Risk

1/24/2018
11:49 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Mind the GDPR gap: Board members at odds with management on level of GDPR compliance

  • 41% of board level respondents think they have all of the necessary processes in place to be GDPR compliant, yet, only 21% of middle management agree.
  • 56% of board members think they could handle hundreds of RTBF requests, yet only a third of middle management agree.
  • Data duplication is common within firms: 49% of board level respondents, and 31% of middle management, thought their organisation definitely duplicated customer data.
  • New whitepaper outlines recommendations for bridging this compliance gap, and growing a business through better information governance.

 

23rd January 2018, Theale UK – New research by data security company Clearswift has shown that board members are more confident than management about their organisation's ability to comply with the General Data Protection Regulation (GDPR), in time for the May 25th deadline.

The research, which surveyed 600 senior business decision makers and 1,200 employees across the UK, US, Germany and Australia, revealed that 41% of board level respondents think they have all of the necessary processes in place to be GDPR compliant, yet, only a quarter of senior management and even fewer middle management respondents (21%) thought the same.

It is important that the board understands the true state of GDPR compliance in order to address any issues in time for the May 25th deadline, and also to identify ways of growing their business through better information governance.

When it came to the right to be forgotten (RTBF), which entitles EU citizens to request that an organisation deletes all references to them that it holds, over half (56%) of board level respondents think that their organisation could handle hundreds of requests at once. Yet, only a third (36%) of middle management agree.

Not only did the research show a differing opinion between the board and management level respondents, but it also revealed insights into the extent of data duplication that exists within organisations. For example, 49% of board level respondents, and 31% of middle management, thought their organisation definitely duplicated customer data. 

Two thirds (66%) of board level respondents and 70% of senior management thought employees in their organisation have downloaded work documents to their personal devices (such as a laptop, smartphone or tablet) that they have not subsequently deleted (unintentionally or otherwise).

Dr Guy Bunker, SVP Products at Clearswift, said: “Board level respondents may have a misplaced confidence when it comes to their organisation’s level of GDPR compliance. However, once a board becomes aware that its confidence may be misplaced, then it is immediately one-step closer to compliance. By engaging closely with management, the board will have a much clearer and more accurate view of the state of compliance, and will be able to put measures in place to address any issues.”

“Middle management is more likely to have a better view of the data that their organisation holds – where it is saved and how it is being used – because they are more familiar with the day-to-day operations and challenges that staff may encounter. For example, if a company doesn’t have its own private file sharing service, then this may drive employees to use third party sites or download data onto a USB. Management should be encouraged by the board not to filter out ‘bad’ information. For example, if data duplication is rife then the board needs to know so it can address the issue in time for the GDPR deadline.”

Bunker added, “GDPR can be the first step towards better information governance: GDPR compliance is about being able to recognise a particular data set and protect it accordingly. The same processes and technology can be used to protect other types of information that are valuable to your organisation. For example, product design documents, price lists, patent applications and even information around service pricing and contract bids.”

Clearswift has published a whitepaper, The GDPR Divide: Board Views vs Middle-Management, which is available for download here: http://pages.clearswift.com/GDPR-divide-guide-2018.html

 

About Clearswift

Clearswift is trusted by organizations globally to protect critical information, giving them the freedom to securely collaborate and drive business growth. Its unique technology supports a straightforward and ‘adaptive’ data loss prevention solution, avoiding the risk of business interruption and enabling organizations to have 100% visibility of their critical information 100% of the time. As a global organization, Clearswift is headquartered in the United Kingdom, with offices in the United States, Germany, Australia and Japan and an extensive partner network across the globe.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
2018 on Track to Be One of the Worst Ever for Data Breaches
Jai Vijayan, Freelance writer,  11/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-9071
PUBLISHED: 2018-11-16
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.
CVE-2018-9073
PUBLISHED: 2018-11-16
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.
CVE-2018-9085
PUBLISHED: 2018-11-16
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
CVE-2018-9086
PUBLISHED: 2018-11-16
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
CVE-2018-19296
PUBLISHED: 2018-11-16
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.