{"id":68120,"date":"2022-01-27T15:25:33","date_gmt":"2022-01-27T15:25:33","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2022\/01\/27\/securing-one-of-our-most-valued-assets-on-data-privacy-day\/"},"modified":"2023-05-25T10:29:44","modified_gmt":"2023-05-25T09:29:44","slug":"securing-one-of-our-most-valued-assets-on-data-privacy-day","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2022\/01\/27\/securing-one-of-our-most-valued-assets-on-data-privacy-day\/","title":{"rendered":"Securing one of our most valued assets on Data Privacy Day"},"content":{"rendered":"\n<p><em>As the world becomes increasingly digitised, we must ensure our data is protected at all costs. Ahead of the annual Data Protection Day, a number of industry experts discuss the importance of protecting data and why organisations should embed this into their core values.<\/em><\/p>\n\n\n\n<p><strong>Sean Carpenter, Senior Director, Product Management\u00a0&amp; Data Privacy\u00a0at project44\u00a0<\/strong><\/p>\n\n\n\n<p>&#8220;Supply chains have become front page news globally over the past two years.\u00a0However,\u00a0there is no time to rest, as\u00a02022 brings even more issues, with shippers, carriers and suppliers facing an\u00a0increased threat of cyberattacks and ransomware.\u00a0It\u2019s time to make data security a\u00a0supply chain priority.\u00a0<\/p>\n\n\n\n<p>&#8220;The first step to protecting\u00a0supply chain\u00a0data is to map out how it\u00a0is being shared, used and stored. In addition to\u00a0which systems, tools and people are tasked with keeping it secure.\u00a0Secondly, end-to-end protection of data requires encryption, with system access restricted, logged and audited.\u00a0Further areas for supply chain experts to consider include getting total visibility, working with trusted suppliers and solutions, focusing on data storage and being proactive.\u00a0<\/p>\n\n\n\n<p>&#8220;Data security is a constant and ever-evolving challenge for businesses and major disruptions invite endless opportunities for breaches.\u00a0From location sharing and shipment documentation, to\u00a0IIoT\u00a0devices and inventory management, organisations connect with exponentially growing data touchpoints every day, that must be secured. It is vital that all data sources are secured, as the supply chain is only ever as strong as its weakest link.&#8221;<\/p>\n\n\n\n<p><strong>Dan Davies, CTO at Maintel<\/strong><\/p>\n\n\n\n<p>&#8220;As restrictions ease, a large-scale return to the office may be attractive for many organisations, but a hybrid model of working can continue to be just as safe and successful \u2013 if you implement the right security.\u00a0<\/p>\n\n\n\n<p>&#8220;It\u2019s correct that a hybrid workforce can be difficult to monitor and makes your data more complex to protect, when\u00a0users only spend a limited amount of time connected to the corporate network. But organisations can combat this\u00a0through strong data management policies and a software defined, borderless network fabric. This means staff know exactly what is available to them and where it sits within the business alongside extra precautions \u2013 such as Multi-Factor Authentication, secure web gateways and Zero Trust systems \u2013 which can ensure only those who really need it have access to highly sensitive company data. \u00a0\u00a0<\/p>\n\n\n\n<p>&#8220;Alongside these policies, organisations should also leverage only cloud technologies that provide high levels of data security and ubiquitous access. Businesses may also want to invest in automation and AI tools that help staff locate the data they need faster, alongside more traditional endpoint defence tools, such as anti-virus and device posture.\u00a0<\/p>\n\n\n\n<p>&#8220;Finally, remember that times of disruption are always likely to\u00a0encourage cybercriminals to seize an opportunity, so remain vigilant. Re-enforce messaging and training with your remote workers and make sure everyone is as educated as possible.&#8221;<\/p>\n\n\n\n<p><strong>Heather Gantt-Evans, CISO at SailPoint<\/strong><\/p>\n\n\n\n<p>\u201cCollectively, are we on the right side of history with data privacy? I would argue not yet.\u00a0We are going to look back at this era as if we were data\u00a0barbarians.\u00a0In our increasingly &#8216;Ready Player One-Esque&#8217; environment, we must set aside time to think about our\u00a0privacy\u00a0and how to protect it.