Gulf Business

How safe is your data?

From Facebook to GDPR, 2018 has been an important year for data protection. We look at why data breaches are in the public eye, and what the region is doing to safeguard your private details

- By Neil King

From Facebook to GDPR, 2018 has been an important year for data protection. We look at why data breaches are in the public eye and what the region is doing to safeguard your private details

When Mark Zuckerberg appeared before US senators in April to face questions about Facebook’s role in the Cambridge Analytica scandal – in which the personal informatio­n of up to 87 million users was harvested without their permission – the spotlight was shone more brightly than ever before on the issue of data security.

Fending off the sometimes probing, sometimes confused questions one by one, the billionair­e CEO largely survived the grilling, but the mere fact he was there at all added fuel to a growing fire.

Data breaches are nothing new. Whether targeted by hackers, the result of poor security or lost computers, accidental­ly published, or part of an inside job, people’s data has always been at risk since the dawn of the technology age.

The stark reminders of this have been periodic. In 2005, some 92 million records were compromise­d as the result of a reported inside job. Two years later, TK/TJ Maxx saw 94 million compromise­d records, followed by Sony PlayStatio­n’s 77 million in 2010.

Yahoo saw an astonishin­g 3 billion user accounts stolen in 2013, and a year later 145 million Ebay records suffered a similar fate. As did 76 million records from JP Morgan Chase in 2014, 80 million from Anthem in 2015, and 145 million Equifax accounts in 2017.

No sector is immune, and as technology continues to grow and develop, so do the chances of data attacks. Market intelligen­ce firm, Internatio­nal Data Corporatio­n (IDC), has predicted that by 2020 more than 1.5 billion people worldwide will be affected by data breaches. Meanwhile, in its 2017 Data Breach Level Index, digital security firm Gemalto noted that the number of data records compromise­d in publicly disclosed data breaches surpassed 2.5 billion – up 88 per cent from 2016. This equates to more than 7 million records lost or stolen every day, or 82 every second.

With less than 1 per cent of the total incidents, according to Gemalto’s findings, the Middle East region is certainly not a hotspot for data breaches, but events of 2018 have already proven that it is far from safe.

In April, Dubai-based ride-hailing app Careem announced that it had experience­d a breach in January this year, compromisi­ng the data of 14 million users. In previous years, breaches have been reported at Al Zahra Private Medical Centre, Etihad Airways and dubizzle, among others.

Back in 2016, statistics from the

UAE’s then new Cyber Security Centre showed that the country was the second most targeted country in the world for cyberattac­ks – sandwiched by the US and Spain in first and third position. So despite the relatively low data breach-rate, the potential for breaches remains high – especially as hackers, attackers and threat actors become more sophistica­ted.

Confrontin­g challenges

The challenges are manifold, but the region has gone to great lengths to keep data safe and continues to not only maintain stateof-the-art security strategies, but also keep businesses aware of the pressing need to safeguard people’s data.

Amir Kanaan, managing director – Middle East, Turkey and Africa for Kaspersky Lab – believes the recent Facebook scandal has been a key contributo­r to that recognitio­n.

“It has resulted in heightened awareness, and I do hope businesses in the region take this opportunit­y to rethink their attitude and approach towards data security,” he says.

“Seeing the response to the issue by a number of national government­s, there will be a move towards more stringent operationa­l guidelines and regulatory frameworks for internatio­nal companies that primarily deal with data.”

Even before the Facebook news broke, regional government­s have been proactive in bolstering their own security levels, as well as advising private businesses to do the same.

In January this year, for example, the UAE’s Ministry of Finance marked Data Privacy Day by issuing a reminder of the importance of protecting personal data for financial transactio­ns. And as well as the obvious concern for people’s privacy, the ministry’s undersecre­tary Younis Haji Al Khouri highlighte­d the economic importance behind it.

“The developed economic and legislativ­e framework of the country sets focus on protecting personal informatio­n by collecting, preserving and processing data, to prevent the misuse of data, privacy violation and financial losses,” he explained at the time.

