{"id":3345,"date":"2017-07-27T13:29:07","date_gmt":"2017-07-27T13:29:07","guid":{"rendered":"http:\/\/chief-exec.com\/?p=3345"},"modified":"2017-09-02T11:13:12","modified_gmt":"2017-09-02T11:13:12","slug":"new-data-rules-for-an-age-of-hacking-and-the-hacked","status":"publish","type":"post","link":"https:\/\/chief-exec.com\/?p=3345","title":{"rendered":"New data rules for an age of hacking and the hacked"},"content":{"rendered":"<h4><span style=\"color: #333399;\">In a new legal landscape fines of up to 4 per cent of global turnover, or \u20ac20 million, are on the cards if companies fail to comply, reports <em>James Fitzgerald<\/em>.<\/span><\/h4>\n<p>In the digital age, information is power. Economic growth is now dependent on data sharing, but many consumers are concerned about how and where their personal details are collected. For some people, the retention of personal privacy has eclipsed more nebulous pursuits, such as self-actualisation or social status, as the ultimate attainment in life.<\/p>\n<p>It is against this backdrop that the European Commission has sought to tighten the rules, under the General Data Protection Regulation (GDPR), due to come into force in May next year.<\/p>\n<p>Nearly 70 per cent of Europeans are concerned about not having complete control over the information they provide online, according to a recent <a href=\"http:\/\/ec.europa.eu\/commfrontoffice\/publicopinion\/archives\/ebs\/ebs_359_en.pdf\" target=\"_blank\" rel=\"noopener\">Eurobarometer survey<\/a>. Seven Europeans out of 10 worry about the potential use that companies may make of the information disclosed, according to the European Commission.<\/p>\n<p>\u201cThese new pan-European rules are good for citizens and good for businesses. Citizens and businesses will profit from clear rules that are fit for the digital age, that give strong protection and at the same time create opportunities and encourage innovation in a European Digital Single Market,\u201d says V\u011bra Jourov\u00e1, commissioner for Justice, Consumers and Gender Equality.<\/p>\n<p>The GDPR promises to give citizens more control over their data. The rules will make it easier to access your own data; give a right to data portability (between service providers, for example); a clarified \u201cright to be forgotten\u201d; and the right to know when your data has been hacked.<\/p>\n<p>The new rules will require large companies to appoint a \u201cdata protection officer\u201d to ensure compliance, with potential fines of up to 4 per cent of global turnover, or \u20ac20m.<\/p>\n<p>The regulation, unlike a directive, will be applicable in all EU member states without the need for national implementing legislation. In this way, the Commission aims to harmonise data protection measures.<\/p>\n<p>The GDPR will also bring implications for employers who wish to \u201cprofile\u201d potential candidates via their social media presence. According to guidelines published by the Article 29 group of advisory regulators, data collected from a search must be \u201crelevant to the performance of the job\u201d.<\/p>\n<p>In this new legal landscape software packages that track an employee\u2019s activities when working from home will likely be outlawed.<\/p>\n<blockquote>\n<h4><span style=\"color: #333399;\">How do you stop hackers? You can\u2019t because there are vulnerabilities created on purpose by the NSA for spying. For them to hack everyone and everything.<\/span><\/h4>\n<\/blockquote>\n<p>The burden of responsibility for data protection is being laid firmly at the door of individuals, SMEs and corporations, but what, if anything, will change in the covert world of government security agencies and the bandit country of hackers?<\/p>\n<p>\u201cIf you suffer a breach, and it\u2019s a question of when not if at the moment, and you are holding personal data, and that is leaked or stolen, you are going to be liable for that, because you were holding the information,\u201d says Toby Stephens, a partner at law firm HFW.<\/p>\n<p>The scale and prevalence of ransomware and cyber attacks has grown markedly over the past year, with Britain\u2019s National Health Service among the large groups hit by the global Wannacry hack in May. The attackers demanded payment to regain access to vital medical records, causing operations to be cancelled and ambulances to be diverted at 40 hospital trusts. The private US postal service FedEx and Germany\u2019s rail operator were also affected.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">Do read advice if you are a member of NHS staff starting work at an organisation affected by <a href=\"https:\/\/twitter.com\/hashtag\/nhscyberattacks?src=hash\">#nhscyberattacks<\/a> <a href=\"https:\/\/t.co\/ToWK5oe814\">https:\/\/t.co\/ToWK5oe814<\/a> <a href=\"https:\/\/t.co\/aXkKKA3kGh\">pic.twitter.com\/aXkKKA3kGh<\/a><\/p>\n<p>\u2014 NHS England Media (@NHSEnglandMedia) <a href=\"https:\/\/twitter.com\/NHSEnglandMedia\/status\/864028884584607744\">May 15, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>This was followed last month by the \u201cPetya\u201d ransomware attack, which crippled businesses across Europe and America.