\u00a0<\/p>\n\n\n\n<p>\u201cWe can see the wave of\u00a0data\u00a0morality coming from thought leaders and governments forcing hands by enacting regulations, including GDPR and CCPA. For enterprises to meet these rising expectations and comply with new regulatory guidelines, they&#8217;ll need to prove that they are investing in\u00a0privacy. Companies who want to capitalise on this moment should seek to collect as little\u00a0data\u00a0as possible, encrypt what\u00a0data\u00a0they do have, give customers a path to opt out of\u00a0data\u00a0harvesting and give customers the ability to be forgotten\u00a0(i.e. providing previously collected\u00a0data\u00a0back to the customer and then deleting it).<\/p>\n\n\n\n<p>\u201cBut most importantly, organisations need to communicate clearly how collected\u00a0data\u00a0is used in order to provide value back to the customer.\u00a0This means clearly articulating how it is protected and the customer\u2019s\u00a0privacy\u00a0options.<\/p>\n\n\n\n<p>\u201cThis can be particularly challenging for\u00a0data\u00a0involved in proprietary Machine Learning, but algorithmic transparency demonstrates that an enterprise is conscientious about\u00a0data\u00a0privacy. This includes Disney, who recently agreed to\u00a0privacy\u00a0changes for children&#8217;s apps, effectively removing tracking software for targeted ads. In addition, companies should seek to embed customer\u00a0privacy\u00a0as one of their core values and communicate this value as part of their customer-facing messaging.\u00a0<\/p>\n\n\n\n<p>\u201cLet&#8217;s usher in a new phrase, &#8216;the customer is always\u00a0<s>right<\/s>\u00a0secure&#8217;.\u201d<\/p>\n\n\n\n<p><strong>Chad McDonald, CIO and CISO at Radiant Logic<\/strong><\/p>\n\n\n\n<p>\u201cThe number of identities linked to businesses has dramatically increased over the past two years, and as organisations begin their Digital Transformation, they need to be able to keep their identity data under control and properly managed.\u00a0<\/p>\n\n\n\n<p>&#8220;For years now, organisations have suffered from scattered identity data across multiple sources which all use different protocols or are in modern cloud repositories that can\u2019t connect back to legacy, on-premise technology. This inevitably results in an identity sprawl with organisations having overlapping, conflicting, or inaccessible sources of data, making it impossible to build complete and accurate user profiles.\u00a0<\/p>\n\n\n\n<p>&#8220;This not only causes frustration for employees, who have to remember multiple logins credentials for all of the different applications and profiles that they need as part of their day-to-day job, but also poses significant GDPR and security risks.\u00a0<\/p>\n\n\n\n<p>&#8220;The recent news story of the UK Government being fined \u00a3500,000 for the New Year honours data breach is an example of the poor processes that happen when governing identity data. Poor identity management will result in data not being fully secured and organisations suffering data breaches. Without accurate user profiles, systems are unable to determine what individuals should and should not be able to access. Siloed systems increase likelihood of a failure in identity management which increases an organisation\u2019s attack surface. This increases the chances of a successful breach and increases the likelihood that it will remain undetected over time.\u00a0 \u00a0<\/p>\n\n\n\n<p>&#8220;While identity sprawl is causing significant challenges to businesses across the world, it is a problem which many organisations don\u2019t realise they have or, if they do know about it, they have decided to turn a blind eye as they believe there is no solution to sanitise and streamline their identity data.\u00a0<\/p>\n\n\n\n<p>&#8220;With the number of cyberattacks substantially increasing during the pandemic, organisations must put in measures which can stop identity sprawl by ensuring they have a unified global profile which has all the attributes of a user irrespective of which source it\u2019s located in. Organisations that fail to manage identity data will suffer from further data breaches as threat actors know that data is not secure and easy to get hold of. While this sounds like a complicated problem to solve, it can be easily done thanks to Identity Data Fabric.