Will the GDPR prevent the next headline-grabbing data breach?

Will the GDPR prevent the next headline-grabbing data breach?

Gavin Millard says that while having a Regulation such as the EU GDPR in place would have reduced the chance of a breach the size of Yahoo!, practicing good cyber-hygiene and timely disclosure have the best effects when dealing with any major breach that compromises personal data.

In a world where new malware and vulnerabilities are discovered every day, one of the more concerning aspects of recent high-profile data breaches are the long periods of time between detection of the compromise and disclosure of the breach.

The revelation that the Yahoo! breach was discovered nearly two years before it was disclosed has highlighted the ambiguity of the US Securities and Exchange Commission (SEC) 2011 requirements that detail cyber-attack disclosures. As a result, pressure is being placed on the agency to investigate not only if senior executives at Yahoo! acted appropriately when disclosing the attack, but also whether the current disclosures process is adequate.

With the European Union (EU) General Data Protection Regulation (GDPR) introduction just 18 short months away, there is even less room for uncertainty. 

Will legislation finally be enough to call time on an era of massive data breaches?

The longer an organisation waits to disclose a breach, the more likely it is that the users exposed will be leveraged for further exploitation. It stands to reason then that if we're going to lessen the impact and risk of a breach, stronger security measures and faster disclosure times must be enforced.

In May 2018, the EU GDPR will impose strict data breach disclosure regulations, requiring organisations to notify authorities of any data loss incident ‘without undue delay and, where feasible, not later than 72 hours.' That might seem like an impossible standard, but as attackers become more sophisticated, this level of accountability can lessen the impact on potential victims.

What perhaps is more concerning is that the latest developments in the Yahoo! breach suggest the company lacked sufficient investment in basic security measures.

 

Share it:
Share it:

[Social9_Share class=”s9-widget-wrapper”]

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

You Might Be Interested In

GDPR keeping you up? There’s another monster hiding under the bed…

4 Feb, 2018

Everyone in the security world is talking about the EU’s General Data Protection Regulation (GDPR), and rightly so. GDPR is …

Read more

How IT leaders can drive digital innovation

5 Jun, 2022

Today’s CIOs and chief digital officers have a critical dual challenge — they need to lead both technology and cultural …

Read more

Ford Eyes Using Personal Data to Boost Profits

23 Nov, 2018

Ford Motor Company is known for making cars and trucks; but the future for the iconic automaker might look a …

Read more

Do You Want to Share Your Story?

Bring your insights on Data, Visualization, Innovation or Business Agility to our community. Let them learn from your experience.

Get the 3 STEPS

To Drive Analytics Adoption
And manage change

3-steps-to-drive-analytics-adoption

Get Access to Event Discounts

Switch your 7wData account from Subscriber to Event Discount Member by clicking the button below and get access to event discounts. Learn & Grow together with us in a more profitable way!

Get Access to Event Discounts

Create a 7wData account and get access to event discounts. Learn & Grow together with us in a more profitable way!

Don't miss Out!

Stay in touch and receive in depth articles, guides, news & commentary of all things data.