<\/p>\n<p>A cyber security expert who led a team countering the Petya attack at a major UK bank told <em>Chief-Exec.com<\/em> that there wasn\u2019t much that could be done to stop breaches of systems \u2013 and data.<\/p>\n<p>\u201cHow do you stop hackers? You can\u2019t because there are vulnerabilities created on purpose by the NSA (National Security Agency) for spying. For them to hack everyone and everything,\u201d says the source, who wished to remain anonymous.<\/p>\n<p>\u201cEncryption is the same. It\u2019s designed to have a backdoor way through. As soon as you have this you can\u2019t be 100 per cent secure. When you\u2019re anything less than 100 per cent secure you are wide open,\u201d the source \u00a0says.<\/p>\n<p>In recent years high profile targets have included Yahoo, Ebay, Sony Pictures, TalkTalk and MySpace, where thousands, and in some cases millions, of customer accounts and emails were accessed by hackers.<\/p>\n<p>\u201cWe have had a huge uptick in enquiries following the recent cyber attacks \u2013 not just on the [data] regulations, but [companies\u2019] risk and crisis management protocols, their contracts and ensuring they have sufficient insurance coverage to cater for the risk gap in their contracts,\u201d says Mr Stephens.<\/p>\n<p>He says companies of all sizes should take a \u201crisk management\u201d approach to the GDPR rules, whereby they can demonstrate that they have a \u201cproper system to minimise and mitigate\u201d their risk, and a clear understanding of what they will do in an emergency. \u201cIf they realise they have been hacked, what are they going to do? How are they going to manage that process with their customers and employees, to minimise their exposure?\u201d<\/p>\n<p>The speed of response to a breach will be a crucial factor in the regulator\u2019s decision to penalise a company, says Mr Stephens, who suggests that the GDPR presents an opportunity for businesses to assess other vulnerabilities in their IT.<\/p>\n<p>\u201cThe Petya attack is an example to everyone that they should have a contingency plan in place, as almost every business these days is reliant on IT. Can they switch back to a paper system? No. How are they going to run their business? What\u2019s the reputational fallout going to be if they cannot get back into their systems?\u201d<\/p>\n<p>He cites one client affected by Petya who had \u201csafely stored all of their contingency plans on their system\u201d \u2013 and therefore could not access them.<\/p>\n<p>It may be a mistake to believe that it all comes down to technicalities. \u201cMany businesses believe that cyber is all about their technical capabilities. Those, of course, are the ones that are ultimately likely to have the greatest exposure,\u201d says Mr Stephens.<\/p>\n<p>In the contradictory world of data, where privacy increasingly becomes a commodity for both citizens and the security state, companies and individuals must become simultaneously more compliant to the rules and more aware of those who will always seek to break the rules.<\/p>\n<p>Complacency is no longer an option.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-1660\" src=\"http:\/\/chief-exec.com\/wp\/wp-content\/uploads\/2016\/12\/Fitzgerald-VB1-300x135.jpg\" alt=\"\" width=\"300\" height=\"135\" srcset=\"https:\/\/chief-exec.com\/wp\/wp-content\/uploads\/2016\/12\/Fitzgerald-VB1-300x135.jpg 300w, https:\/\/chief-exec.com\/wp\/wp-content\/uploads\/2016\/12\/Fitzgerald-VB1.jpg 371w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<h6>Headline image credit: Billion Photos\/Shutterstock<\/h6>\n","protected":false},"excerpt":{"rendered":"<p>In a new legal landscape fines of up to 4 per cent of global turnover, or \u20ac20 million, are on the cards if companies fail to comply, reports James Fitzgerald. In the&#8230;<\/p>\n","protected":false},"author":5,"featured_media":3347,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,115,61],"tags":[50,120,133,53,43,148,147],"class_list":["post-3345","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-chief-exec-eu","category-featured-news","category-innovation","tag-european-union","tag-ict","tag-law","tag-management","tag-regulations","tag-risk","tag-security"],"_links":{"self":[{"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/posts\/3345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/chief-exec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3345"}],"version-history":[{"count":6,"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/posts\/3345\/revisions"}],"predecessor-version":[{"id":3353,"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/posts\/3345\/revisions\/3353"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/chief-exec.com\/index.php?rest_route=\/wp\/v2\/media\/3347"}],"wp:attachment":[{"href":"https:\/\/chief-exec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/chief-exec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/chief-exec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}