\u00a0<\/p>\n\n\n\n<p>&#8220;The concept of Identity Data Fabric is to unify distributed identity data from all sources in an organisation and create a resource that delivers identity data on-demand wherever and whenever needed. Applications are then able to access identity data using different formats and protocols, irrespective if it\u2019s on-premise or in the cloud.\u00a0<\/p>\n\n\n\n<p>&#8220;Not only does the Identity Data Fabric approach ensure that businesses have access to all their identity data, but it also ensures that users\u2019 profiles can be regularly updated in real time. Businesses can be confident that employees have access to the right information, yet they\u2019re not able to access areas they don\u2019t need for their job. With identity data in one flexible and manageable system, there is less chance of that data being accidentally leaked by employees or stolen by cybercriminals and it is more likely that the identity data and processing will be accurate across all systems.\u201d<\/p>\n\n\n\n<p><strong>Rick Vanover, Senior Director of Product Strategy, Veeam<\/strong><\/p>\n\n\n\n<p>&#8220;Today, privacy matters. Data privacy continues to be more important than ever. From an awareness standpoint, data privacy doesn\u2019t get the attention it needs. I see IT organisations constantly manage large amounts of data that really doesn\u2019t matter any longer. ROT \u2013 Redundant, Obsolete or Trivial \u2013 data should be moved out of its storage life cycle. My practical advice on Data Privacy Day is to assess what data is where and identify what needs to be removed. If it doesn\u2019t need to be removed, then determine if selected data should be moved to a correct tier or policy. From a privacy perspective, where it exists is an important first step of the process.&#8221;<\/p>\n\n\n\n<p><strong>Chris Boyd, Lead Analyst at Malwarebytes<\/strong><\/p>\n\n\n\n<p>\u201cAs Data Privacy Day is upon us, it&#8217;s important that everyone adheres to the three Cs. Firstly, check your socials \u2013 we live in a society in which we feel obliged to project every detail of our lives across the Internet. This eats away at our privacy and increases the risk of unsolicited and private information being shared. Re-evaluating this mindset could boost your privacy and security considerably. Secondly, consider alternating browser usage every so often. Switching from one browser to another can help keep advertisers and profilers on their toes and gives you greater insight into security measures put in place by the developers. It&#8217;s also important to ensure your browser is legitimate and not rogue software or simply an advertisement farm masquerading as a privacy tool. And finally, challenge yourself \u2013 the evolution of social media, camera phones and smart devices threatens other people\u2019s privacy by allowing multiple parties to access it. We need to be as motivated to protect the privacy of others as we are our own.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the world becomes increasingly digitised, we must ensure our data is protected at all costs. Ahead of the annual Data Protection Day, a number of industry experts discuss the importance of protecting data and why organisations should embed this into their core values. Sean Carpenter, Senior Director, Product Management\u00a0&amp; Data Privacy\u00a0at project44\u00a0 &#8220;Supply chains [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":68121,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[11661,5,6,9961,13],"tags":[1146,14435,1643,14436,14437,1390,14438,14439,8166,1860,712],"class_list":["post-68120","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-latest-threats-data","category-enterprise-security","category-insights","category-thought-leadership","category-top-stories","tag-data-management","tag-data-privacy-day","tag-data-security","tag-identity-data-fabric","tag-maintel","tag-malwarebytes","tag-project44","tag-radiant-logic","tag-sailpoint","tag-supply-chain","tag-veeam"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/68120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=68120"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/68120\/revisions"}],"predecessor-version":[{"id":68331,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/68120\/revisions\/68331"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/68121"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=68120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=68120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=68120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}