A third of organisations admit they do not have a system in place to adequately deal with security breaches
(18/03/2010)
Stewart Room is a partner at Field Fisher Waterhouse LLP and is the author of three books the most recent titled Butterworths Data Law & Practice (2009).
Stewart Room offers organisations structured advice to keep them out of court, and avoid the £500K fine to be levied by the Information Commissioner from April, should they experience a security breach or data loss. This is an area where organisations inherently fail to plan as, according to results of an online poll conducted by Infosecurity Europe, a third of organisations admitted if they experienced a security breach tomorrow they do not have a system in place to adequately deal with the incident.
Stewart’s advice is that as far as data security and handling is concerned, and in deed applies to any area where there’s a regulatory framework, organisations need to focus on two elements: the system and the operations.
The system sets out the organisations position on security through documented rules, policies and procedures; and the operations detail how the organisation implements the system in its day to day activities. The premise is that if the system is legally compliant and covers all the benchmarks within the legislation then the law says that operational failures can be excused.
That said, if you experience operational failure and a breach occurs, the law is then interested in whether the system in place covers containment, damage limitation and recovery. In Stewart’s experience it’s the system, especially this latter part, that has historically been ignored and it is on this point that many organisations face prosecution.
“Most organisations unfortunately don’t have good systems for actually managing the problem. If a breach occurs, the law is really concerned with your behaviour at that point in time. You can’t unravel the past and pretend the breach didn’t occur, it’s what you do from that point on that will determine your culpability” explains Stewart.
“The law is about changing behaviours, so if you adopt an honourable stance from the outset, doing the right thing at the right time, then your legal team are in a very strong position to defend you to the regulator arguing that you’re not the kind of organisation that has the profile that requires all of the effect of the law and therefore the punishment.”
Organisations need to adopt the right behavioural controls, preferably before a breach, so that if the worst should happen they know what the right thing to do is. In Stewart’s experience a data breach requires a multi-disciplinary response that may include some or all of the following disciplines; a security specialist, IT resources, a PR agency, legal advice, credit reporting services, credit file freezes etc., and an organisation should reflect on these requirements so that, in a crisis situation, it isn’t left floundering.
Stewart is participating in a panel discussion as part of Infosecurity Europe’s Keynote Theatre titled ‘Compliance – How To Defend Yourself And Stay Out Of Court’. For more details on this session, and Infosecurity Europe, visit www.infosec.co.uk. The event takes place at Earls Court, London, from 27th–29th April 2010.
Related topics: Data management and data security Security management and policies
Print version |
Email to a friend |
Related articles
Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.
Other Security news and resources
Security News
Suppliers Directory
Jobs forum
Classifieds
Knowledge base
White papers
Research library
Security books
Special reports
Security interviews
Security companies
Security events
Security links
Security market
Product channels
Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products
IT Security white papers and research library
Access Control Authentication Data Management Data Security Digital Signatures Email Security Identity Management Internet Security Intrusion Prevention Network Security Remote access security Security Management Security Policies Security Software Security Threats Virus Detection Software Virus Protection VPN Vulnerability Assessment Wireless Security
Security books, guides, standards and toolkits
RFID and Smart Cards books, guides and reference documents Biometric books, guides and reference documents CCTV books, guides and reference documents Intruder alarms and intrusion detection systems books, guides and reference documents Monitoring and surveillance books, guides and reference documents IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits Fire, Health & Safety books, guides and reference documents


