Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Thursday, 21 June 2018

A Market Overview on the Changing Data Landscape



- Alan Jamieson


We live in changing times and data has become a major part of our lives.  With the recent enactment of the General Data Protection Regulation (GDPR) in late May, we have all been inundated with privacy emails from our suppliers emphasizing that we own our data which helps both parties with relevant information, offers etc.

Having data and the rights to opt out are important, but how do we know it’s safe with ongoing, frequent data breaches across the globe? Can we cope with the number of offers sent to us from suppliers who hold our data, and can we be assured that they are using my current and historic personal data?  If data has been collected over weeks, months and even years, the reality is the more data you can analyze, the greater insight can be obtained.

A few years ago, data was expected to increase in volume by 100% annually, which challenged computing infrastructures and brought to light questions such as where is the most cost-effective place to store the data? And, what analytical tools should we be using? Can the tool look at all data types (structured and unstructured)? Do we need to hire data scientists looking to make real-time decisions? Are we aware that running complex queries take time? Today, most data volumes are increasing higher than previously predicted, especially in social media where data volumes can increase by Petabytes of data daily (not solely text but increasingly with video and audio content) and through our adoption of IoT products.

Terminology is also changing, terms such as big data. which had various means based on its context.  Gaining business insights from the increasing volumes of data being held are important to help improve user experiences, drive business efficiency, help fine tune marketing offers, and predict what equipment needs maintenance to avoid unnecessarily outages etc.

While we can protect data through encryption technologies either when data is at rest or in transit, searching for data in databases (on prem or in the cloud), repositories such as Microsoft SharePoint and other documentation types is also a critical challenge. It’s great to collect data but it you can't easily access it, you are incurring unnecessary storage business costs that will not be recovered.

Speaking to enterprise customers and global vendors, there is another change in how we interact with data.  With our widening generation employee bases across most enterprise companies, how we access data is changing.  Our younger global workforce, who have grown up with smartphones, are increasingly looking to request information or data via a voice request and not a keyboard.  Enterprise companies must cater for information or data access via keyboard and/or voice request but only to authorized data requestors. 

We at BOHH Labs address this changing data landscape with a service that provides voice and keyboard access to secure data enabling data analytics to be performed whilst importantly preventing data breaches. We are hoping to lead a shift in how the market both views and interacts with their data. After all, data is a business asset and we are looking to help companies unlock its value.

Thursday, 29 March 2018

How Does the United States’ Approach to Security Compare to the Rest of the World?


- Alan Jamieson, BOHH VP of Business Development


Continual data breaches and the constant collection of personal information fuels debate on whether privacy is dead in the digital age. Regardless of who is winning this debate, privacy, security and trust—all increasingly at risk—are vital and must be interlinked in our data-driven society.

With the global focus to prevent cybersecurity threats or attacks, companies are investing in new strategies and even new roles, such as Chief Privacy Officer. CEO’s and their Boards say they are investing in cybersecurity to build trust with customers concerning the usage and storage of data, but is that enough?  As we have seen after many breaches, consumers will vote for responsible innovation and data use with their wallets.  In fact, we have seen a significant number of Fortune 500 companies who have lost significant earnings and customer retention because they have not adequately protected customer data as they embrace the digital times.

As security becomes more critical to the existence and growth of companies, some parts of the worlds are better prepared than others to combat these complex cyberattacks. Where does the US fit in?

The Global Cybersecurity Index (GCI) is a survey that measures the commitment of 193 Member States to cybersecurity in order to raise awareness.  In 2017, The United States was ranked 2nd globally in the Global Cybersecurity Index 2017, the first and third places were taken by Singapore and Malaysia respectively.  Europe’s best country was Estonia ranked 5th globally. 

  • Singapore ranks number one as its started its cybersecurity strategy in 2005, so it has greater knowledge and experience than most other mature countries.  Singapore’s Internet Content Providers (ICPs) and Internet Access Service Providers (IASPs) are licensable under the Broadcasting Act and they are required to comply with the Internet Code of Practice to protect children online. Since 2012, all service providers have been legally obligated to offer filtering services with Internet subscriptions and to make this known to consumers when they subscribe or renew. The Info-communications Media Development Authority also symbolically blocks 100 pornographic, extremist or hate websites.  Malaysia is second in Asia and third globally, its Government is a strong advocate of cybersecurity which focuses on businesses and Government alike. Malaysia created the Information Security Certification Body (ISCB), a department of Cybersecurity Malaysia, which manages information security certification.

