This means that the majority of organizations in this study are failing to comply with Sarbanes-Oxley, the UK Data Protection Act 1988 and the EU Data Directive on Privacy which may result in organizations being subject to 2% fines of global revenue.
David Gibson, director of strategy for Varonis, explained, “It’s worrying that so many companies are still complacent when it comes to data protection. It means that these organizations would have some serious questions to answer should they suffer a breach. In fact, regulators such as the SEC, ICO and EU would likely deem that they had failed in their obligation to provide appropriate security protection to prevent sensitive data breaches and impose a hefty financial penalty. It’s really not rocket science - if you’ve got sensitive data and you’re not very confident that it’s adequately protected, you need to take action.”
When looking at the difference between organizations, of those who claimed to be very confident that their data was protected, 60% were very confident that they know where their sensitive data is stored. Over 40% monitor all actual access activity and assign owners to all folders and intranet sites. Additionally, 65% review and revoke permissions– 45% do so regularly, so not just when someone leaves the organization.
Unsurprisingly, those who are not confident that the data within their organizations is protected do not know where their data is stored (10%), do not monitor all data access (0%), do not have owners assigned for all data (3%), and less regularly review and revoke access.
For an infographic on The State of Data Protection, and to download the full report, visit http://www.varonis.com/thanks/downloads/download-dataprotection.html
Varonis is the leader in unstructured and semi-structured data governance for file systems, SharePoint and NAS devices, and Exchange servers. The company was named "Cool Vendor" in Risk Management and Compliance by Gartner, and voted one of the "Fast 50 Reader Favorites" on FastCompany.com. Varonis has over 4500 installations worldwide. Based on patented technology and a highly accurate analytics engine, Varonis' solutions give organizations total visibility and control over their data, ensuring that only the right users have access to the right data at all times. Varonis is headquartered in New York, with regional offices in Europe, Asia and Latin America
Varonis, the Varonis logo, DatAdvantage and DataPrivilege are registered trademarks of Varonis Systems in the United States and/or other countries and Data Classification Framework and Metadata Framework are under a registration process in the United States and/or other countries. All other product and company names and marks mentioned in this document are the property of their respective owners and are mentioned for identification purposes only.