database activity monitoring, among others. Building the capability to monitor systems, applications, people, and the outside environment to detect incidents more effectively.
- Consistently execute the security fundamentals: Many organizations are still not consistently executing fundamental data protection capabilities (e.g., patching, privileged access, asset management), which leaves sensitive data even more vulnerable.
This may require more investment, but it may also simply entail a new approach. The crux of that approach is to recognize that managing cyber risk must be an inherent aspect of growth and innovation strategies. The two cannot be separated.
How secure is your data? Do you REALLY know? Find out now
Free Healthcare Data Risk & Audit Preparedness Assessment
Can you meet all those compliance & regulatory requirements? Do understand your HIPAA Risk?
Risk Analysis is the first step in an organization’s Security Rule compliance effort. Risk Management is a requirement. GTB’s Healthcare Data Risk Assessment allows an organization to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities of a covered entity’s ePHI.
Utilizing the GTB Data Protection that Works platform, organization’s will be able to start the required security risk analysis and audit preparedness as mandated by the HIPAA Security Rules and the HIPAA Privacy and Breach Notification Rules … at a substantial savings!
Free HIPAA Risk Assessment · Identify & Classify Regulated ePHI Data to be controlled · Identify potential places where this information might leak – all outbound channels & ports need to be inspected, not just HTTP, Email and the usual Web protocols · Scan data stores & Endpoints (laptops, USB, local drives, etc.) for regulated ePHI, PII, PCI information · Apply Policies & Controls – automatically, in real-time · Enterprise Reporting – accurate and detailed for Auditors & Administrators · No Cost Implementation, Training, Support and Report Review And a lot more Try it out Contact GTB’s Compliance Assurance Services for more information and to receive our latest Case Study:
|
Is your organization subject to FERPA regulations for student information?
Being Family Educational Rights and Privacy Act (FERPA) compliant is a must for today’s educational organizations. Confidential information sent to students, parents, colleagues, and other institutions must have protective controls and must remain private.
GTB DLP that Works Platform easily protects FERPA data while staying in compliance with state and federal regulations.
The ever-increasing use of email to communicate between teacher and student/parent including sending scanned attachments with PII, HIPAA, FERPA, and like data, intensifies the vulnerability of being out of compliance.
GTB DLP that Works platform can help with the ACCURATE detection and encryption of these communications.
GTB DLP that WorksTM Platform Secures Enterprise Healthcare Insurer