Leaders in the United States and European Union have recognized that the interconnected nature of information and communications systems and the global nature of the threats demand international cooperation.  Legalizations that are driving change and commonality of strategy between the US and European Union (EU) are:

  • In the United States, the centerpiece is the National Institute of Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity (NIST Framework) issued in 2014.  It’s now undergoing revision, coupled with state data breach notification laws and regulation of data security practices by various federal and state laws and agencies.
  • At the European Union level, legislation that takes effect in 2018: the Network Information Security Directive (NIS Directive) and the General Data Protection Regulation (GDPR) effective May 25, 2108.

While there are certain differences between the US and EU legal processes, their approaches to cybersecurity are aligned in essential ways.

Cybersecurity is an ecosystem where laws, organizations, skills, cooperation and technical implementation needs to be in harmony to be most effective.  Cybersecurity is not just a concern of the Federal or Central Governments, but also needs commitment from the private sector and consumers which we are starting to see happening in the tumultuous cybersecurity climate. As such, it is critical to develop a cybersecurity culture where citizens are aware of the trade-off between risks and monitoring of personal data when using electronic networks for research, data storage and/or acquisition.

While, the US was ranked 2nd in 2017 for commitment to cybersecurity, as the cyber threat grows, so must the government’s capabilities to put forth strategies to keep its citizens and their information.

Up until now, a large amount of cybersecurity protection efforts have largely fallen on private sector institutions, but many government officials and security experts believe not enough is being done and more standard regulations are needed. Already we are seeing more states bring forth their own data breach notification laws, privacy laws, and even cloud regulations, but only time will tell if and when these get passed and what impact they might have. As the number of security breaches and threats continue to rise, it is time we start to take a closer look at the standards we are using and re-evaluate what tools are needed to keep information protected from. Cyber hacks have become more complex and it is time we figure out how to flip the switch on them as well. 


Tuesday, 9 January 2018

BOHH Breakdown Part 17: Advice from BOHH for Starting 2018 Right and Tackling Security


It’s the start of a new year and with that comes new goals and resolutions. As cybersecurity continues to be a top concern for companies, it will most certainly be at the top of most companies’ resolution lists. However, staying ahead of the quickly evolving cybersecurity industry has become increasingly challenging, and it’s hard for companies to stay on top of all the threats and solutions they should have in place. Below are several ways BOHH recommends for companies to start 2018 right and help them better tackle their security resolutions.

Finalize your General Data Protection Regulation Plan: 
If this is not in action now or at the top of your list, it is time to get started on this now. Going in to effect later this year in May, companies will need to comply with the GDPR regulations, which applies to all companies that use or process data in the European Union. Since there are a lot of moving parts to ensuring compliance, it is important to take a strategic approach. There are many new changes that companies will be accountable for, so it’s critical to research them properly and have a specific plan for each one. Having your GDPR plan in action and completed by May 2018, will help you avoid fines or penalties imposed on a non-compliant company, as well as stand out as leader in the market committed to security.

Always Implement New Security Patches and Update Old Systems: 
Because software systems are constantly evolving, security updates and patches are commonly released to keep up with software improvements. Often, these patches come with instructions to make the updates, and failure integrate these into your system can lead to vulnerabilities and allow hackers to gain access company and customer data. Unfortunately, as we saw in many data breach instances in 2017, many businesses often ignore patches or updates until they encounter issues. When this happens, it leaves the door open for hackers use malware and other type of attacks to exploit these holes and get into your system. Companies that monitor when new patches and updates are out and implement them immediately will face less risk to breaches than those do not and avoid having to undergo an embarrassing explanation on why they are not up-to-date with the recommended security systems.

Create a Zero Trust Model:
There is no longer any trust in security. It’s clear there are no longer any trusted and an untrusted engagements on our security devices, networks or even users. In 2018, companies need to eliminate the idea of a trusted network and start implementing a zero-trust model approach that views all users and network traffic as untrusted that must be verified and enforce strict access control. 

