The GDPR: General Data Protection Regulation. Almost every business knows about this European data protection law. Much has been written about it in recent years, but practical explanations of how to approach it internally are often missing. How do you explain why certain actions should be avoided or reported? And how do you make the potential consequences for your organisation clear?
Past experience shows that employees are often the weakest link when it comes to security breaches. I do not mean loading sensitive information or personal data onto a USB stick and leaving it on your car’s passenger seat. I mean everyday computer use, where employees may not realise they have caused a data breach or know what steps to take when one occurs.
For example, you receive a reminder from an online shop you regularly use for work about something supposedly left in your basket. Only after clicking the link do you remember that you have not visited the site for a while. Or a message from your credit card company says your statement is ready, but arrives at an email address that is not linked to your card. These are simple examples of fake emails, yet any of us could fall for them, with potentially serious consequences for an organisation.
Organisations clearly need to do more to inform employees. Here are three tips.
1. Explain the damage phishing, viruses and ransomware can cause
Start with an explanation: many employees do not really know what these threats are. Ransomware in particular is becoming more sophisticated and more common. Fake emails remain a major route of infection, and people continue to fall for them despite repeated warnings.
To give a sense of the impact, security provider Datto calculated that ransomware-related downtime costs an SME around €7,500 per hour. Cybersecurity Ventures predicted that global ransomware damage would exceed US$5 billion in 2017.
2. Work closely with HR to help employees understand sensitive information
Explain the steps the company takes to protect data, and work with HR and IT to establish who can access which information. Have new employees joined? Has access for former employees actually been removed? Without a clear picture, demonstrating that data was properly protected under the GDPR will be difficult.
3. Before the summer holidays, raise awareness of the risks of free Wi-Fi
Work and private life are increasingly intertwined. As more organisations use cloud services, people can work almost anywhere, including from a beach, holiday home or campsite. Attackers can imitate public Wi-Fi networks and use them to intercept information or trick people into revealing credentials. If an employee enters business network passwords through an unsafe connection or fraudulent login page, company data may be put at risk.
In 2017, keeping business networks safe is no longer solely the IT department’s job. It is everyone’s responsibility. I regularly see IT clients dealing with data breaches, including breaches at third parties. Sometimes these are serious enough for our communications support to be needed too. Crisis communications, PR advice, Q&As, media monitoring and webcare: we are happy to help.
Inger
More security blogs and the crisis communications white paper
More news ›