Connect with us

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website. .

Business

DELL SURVEY SHOWS ORGANISATIONS LACK AWARENESS AND PREPARATION FOR NEW EUROPEAN UNION GENERAL DATA PROTECTION REGULATION (GDPR)

Dell Survey Shows Organisations Lack Awareness and Preparation for New European Union General Data Protection Regulation (GDPR)
  • More than 80 percent of global respondents know few details or nothing about GDPR
  • Less than one in three companies feel they are prepared for GDPR today
  • 97 percent of companies don’t have a plan to be ready for GDPR
  • Only nine percent of IT and business professionals are confident they will be fully ready for GDPR

Dell today announced results of a global survey on the European Union’s new General Data Protection Regulation (GDPR), revealing that organisations ‒ both SMBs and large enterprises ‒ lack general awareness of the requirements of the new regulation, how to prepare for it, and the impact of non-compliance on data security and business outcomes.

Designed to strengthen protection of personal data for all EU citizens, the new regulation goes into effect in May 2018 and affects companies of all sizes, in all regions, and in all industries. Those not fully compliant when GDPR goes into effect risk significant fines, potential breaches and loss of reputation.

Survey results show that 82 percent of global IT and business professionals responsible for data security at both SMBs and enterprises are concerned with GDPR compliance. Although the majority of global IT and business professionals express compliance concerns, respondents lack general awareness of GDPR, and they are neither prepared for it now, nor expect to be when it goes into effect.

  • More than 80  percent of respondents say they know few details or nothing about GDPR
  • Less than one in three companies feel they are prepared for GDPR today
  • Close to 70 percent of IT and business professionals say they are not nor don’t know if their company is prepared for GDPR today, and only three percent of these respondents have a plan for readiness
  • Respondents in Germany feel most prepared for GDPR (44 percent), while respondents in Benelux (Belgium, the Netherlands, Luxembourg) feel least prepared (26 percent)
  • More than 75 percent of respondents outside Europe say they are not or don’t know if they are prepared for GDPR
  • Nearly all companies (97 percent) don’t have a plan in place when GDPR kicks off in 2018

Results further show that while organisations realise failure to comply with GDPR will impact both data security and business outcomes, they are unclear on the extent of change required, or the severity of penalties for non-compliance and how changes will affect the business. Seventy nine percent say they would not, or were not aware whether their organisation would face penalties in its approach to data privacy if GDPR had been in effect this past year.

  • Of the 21 percent of respondents who said they would face a penalty if GDPR were in place today, 36 percent think it would require only an easy remediation, or don’t know the penalty
  • Close to 50 percent believe they would face a moderate financial penalty or manageable remediation work
  • Nearly 25 percent expect significant changes in current data security practices and technologies

Additional findings show that most organisations don’t feel well-prepared across security disciplines for GDPR compliance.

  • Less than half of respondents feel well-prepared for any of the security disciplines impacting GDPR
  • Only 21 percent feel well-prepared for access governance, a key security discipline for GDPR
  • More than 60 percent of enterprise respondents in Europe either are not or don’t know if they are prepared for GDPR. Nearly 70 percent of SMB respondents in this region said they are not or don’t know if they are prepared for GDPR
  • More than 90 percent of respondents say their existing practices will not satisfy the new GDPR requirements
  • More than 80 percent said they are well- or somewhat prepared with their organisations’ current email security technologies
  • Nearly 60 percent said they are well- or somewhat prepared with their organisations’ current access governance technologies
  • More than 80 percent said they are well- or somewhat prepared with their access management technologies
  • 65 percent said they are well- or somewhat prepared with their next generation firewall (NGFW) technologies

Best practices help successfully address GDPR requirements and avoid the consequences of non-compliance

  • Hire a data protection officer (DPO). A requirement for GDPR, the position can be full-time, or filled by an employee with other responsibilities or an outsourced agency. The good news is that a designated DPO can be used as a service, so some system integrators or resellers could offer this as a service to grow their businesses.
  • Deploy a firm access governance solution. The ability to govern access to applications that permit access to EU citizens’ personal data ‒ particularly unstructured data ‒ is a major factor in data security and GDPR compliance. Governance generally requires periodic review of access rights by line-of-business managers and attestation (or recertification) that the permissions align with their job roles and do not compromise data security. The One Identity family of Identity and Access Management solutions provides this level of visibility and control.
  • Control access management. To satisfy GDPR, employees and contractors must have the correct access permission to do their jobs and nothing more. The right identity and access management technologies that facilitate this level of control include multi-factor authentication, secure remote access, risk-based/adaptive security, granular password management, and full control over privileged user credentials and activity.
  • Protect the perimeter. Deploy next-generation firewalls to reduce the network’s exposure to cyber threats, mitigate the risk of data leaks that could lead to a data breach resulting in stiff penalties assessed under GDPR, and deliver the forensic insight required to prove compliance and execute appropriate remediation following a breach. The Dell SonicWALL next-generation firewalls protect against emerging threats and feature deep packet inspection; real-time decryption and inspection of SSL sessions; adaptive, multi-engine sandboxing; and full control and visualisation of applications.
  • Facilitate secure mobile access. Foster the secure flow of covered data while enabling employees to access the corporate applications and data they need in the way they prefer, and with the devices they choose. Enhance data security (while removing access obstructions) by combining identity components, device variables and temporal factors (time, location, etc.) to deliver an adaptive, risk-based approach that ensures the right access all the time, every time, while concurrently improving data protection and GDPR compliance. 
  • Ensure email security. To fulfill GDPR requirements, achieve full control and visibility over email activity to mitigate the threat of phishing and other email-based attacks on protected information, while enabling the secure and compliant exchange of sensitive and confidential data. 

Methodology

In the survey, conducted by Dimensional Research, 821 IT and business professionals responsible for data privacy at companies with European customers responded to questions about awareness, perception and readiness for GDPR, and the expected impact of non-compliance when GDPR comes into force in May 2018. The survey was conducted across the United States, Canada, Asia Pacific (Australia, Hong Kong, Singapore, India), United Kingdom, Germany, Sweden, Belgium, The Netherlands, France, Italy, Spain and Poland. Business executives at organisations with fewer than 100 employees also completed the survey.

Global Banking & Finance Review

 

Why waste money on news and opinions when you can access them for free?

Take advantage of our newsletter subscription and stay informed on the go!


By submitting this form, you are consenting to receive marketing emails from: Global Banking & Finance Review │ Banking │ Finance │ Technology. You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Recent Post