There’s No One Size Fits All:
When it comes to security, there is no quick fix or a magical solution that will solve all your security woes. Because there are more tactics to get into a company’s network, it’s hard for companies to rely on just one or two solutions to stay protected. The best way to stay on top of all the threats is by having a combination of solutions like patched systems, constant updates, multi-factor authentication, firewalls, encryption, AI-based tools and more. More than ever, it is important to take the time to make sure you have the right security investments in place and not rely on just one or two.

Hopefully these recommendations will be useful to get your 2018 security strategy started right. Come back next Tuesday when we take a closer look back at the latest news on the Intel chip security flaw and what is the good and bad to take from it.

Tuesday, 12 December 2017

The BOHH Breakdown, Part 15: How to Get Your Board Involved in Your Cybersecurity Strategy


In our last post, we shared tips for individuals to stay safe as they begin their Christmas holiday shopping this season. Today, we will address an increasingly important topic – how to address cybersecurity with your board of directors. 

One thing is becoming increasingly clear in today’s climate of nonstop breaches: security matters and data is becoming an asset. It’s time organizations treat cybersecurity as a core business value. Business leaders, starting from the Board of Directors and moving through the C-suite, must insist on their organizations adapting the most effective security measures in their IT platforms, workflows and processes today. 

However, many board members feel they lack the technical aspects about what their role should be as directors when it comes to cybersecurity. Below are some tips to get the conversation started.

  1. Speak in language your board understands. Many board members may not know the technical terms when speaking about technology and security.  Try to break it down in terms that are simple and easy for a non-technical professional to understand.
  2. Talk about security investments and cybersecurity risks in terms of how it impacts the organization’s business and financial bottom line.
  3. Communicate everything in numbers. The board is the oversight of the company, so money matters. If you can relate security investments, potential breach loss, etc. in dollars, it will have a greater impact to how cybersecurity can impact the organization overall.
  4. Tie cybersecurity measures to the competitive marketplace. Highlight what the company’s competitors are doing, so the board can understand how the company needs to keep pace with the market. 
  5. Share examples of how cybersecurity breach incidents have impacted other organizations in your similar market (Equifax, Uber etc.) – did they lose customers, pay a breach settlement fine, pay a ransom fee?
  6. Present the facts of the company. To start a conversation on why having proper security strategies in place is important, gather a list of the organization’s valuable data assets that require protection, so you can customize the conversation to your company’s specific needs.
  7. Share a game plan on where and how you think the board should be involved in the company’s cybersecurity strategy. Having this prepared ahead of time will help show the board where they fit into the plan.
  8. Bring in a security expert to talk to your board about the importance of having proper cybersecurity measures in place. Having a trusted source always goes a long way in the decision-making process, plus highlights the consequences of a breach such as fines, potential senior job losses etc.
  9. Educate them on all of the laws and industry compliance rules in place. This will help them understand why a certain amount of the business strategy needs to be designated to security investments.  Highlight that General Data Protection Regulation (GDPR) is effective starting in May 2018, so there must be a strategy to meet this deadline.
  10. Be concise and clear. Do not waste their time. Prepare ahead of time the main points you want to hit to educate them on the necessary security investments.

Leaders who make security a business priority and an integral part of their organizations daily operations, can help navigate their organization to better long-term performance and success. 

Hopefully these will be a useful tool to get the conversation started. Come back next Tuesday when we take a look back at all of the developments and accomplishments made by BOHH this year.

Tuesday, 28 November 2017

The BOHH Breakdown, Part 13: BOHH Predicts the Top Security Trends for 2018


In our last post, we reviewed some of the best security techniques being used to keep our data protected and that we are grateful for in honor of Thanksgiving. Today, we will shed some light on what the team at BOHH Labs believes will be the hot topics in 2018 and share our predictions.

Every year experts turn to their magic crystal ball and share their thoughts on predictions they have for the upcoming year. Will we see the same trends from 2017 repeat themselves or we will see new ones develop in 2018? Below our experts from BOHH Labs weigh in on the discussion and offer their predictions for what’s ahead.

Blockchain will be the Heart of The Finance Industry:
It’s no secret that blockchain is the hot new technology, and we will see this technology be embraced   predominantly by the financial industry. Because of its decentralized and distributed nature, more financial services institutions are looking at blockchain to replace the centralized business model. As an example, KPMG, one of the “Big Four” accounting firms, recently just joined the Blockchain Advocacy Group.

