• CERTIFICATE
    • Eminent VARs of India
    • Best OEM 2023
  • SYNDICATION
    • AMD
    • DELL TECHNOLOGIES
    • HITACHI
    • LOGMEIN
    • MICROSOFT
    • RIVERBED
    • STORAGECRAFT
    • THALES
  • EVENTS
  • GO DIGITAL
  • INFOGRAPHICS
  • PRESS
    • Press Release PR News Wire
    • Press Release Business Wire
    • GlobeNewsWire
  • SPECIAL
    • WHITE PAPER
    • TECHNOMANIA
    • SME
    • SMART CITY
    • SERVICES
    • EDITOR SPEAK
    • CSR INITIATIVES
    • CHANNEL GURU
    • CHANNEL CHIEF
    • CASE STUDY
  • TECHTREND
    • VAR PANCHAYAT
    • TELECOM
    • SOFTWARE
    • POWER
    • PERIPHERALS
    • NETWORKING
    • LTE
    • CHANNEL BUZZ
    • ASK AN EXPERT
  • SUBSCRIBE
  • Apps
  • Gaming
  • KDS
  • Security
  • Telecom
  • WFH
  • Subscriber to Newsletter
  • April Issue
  • Blogs
  • Vlogs
  • Faceoff AI
    

HOME
NEWS

Security-Privacy: How do we get the right risk reward balance


By VARINDIA - 2019-11-19
Security-Privacy: How do we get the right risk reward balance

Suresh Kumar, Partner & CIO, Grant Thorton

 

New regulations and legislations are coming into effect across the globe impacting businesses. One of the major regulations related to Data privacy and security is the European Union’s General Data Protection Regulation (GDPR), which came into effect from May 25, 2018. A recent update about GDPR is UK’s Information Commissioner’s Office has imposed substantial fines on two large organizations for data breaches. Firstly, a fine of US $230 million on British Airways for a security incident that led to theft of customer data in September, 2018. Another fine of US $ 124 million has been imposed on Marriott International for a data breach at Starwood which it acquired in 2016. Both the penalties are very high and severely impacted these organizations.

 

In the US, the Healthcare sector has HIPAA since 1996 that has penalties for data breach of patients’ records. Another regulation is COPPA, or Children’s Online Privacy Protection Act that regulates collecting data directly from children under 13 years of age. Under COPPA, even seemingly straightforward online data collection and storage practices such as logging an IP address or storing an email address are subject to strict requirements, such as providing notice and obtaining advanced parental consent prior to collection or storage.

 

Russia has enacted a new law called RuNet law that will significantly impact Internet and Telecom providers and affect social media platforms. This law will come into effect from 1 Nov 2019 and establishes a centralised Russian Internet data traffic routing system. Which would mean businesses will need to install additional network equipment that will route data to central monitoring agency.

 

In India, right to privacy is a fundamental right and it is necessary to protect personal data as an essential facet of informational privacy through“THE PERSONAL DATA PROTECTION BILL, 2018”. This regulation is very similar to GDPR and places great responsibility on businesses. Similar to GDPR, there are provisions of hefty penalties up to 2% of worldwide revenue of INR 5 Crores, whichever is higher.

 

Changing relationship between compliance and security

 

Adherence to industry compliance regulations is increasing year-on-year. Regulations such as the PCI DSS, HIPPA for retailers/travel industry and healthcare organisations respectively require IT administrators to implement controls necessary to support their compliance framework. 

 

On a broader perspective, compliance is not security. We might have managed to implement the controls outlined in HIPAA/PCI DSS which highlights the technical safeguards necessary to protect patient data; however, that does not mean that your network/infrastructure/assets are safe. The guidelines provided in the respective industry compliance should serve as a template for the organisation’s security program, enabling organisation to build out a robust security strategy from the very foundation.  

 

Balancing security and running the business

 

Aligning the information security policy with the mission, vision and objectives of organization is the key to achieve the right balance between protecting the organization and running the business. Management and the board should be kept updated on the new regulations, changes in the threat landscape along with a robust Risk Management policy. Identification of therisks and updating the risk register and the steps to mitigate them, there is a need to change the thinking of Risk from a worst-case scenario to a ‘Structured what-if-technique’ (SWifT).

