GDPR Deadline: A Horrorshow Or A Non-Event?

The seemingly endless studies on corporate readiness for the pending General Data Protection Regulation demonstrate that data truly can be made to say just about anything.

If recent surveys are to be believed, organisations are either fairly well prepared for the new data privacy mandate … or they will fail miserably at compliance.

As evidence, consider the results of two different studies of GDPR compliance readiness that were both released this week. One paints a fairly optimistic picture of corporate readiness. The other tells a tale of doom.

First the Good News

Companies are taking the new General Data Protection Regulation much more seriously than the Health Insurance Portability and Accountability (HIPAA) and Payment Card Industry Security Standards Council (PCI SSC), according to a survey conducted by Propeller Insights on behalf of Web application security company Netsparker.

About half of the more than 300 senior security executives surveyed online in March (49 percent) said their organisations are 75 percent of the way through the process of being compliant with GDPR, a set of regulations the European Union (EU) to protect citizens’ sensitive data from cyber security breaches. Organisations that fail to comply will face penalties when GDPR goes into effect May 25, 2018.

More than two thirds of the organisations (71 percent) are confident that they’ll be fully compliant by the deadline, but many of the organisations surveyed still are not compliant with PCI and HIPAA, the report said.

In preparation for GDPR, 57 percent of companies are re-engineering internal systems and procedures, 55 percent are recruiting new people specifically to tackle GDPR compliance, and 48 percent are re-engineering internal security teams.

For some, the cost of GDPR compliance will be steep, the report said. About one quarter of the organisations (24 percent) will spend between $100,000 and $1 million, and one in 10 said GDPR compliance will cost their business more than $1 million.

Now the Bad News.

A study by SAS on global readiness reveals that only 7 percent of US organisations consider themselves as GDPR compliant at this time, and only 30 percent expect to be by the May 25, 2018 deadline.

The picture is slightly better in Europe, where 53 percent of organisations surveyed expect to be GDPR compliant by May 25. Among global organisations, expected compliance falls to 46 percent.

The SAS survey does agree that data privacy is getting more attention, fueled in large part by the recent revelations of data sharing by Facebook with Cambridge Analytica.

It also agrees that the financial implications of non-compliance with GDPR have served as a wake-up call for many organisations on the need for better data transparence and security.

Some 93 percent of organisations in the SAS study do have a compliance plan in place, or they expect to have one. A majority of respondents also expect to gain long-term benefits in the areas of data management and data governance.

“Consumers are now demanding the kind of trust that GDPR requires,” noted Todd Wright, senior product marketing manager at SAS.

“Organisations that comply will have much stronger data management that leads to increased productivity and a better understanding and ability to serve their customers.”

Anticipated benefits from GDPR compliance and data privacy efforts, according to the SAS survey respondents are:

  • Improved data governance (cited by 84 percent)
  • Increased trust between organisations and customers (cited 68%)
  • Improved personal data quality
  • Improved organisational image
  • Movement toward being a data-driven organisation

Information Management

You Might Also Read: 

Cybersecurity Advice For SMEs:

Six Myths About  GDPR:

 

« Brexit Might Freeze The UK Out Of Robotics
AI Increases The Risks of Nuclear War »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

DCL Search & Select

DCL Search & Select

DCL Search & Selection connect candidates to the best companies in the IT Security, Telco, UC, Outsourcing, ERP, Audit & Control markets.

World Privacy Forum (WPF)

World Privacy Forum (WPF)

The World Privacy Forum is a non-profit public interest research group that focuses on privacy and technology issues.

CyberVista

CyberVista

CyberVista is a cybersecurity training education and workforce development company. Our mission is to eliminate the skills gap by creating job ready professionals.

D3 Security

D3 Security

D3's Smart SOAR platform is at the forefront of the security automation revolution, helping clients around the world to rapidly identify, analyze, and resolve advanced threats.

State e-Government Agency (SEGA) - Bulgaria

State e-Government Agency (SEGA) - Bulgaria

The State e-Government Agency (SEGA) is responsible for matters relating to electronic governance in Bulgaria.

UK Research & Innovation (UKRI)

UK Research & Innovation (UKRI)

UKRI works in partnership with universities, research organisations, businesses, charities, and government to create the best possible environment for research and innovation to flourish.

TrustGrid

TrustGrid

Trustgrid is a pioneer and leader in secure, cloud-native software-defined connectivity.

NARIS

NARIS

NARIS is the leading provider of an integrated Governance, Risk and Compliance platform called NARIS GRC.

Harvey Nash

Harvey Nash

Harvey Nash is a leading global provider of talent and technology solutions.

Terra Quantum

Terra Quantum

Terra Quantum is a deep tech pioneer, developing revolutionary quantum applications to shape the technology of the future.

Systal Technology Solutions

Systal Technology Solutions

Systal is a global managed network and security service and transformation specialist. We help enterprise-level businesses maximise the security and business value of their complex IT infrastructure.

Anch.AI

Anch.AI

Anch.AI is an Ethical AI Governance platform that helps you comply with EU regulations and avoid risks and penalties when developing and using AI as part of your business.

Cypheria

Cypheria

Cypheria harness the expertise of elite military units and combine it with extensive digital combat experience to deliver unparalleled security solutions for organizations.

Cyber Security Certification Australia (CSCAU)

Cyber Security Certification Australia (CSCAU)

CSCAU is the world’s first 'for mission' industry council set up to address small and medium-sized business (SMB) cyber resilience through annually updated certifiable standards.

Panasonic Automotive Systems

Panasonic Automotive Systems

Panasonic Automotive Systems brings together security technologies and human resources cultivated across an extensive range of businesses into the automotive field.

Inoxoft

Inoxoft

Inoxoft delivers IT security consulting, assessment, and protection services to help businesses secure their infrastructure, applications, and sensitive data.