As Bitcoin is based around blockchain technology, and it has seen significant growth in value during 2017 event though it’s an unregulated currency, will continue to increase when security is a potential issue or will it fall off the tracks?


NASDAQ Advising People to Jump on Security Boards:

We all know security breaches are a big deal, so why aren’t more board of directors versed in the area? As the oversight of an organization’s value and growth, it’s critical for security to become a business priority and an integral part of their organizations’ daily operations. This means a companies’ cybersecurity activities must hold as much weight in decision-making in the same way as they do in the financial ones. As such, in 2018, we will see NASDAQ advise more security expert to join companies’ boards, so they can help companies navigate to better long-term performance and success.

Website Attacks Become a Bigger Target:
One of the type of attacks that we will see gain more traction this year is the website attack. With the growing use of online services (checking accounts, merchant accounts and Point-of-Sale (POS) systems, etc. now going through the web) the risk of attacks is large and has the potential to affect any institution using these services, as it opens access to institutions’ backend databases, document stores and applications all within easy reach. 

Because an attacker gains access to the website through a hijack of a user’s requests and then makes a simple change of code to redirect payment information their way, while NOT stopping the requests correct path, this type of attack is very hard to find, but incredibly easy for attackers to undertake.

The website is no longer just a marketing tool. It has become a business tool, and as such, it now needs to be properly protected from attacks and placed inside a firewall, and preferably completely encrypted, so that attackers are unable to change, manipulate and delete code to their advantage.

Continued Chat Bot Growth:
The growth in the business use of chat bots will continue to increase based on their interactive nature and their capabilities to complement existing call center activities by taking away mundane tasks. However, with their interactive capabilities and the ability to use location services to reserve a table in your proximity and even order an item such as a coffee, it is becomingly increasingly important that all chat bot transports are secure.  Similar to website data breaches, should intrusion attacks penetrate the chat bots, user trust will be lost as well as the possible loss of confidential data.

Public Cloud Adoption will Continue to Challenge Enterprise Companies:
While Cloud adoption is the goal of most global enterprise companies to help improve their IT speed, business agility, and modernize existing on-premise applications such as ERP, Finance and HR, adoption will be limited due to the time and money needed to implement cloud security standards that emulate enterprise on premise infrastructures.  

By using a secure gateway to a Public cloud provider, enterprise accounts could accelerate their cloud deployments and benefit from the economics of cloud, plus have the ability of choice and move Cloud providers as the business sees fit.

IoT Attacks Will Keep Growing:
We will continue to see companies scramble to implement security for IoT devices and applications. We’ve already seen the significant and expansive impact that hacks on IoT devices can have and it will only continue as we move in to 2018.

General Data Protection Regulation: 
Effective from 25th May 2018 companies will need to comply with the General Data Protection Regulation (GDPR) which applies to all companies that use or process data in the European Union.  As several analyst articles suggest, only 25% of companies are expected to be in full GDPR compliance in May 2018, and as a consequence of this, the initial fine or penalties imposed on a none compliant company will be significant to warn other companies of its importance.

Now that we’ve highlighted some of the major security themes we predict will take center stage in 2018, come back next Tuesday when we will share some tips to stay cyber safe in the holiday shopping season.

Tuesday, 10 October 2017

The BOHH Breakdown, Part 6: How BOHH Labs Helps Meet GDPR Requirements


In our last post, we talked about how the ease of implementation when integrating a new cybersecurity tool into your existing infrastructure network can help enhance productivity. Today we will address a situation many companies are facing and trying to beat the clock on: how to comply with GDPR regulations and how BOHH Labs’ security solutions can help organizations successfully address many of the requirements.

The General Data Protection Regulation (GDPR) is the biggest change to European Union (EU) privacy law in over 20 years, and it will have a major impact on how many organizations in the EU and across the globe collect, use, and store personal information about individuals. Although greater data protection is becoming more important than ever, the burden of updating security polices and strategies for organizations to comply with GDPR can be overwhelming and take a considerable amount of time and resources. As the deadline for complete GDPR compliance in May 2018 nears, many companies are scrambling to find solutions and make updates that meet the requirements. 

