Risk

1/24/2018
11:49 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Mind the GDPR gap: Board members at odds with management on level of GDPR compliance

  • 41% of board level respondents think they have all of the necessary processes in place to be GDPR compliant, yet, only 21% of middle management agree.
  • 56% of board members think they could handle hundreds of RTBF requests, yet only a third of middle management agree.
  • Data duplication is common within firms: 49% of board level respondents, and 31% of middle management, thought their organisation definitely duplicated customer data.
  • New whitepaper outlines recommendations for bridging this compliance gap, and growing a business through better information governance.

 

23rd January 2018, Theale UK – New research by data security company Clearswift has shown that board members are more confident than management about their organisation's ability to comply with the General Data Protection Regulation (GDPR), in time for the May 25th deadline.

The research, which surveyed 600 senior business decision makers and 1,200 employees across the UK, US, Germany and Australia, revealed that 41% of board level respondents think they have all of the necessary processes in place to be GDPR compliant, yet, only a quarter of senior management and even fewer middle management respondents (21%) thought the same.

It is important that the board understands the true state of GDPR compliance in order to address any issues in time for the May 25th deadline, and also to identify ways of growing their business through better information governance.

When it came to the right to be forgotten (RTBF), which entitles EU citizens to request that an organisation deletes all references to them that it holds, over half (56%) of board level respondents think that their organisation could handle hundreds of requests at once. Yet, only a third (36%) of middle management agree.

Not only did the research show a differing opinion between the board and management level respondents, but it also revealed insights into the extent of data duplication that exists within organisations. For example, 49% of board level respondents, and 31% of middle management, thought their organisation definitely duplicated customer data. 

Two thirds (66%) of board level respondents and 70% of senior management thought employees in their organisation have downloaded work documents to their personal devices (such as a laptop, smartphone or tablet) that they have not subsequently deleted (unintentionally or otherwise).

Dr Guy Bunker, SVP Products at Clearswift, said: “Board level respondents may have a misplaced confidence when it comes to their organisation’s level of GDPR compliance. However, once a board becomes aware that its confidence may be misplaced, then it is immediately one-step closer to compliance. By engaging closely with management, the board will have a much clearer and more accurate view of the state of compliance, and will be able to put measures in place to address any issues.”

“Middle management is more likely to have a better view of the data that their organisation holds – where it is saved and how it is being used – because they are more familiar with the day-to-day operations and challenges that staff may encounter. For example, if a company doesn’t have its own private file sharing service, then this may drive employees to use third party sites or download data onto a USB. Management should be encouraged by the board not to filter out ‘bad’ information. For example, if data duplication is rife then the board needs to know so it can address the issue in time for the GDPR deadline.”

Bunker added, “GDPR can be the first step towards better information governance: GDPR compliance is about being able to recognise a particular data set and protect it accordingly. The same processes and technology can be used to protect other types of information that are valuable to your organisation. For example, product design documents, price lists, patent applications and even information around service pricing and contract bids.”

Clearswift has published a whitepaper, The GDPR Divide: Board Views vs Middle-Management, which is available for download here: http://pages.clearswift.com/GDPR-divide-guide-2018.html

 

About Clearswift

Clearswift is trusted by organizations globally to protect critical information, giving them the freedom to securely collaborate and drive business growth. Its unique technology supports a straightforward and ‘adaptive’ data loss prevention solution, avoiding the risk of business interruption and enabling organizations to have 100% visibility of their critical information 100% of the time. As a global organization, Clearswift is headquartered in the United Kingdom, with offices in the United States, Germany, Australia and Japan and an extensive partner network across the globe.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Facebook Aims to Make Security More Social
Kelly Sheridan, Associate Editor, Dark Reading,  2/20/2018
SEC: Companies Must Disclose More Info on Cybersecurity Attacks & Risks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  2/22/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.