 

Due diligence is the need of the hour for third party vendors, suppliers, contractors etc. on a information security perspective. Vendors should be aligned to the IS standards of organization. Organisations should also benchmark their cybersecurity alignment with industry best practices such as NIST/CIS etc.

 

Security needs to be a priority in day-to-day activities and build the business practices. Security cannotbe treated as a one-time exercise. Keeping this in view, we should invest in building our security and compliance programs in achieving the best security framework for the organization and clients. 

 

See What’s Next in Tech With the Fast Forward Newsletter

SECURITY
View All
Zscaler announces AI innovations to its Data Protection Platform
Technology

Zscaler announces AI innovations to its Data Protection Platform

by VARINDIA 2024-05-20
SHIELD to enhance Swiggy’s fraud prevention and detection capabilities
Technology

SHIELD to enhance Swiggy’s fraud prevention and detection capabilities

by VARINDIA 2024-05-20
Axis Communications announces its first thermometric camera designed for Zone/Division 2
Technology

Axis Communications announces its first thermometric camera designed for Zone/Division 2

by VARINDIA 2024-05-20
SOFTWARE
View All
Hitachi Vantara and Veeam announce Global Strategic Alliance
Technology

Hitachi Vantara and Veeam announce Global Strategic Alliance

by VARINDIA 2024-05-16
Adobe launches Acrobat AI Assistant for the Enterprise
Technology

Adobe launches Acrobat AI Assistant for the Enterprise

by VARINDIA 2024-05-11
Oracle Database 23ai offers the power of AI to Enterprise Data and Applications
Technology

Oracle Database 23ai offers the power of AI to Enterprise Data and Applications

by VARINDIA 2024-05-10
START - UP
View All
Data Subject Access Request is an integrated module within ID-REDACT®
Technology

Data Subject Access Request is an integrated module within ID-REDACT®

by VARINDIA 2024-04-30
SiMa.ai Secures $70M Funds from Maverick Capital
Technology

SiMa.ai Secures $70M Funds from Maverick Capital

by VARINDIA 2024-04-05
Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure
Technology

Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure

by VARINDIA 2024-02-08

Tweets From @varindiamag

Nothing to see here - yet

When they Tweet, their Tweets will show up here.

CIO - SPEAK
Automation has the potential to greatly improve efficiency and production

Automation has the potential to greatly improve efficiency and production

by VARINDIA
Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

by VARINDIA
Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

by VARINDIA
Start-Up and Unicorn Ecosystem
GoDaddy harnesses AI power for new domain name recommendations

GoDaddy harnesses AI power for new domain name recommendations

by VARINDIA
UAE’s du Telecom selects STL as a strategic fibre partner

UAE’s du Telecom selects STL as a strategic fibre partner

by VARINDIA
JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

by VARINDIA
Rapyder partners with AWS to accelerate Generative AI led innovation

Rapyder partners with AWS to accelerate Generative AI led innovation

by VARINDIA
ManageEngine integrates its SIEM solution with Constella Intelligence

ManageEngine integrates its SIEM solution with Constella Intelligence

by VARINDIA
Elastic replaces traditional SIEM game with AI-driven security analytics

Elastic replaces traditional SIEM game with AI-driven security analytics

by VARINDIA
Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

by VARINDIA
Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

by VARINDIA
Dassault Systèmes to accelerate EV charging infrastructure development in India

Dassault Systèmes to accelerate EV charging infrastructure development in India

by VARINDIA
Tech Mahindra and Atento to deliver GenAI powered business transformation services

Tech Mahindra and Atento to deliver GenAI powered business transformation services

by VARINDIA
×

Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.

  • Distributors & VADs
  • Industry Associations
  • Telco's in India
  • Indian Global Leaders
  • Edit Calendar
  • About Us
  • Advertise Us
  • Contact Us
  • Disclaimer
  • Privacy Statement
  • Sitemap

Copyright varindia.com @1999-2024 - All rights reserved.