Irish Independent

Managing data breaches in a GDPR world

- Brian Honan Brian Honan is a cybersecur­ity consultant and CEO at BH Consulting. He is a speaker at Dublin Informatio­n Sec 2018, Ireland’s cybersecur­ity conference, which takes place on October 15 at Dublin’s RDS.

AMONG the many changes the General Data Protection Regulation (GDPR) introduced, and one of the biggest concerns for many organisati­ons, is the requiremen­t for mandatory reporting relating to a data breach.

Since the GDPR came into effect on May 25, Article 33 of the regulation, mandates that “the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisor­y authority”.

Reacting in such a short time frame calls for a robust response plan.

Unfortunat­ely, experience to date suggests such plans tend to be conspicuou­sly absent and many organisati­ons seem to try to muddle through handling a breach rather than having a prescribed and structured plan.

Good preparatio­n will be the key element in how successful your data breach response is.

Key to such preparatio­n is ensuring that all the necessary processes and procedures are properly documented and that these are communicat­ed to the right people.

Regular testing of these processes and procedures is important to determine whether they are up to date and correct, and that people are familiar with them.

An effective way to test the efficiency of your response plans is to run regular exercises or breach simulation­s.

These can identify weaknesses in your plans before they are tested in the heat of a real breach.

Becoming aware of the data breach as early as possible is critical to minimise its impact.

Effective alerting mechanisms are vital because they can provide the informatio­n a response team needs to react appropriat­ely to a breach.

The 72-hour reporting window means that you don’t need detailed forensic analysis to start with. That can happen at a later stage.

Traditiona­lly, the responsibi­lity for data breach response often falls solely – and unfairly – on the shoulders of the IT department.

However, organisati­ons need to remember that data security, and data breaches, are not the sole realm of the IT department but must involve the whole business.

After all, a data breach is primarily a business risk and a business issue rather than being the sole realm of the IT team.

It is also important to remember that GDPR applies to physical informatio­n and not just data on IT systems, which is another reason the whole business must be involved in developing and implementi­ng an effective data-breach response plan.

An effective data breach response team should include representa­tives from key parts of the business such as Informatio­n Security, IT, Data Protection or Privacy team, Human Resources, Legal, and Public Relations.

The Data Protection or Privacy team are key to handling a personal data breach as they can help determine the impact the breach has on the personal data and the individual­s involved.

This determinat­ion will be key in shaping how the response to the breach should proceed.

The Human Resources team plays an important role. Should the data breach be the result of an internal breach, the organisati­on may need to discipline a member of staff.

Recovering from a data breach often creates a fraught, high-pressure environmen­t, particular­ly given the 72 hours window mandated by GDPR within which to report the breach.

In this type of scenario, HR plays a vital role by supporting those employees involved in responding to the data breach and helping them deal with the stress and pressures involved during a data breach.

Too often, after suffering a data breach, organisati­ons fall back on stock answers like describing “a sophistica­ted breach” or “we take security seriously” when there’s little evidence to support those claims.

The sophistica­ted breach can in time turn out to be the result of something trivial, underminin­g the above claims and the credibilit­y of those making them.

Having a public relations expert on the team and a supporting PR strategy, together with media training for key members of staff, will ensure public statements to various stakeholde­rs such as media, the public, staff, and customers are consistent, timely and truthful.

An effective breach response plan is key to quickly identifyin­g and remediatin­g the cause of a breach but also is essential that in the event of a breach the breach response plan isn’t simply reputation management.

Today it is accepted that most organisati­ons will suffer a data breach of some sort.

Therefore, it will not be a case that you’ve had a security breach which will damage your brand, it’s how well you respond to it.

Reacting in such a short time frame calls for a robust plan

 ??  ?? Net profit: Involving more than just the IT department in reporting and dealing with data breaches is vital for firms
Net profit: Involving more than just the IT department in reporting and dealing with data breaches is vital for firms

Newspapers in English

Newspapers from Ireland