A bit more clarification about data protection for SMEs
Trust H2 to deliver solutions that are Appropriate, Affordable and Accreditable

A bit more clarification about data protection for SMEs

Data Protection, a somewhat dry subject that many companies, particularly SMEs, think they can get away from by simply paying a bit of lip service.? The Data Protection Act 2018, or as it has become known, UK GDPR, is far from a toothless beast and can cause businesses to find themselves in all sorts of trouble if they’re not careful.?

Businesses that you might not think about, like Estate Agents for example, hold large amounts of personally identifiable information or PII, that is information that can identify a living individual.??Not so long ago a London estate agent was fined £80,000 by the?Information Commissioner’s Office?(ICO), after leaving the personal data of more than 18,000 customers exposed for almost two years.

The incident occurred when the estate agent passed the details from its own servers onto a partner company. An “Anonymous Authentication” function was not switched off, which meant there were no access restrictions to the data.

It’s surprising just how much PII estate agents hold.? Just think about what they ask for when you’re buying a house.? In this case the exposed details included bank statements, salary details, copies of passports, dates of birth and addresses of both tenants and landlords.

But in some cases that might not be the end of it.? Individuals can sue companies that release data into the wild.? In fact, there are now law firms advertising no win no fee when representing these cases.? Remember that data breaches almost always involve multiple people, sometimes hundreds if not thousands of records, which could potentially mean hundreds if not thousands of individual compensation payments.

The regulations apply to all?businesses?large and?small, although some exceptions exist for SMEs.?Companies?with fewer than 250 employees are not required to keep records of their processing activities unless it's a regular activity, concerns sensitive information or the data could threaten an individuals' rights.? Just exposing PII can threaten an individual’s right to privacy. Of course in the above example, this was classed as regular activity and therefore accurate records needed to be kept.?

Just about everyone processes personal data of some sort.? Data that can identify a living individual.? HR data will have bank account information, home addresses, NOK, phone numbers, maybe references from previous employers.? The exposure of some or all of that could be judged as prejudicial to an individual’s rights.? Some companies may have bigger problems, for example Solicitors, Estate Agents, Financial Advisors and Recruiters (the list is not exhaustive), which hold an abundance of personal data about their clients, much of which, under other legislation they are required to retain for up to 7 years, even if that customer is no longer active.?

What this means is that a significant number of policies and processes will need to be written and taken into use by the organisation.? It is not unusual for many to visit the web and download templates to cover their requirements.? However, whilst these templates in themselves maybe adequate when used by someone who knows what the requirement is, they may be less than effective in the hands of someone who is just looking for a quick tick in the box.?

And let’s not forget that the Act requires personal data to be secured by ‘default and design’.? This means that cyber security requirements must be designed into your protections.? This could mean at least another 6 or 7 policies and procedures.?

When we here at H2, are first approached by a prospective client and we begin our offer of a 30 day free trial to examine their requirements, one of the first things we find is that they don’t know what data they are holding, or where it all is.? Oh, they have a general idea; it’s on the cloud server(s), it’s not on laptops or desktops, it’s just the stuff we need to process our clients’ requirements and yes, we’ve only got one copy.? And then we install our software that first carries out a discovery exercise and we discover that their laptops/desktops are holding lots of copies of the data that should only be on the cloud server(s).? How does that happen?? Over time, especially with many now employing the hybrid system of working, ie between the office and remote (home) locations, employees log on to the cloud, find they have a bit of shaky internet link and download the data they need, work on it and then upload it again, forgetting to delete it from their machine.? Or they need to share it and attach it to an email and send it out, forgetting, or perhaps not realising, that the data is now stored, attached to an email, on their email server.?

Then comes the issue with audit trails.? If the ICO ever wanted to carry out an investigation, then having an audit trail of who created/copied/deleted/forwarded what to who, is essential.? And let’s not forget the member of the public who is fully entitled to submit a Data Subject Access Request or DSAR, which demands that you reveal what data you are holding on that person.? The law insists on it, and you can’t refuse it.? I know of a financial firm that took nearly 3 weeks to satisfy a DSAR, taking an employee off billing, for that time.?

We have a solution that meets the requirements and not only that, has a built in encryption system, all within the same monthly cost.? It’ll cost you nothing to trial it and we’d be very surprised if once you’ve seen it and seen the ridiculously low monthly charge for the managed service, you don’t want to keep it.?

H2 provides affordable and flexible one-off and ongoing data protection and cyber risk protection services.?

To learn more about the services we provide please click here?https://www.hah2.co.uk/?

Alternatively, please feel free to give us a call, email or book an online meeting on https://calendly.com/kevin_hawkins-0pc/30min?

T: 0845 5443742

M: 07702 019060

E:?[email protected]

Trust H2 – Making sure your information is secure

要查看或添加评论,请登录

H2 Cyber Risk Advisory Services的更多文章

社区洞察

其他会员也浏览了