“This will contribute to establishi­ng a sound economic environmen­t that gains the trust of investors and financial institutio­ns, and leads the UAE to become the preferred place to do business.”

This trust is something regional government­s have been trying to instil with a series of policies, regulation­s, authoritie­s and institutio­ns announced in recent months and years.

In November last year, Saudi Arabia announced one of the most high-profile – the National Authority for Cyber Security – while the Dubai Data Strategy has been instrument­al in establishi­ng the right frameworks, foundation­s and practices to ensure the emirate can achieve its smart city vision while ensuring the safety of all data.

Kuwait, Bahrain and Oman’s data protection landscape is slightly less advanced, but for all three, new laws are being drafted to regulate the handling of data across sectors.

Each jurisdicti­on is tightening its legal framework, with harsh penalties to be meted out to individual­s breaking the law, or companies selling data without permission. In the UAE, under the cyber crimes law, fines can range from Dhs100,000 ($27,226) to Dhs1m ($272,257), as well as imprisonme­nt.

But for businesses in particular, there are perhaps more critical concerns. The 2017 Cost of Data Breach Study: Global Overview by IBM Security and Ponemon Institute showed that the average organisati­onal cost of data breaches in the UAE and Saudi Arabia now stands at $4.94m – the second highest in the world behind the USA. This is up 20 per cent on the 2016 cost, which was $4.12m. The global average is $3.62m.

And in terms of reputation, there is a lot at stake. According to Gemalto's 2017 Data Breaches and Customer Loyalty report, 67 per cent of people would be unlikely to do business with a company again where financial and sensitive informatio­n were stolen. A huge 93 per cent of people would consider legal action against businesses if their personal data was stolen during a breach.

What's more, a 2017 report from Comparitec­h showed that a company's stock price would drop 0.43 per cent on average immediatel­y after a breach, with the subsequent rise much slower than before, and growth struggling to go past 10 per cent until after at least two years.

Cisco added weight to the negative reputation­al impact of data breaches in its 2017 report, Cybersecur­ity Report: Chief Security Officers Reveal True Cost of Breaches and the Actions that Organisati­ons are Taking. The firm noted that more than 50 per cent of organisati­ons faced public scrutiny after a security breach, with operations and finance systems most affected, followed by brand reputation and customer retention. Some 22 per cent of breached organisati­ons across the 13 countries surveyed lost customers – 40 per cent of them losing more than a fifth of their customer base. Almost a third – 29 per cent – lost revenue, and 23 per cent lost business opportunit­ies.

Change in mindset

These are the kind of statistics regional companies are keen to avoid contributi­ng to, and while security breaches are considered inevitable rather than possible, the strength of the Gulf 's cybersecur­ity industry is going to great lengths to keep businesses protected.

A key part of that, according to UAEbased cybersecur­ity firm DarkMatter, is a change of mind-set.

In its 2018 Cyber Resilience and Trust Report, CEO Faisal Al Bannai wrote: “The fact is, we are facing a crisis and trust is being eroded; but, we are doing little to avert it. While technology has advanced for the better, our thinking has not. Now more than ever, the need for a revolution within the cyber security industry is vital to rebuild trust.”

Owing to the evolution of the threat landscape, Al Bannai posited that “a new, more predictive and intelligen­t dimension of cyber security will need to be embraced – one that masters an understand­ing of threats post-perimeter”.

Calling traditiona­l cyber security offerings “increasing­ly outdated and ineffectiv­e”, he said that the industry will need to foster a level of ‘cyber resilience' instead – “a shift in focus from the cyber security thinking of today to a focus on cyber resilience and the industry needs of tomorrow”.

The report identifies resilience as the “the capacity to recover quickly from difficulti­es and end up stronger” and highlights a number of steps in order to establish this. They range from tactical measures such as confrontin­g the talent problem, strengthen­ing the ecosystem, and investing in cyber security function, to action on a systems level, such as constructi­ng a ‘dome of trust and transparen­cy' to protect digital society.

In signpostin­g these changes, and others, the report symbolises a heightened awareness of the cyber security industry's role and responsibi­lities when it comes to safeguardi­ng data. But the weight of responsibi­lity remains largely on the shoulders of businesses themselves.

And according to Kanaan, preparedne­ss is the key: “In the case of security the trick is to always be prepared. And when you feel that you are fully prepared, check once again,” he says.

“I believe preparedne­ss is the best strategy to stay protected. Companies can bring onboard cybersecur­ity specialist­s who can test systems for security gaps and plug those gaps accordingl­y.

“If this isn't taken seriously, the resultant potential for data loss, lack of control, loss of customer trust, and loss of revenues will be far-reaching and difficult to remedy.”

Sunil Paul, co-founder and chief operating officer of software system integrator Finesse, adds that clarity and workplace culture is also vital.

“As proper security policies and strategies are very important for organisati­ons, communicat­in of the same among staff is essential,” he says.

“A poor organisati­on culture with respect to employee mobility can also lead to security vulnerabil­ities. Organisati­ons that fail to adjust to modern workplace needs, such as employees using their own devices at work, are far more likely to experience data breaches.

The GDPR effect

This enhanced self- awareness and sense of responsibi­lity has been felt more keenly since the introducti­on of the General Data Protection Regulation – GDPR – across Europe.

GDPR strengthen­s the rights of individual­s to demand that companies reveal or delete the personal data they hold. It also requires organisati­ons to report any kind of breach to the authoritie­s within 72 hours of being aware of it. This in turn should push them to strengthen their detection and response plans, improving the overall data protection landscape.

Implemente­d on May 25, the regulation addresses the export of personal data outside the European Union and the European Economic Area. And while it is a law tailored to the data protection and privacy of individual­s within the EU and

“The fact is, we are facing a crisis and trust is being eroded; but, we are doing little to avert it. While technology has advanced for the better, our thinking has not . Now more than ever, the need for a revolution within the cyber security industry is vital to rebuild trust .”

EAA, the regulation is having an impact around the world. This is largely because many companies are taking the opportunit­y to fall into line with best practices, but also any company that has access to the data of EU citizens must comply with GDPR. With such a large expat community – many of whom are from Europe – the GCC will certainly feel the force.

You may already have noticed a flurry of emails to your inbox, telling you that a company’s privacy policy has changed and requiring you to opt-in in order to continue receiving communicat­ions from them. But this is just the tip of the iceberg. Some seven years in the making, GDPR is expected to have a massive impact on data protection and the companies holding your details.

Despite these landmark changes to the way data is handled, security is approached, and organisati­ons are held accountabl­e, there are still several challenges ahead. And there always will be.

The progressiv­e nature of technology means that threat actors will always find new ways to breach data, and organisati­ons will need to find new ways to combat this – in terms of eliminatin­g the chances of attack as much as possible, and in terms of dealing with any hacks that occur.

As the Internet of Things, smart cities and cloud technology develop at pace, so too does the scope for cybercrime, meaning focus on protection will necessaril­y increase in breadth and intensity.

This is where the challenge of talent comes into the picture. According to Frost & Sullivan there are expected to be more than 1.5 million unfilled cyber security positions around the world by 2020. Naturally, this issue extends to businesses, which will need in-house talent to safeguard any data they are holding. The talent pipeline must be improved quickly in order to ensure data is protected long-term.

Finally, legislatio­n must also continue to expand in scope. The GDPR is an important step in the right direction, and Gulf countries – at least the UAE and Saudi Arabia – have been proactive in tightening their laws. But technology and people move faster than legislatio­n, making it hard for it to keep pace with hackers. Lawmakers face a challenge in ensuring any new legislatio­n or regulation is relevant and effective both now and in the future.

But even with these challenges, there is a new appreciati­on for privacy and the importance of data safety. The Facebook and Cambridge Analytica scandal may have shocked many, but in its aftermath businesses in the GCC and around the world have been given the opportunit­y to look again at the way they store and use data, which can only have a positive impact on the security landscape in general.

 ??  ??
 ??  ??
 ??  ??

Newspapers in English

Newspapers from United Arab Emirates