BOHH Labs’ security solution was built on making data privacy a priority, so we are confident that our security solution will help organizations successfully address GDPR requirements. Our approach to security is to become more dynamic within the existing system and protect data from within. While our security approach focuses on on-premise and Cloud data security, the concept of securing and managing data in certain domains has many parallels with GDPR regulations. 

How we do this?

Unique Encryption
Our approach to security is to encrypt all data in real-time, while still retaining search capabilities, but only providing access to data to authorized parties. Our patented, unique encryption algorithms are proven to secure with no key store or data storage, enabling us to help organizations mitigate data breaches and any associated penalties.

Data Records 
BOHH Labs’ proven security platform helps companies to maintain data records and audit data is available if required (although as part of our data privacy philosophy, we don’t keep historic data today, but it can be stored within an enterprise database).

Infrastructure Agnostic
Our appliance is infrastructure agnostic and is deployed on top of existing systems between the infrastructure, firewalls and transactions with both Cloud and on-premise implementations, so there is automatic backend data protection as data goes in and out of the entire ecosystem. 

Data Masking
GDPR punishes businesses that fail to leverage appropriate protection measures – such as data masking technologies—as a part of their overall security posture. Data masking enables companies to fulfill GDPR requirements to pseudonymize (anonymize) sensitive data that otherwise could directly or even indirectly identify a specific individual.  BOHH’s encryption capability helps companies to protect/mask data from unauthorized users. 

Right to Access
GDPR also introduces the right for data subjects to obtain from the data controller confirmation as to whether personal data concerning them is being processed, where and for what purpose. This means companies must be able to find and produce a copy of an individual’s data quickly among the millions of data they hold. BOHH Labs helps solve this with its patented, secure federated search that enables for one request to perform a simultaneous search across multiple repositories in real-time to return results in under a millisecond. 

As organizations work toward implementing strategies to be compliant with GDPR, BOHH Labs is here to help companies focus on data privacy and provide a simple and quick solution to successfully meet many of the requirements. For more information on how BOHH Labs can help with compliance, reach out to us at info@bohh.io.

Now that we’ve looked at how BOHH Labs’ security solution can help organizations successfully address GDPR requirements, check back in next Tuesday when we will revisit some of the most pressing cybersecurity trends in 2017 we cited at the beginning of the year and track where the industry is at as the end of the year nears. 

Thursday, 10 August 2017

The Impact GDPR Compliance Will Have Across the Entire Business Ecosystem



Insight on GDPR from BOHH's Becca Bauer

There is now less than a year for organizations collecting, using or working with anyone that handles data regarding citizens in the EU to get their policies in place to comply with the mandated General Data Protection Regulations (GDPR) that go into effect in May 2018.

Although greater data protection is becoming more important than ever as our economies become digitized and the potential for breaches have become a daily norm, the burden of updating security polices and strategies for organizations to comply with GDPR can be overwhelming and take a considerable amount of time and resources. As companies scramble to integrate GDPR-compliant solutions in to its data protection and collection strategy, it is likely to have some profound impacts on how the entire business operates. Below are three ways some of the key changes mandated by GDPR will make an impact on organizations’ entire ecosystem.


Reputation Damage and Strict Penalties


It is no secret that data breaches often bring negative press and a lack of trust among consumers, and while some of these breaches result in settlements, most until now have not had financial penalties. One of the major impacts GDPR will have on organizations is the pressure of strict fines if companies are found to be in breach of GDPR or do not follow the proper procedures following the event of a breach. According to the EU GDPR site (http://www.eugdpr.org), the new regulations have fines of up to 4% of annual global turnover or €20 million, which is enough to not only financially hurt a company, but will also draw attention to them in public for being in defiance of the law and a standard set of security and privacy regulations that organizations must comply with to ensure an individual’s data is protected.


Approach to Data/Technology Management
Much of GDPR centers around how companies are collecting, storing and using individual’s information. Under GDPR, companies must offer individuals, whose data they hold, to the right to be notified if a data breach exposes their information, the right to access their own personal data when they request it, the right to be forgotten, and the right to data portability. These new regulations will have a major impact on the strategies companies use to protect data privacy. This means organizations need to build more flexible architectures that will easily allow them to incorporate innovative technologies and security solutions that meet these new requirements. However, this can quickly become expensive and complex with updates such as legacy to cloud infrastructure overhauls and the addition of at least one or more products to enhance data protection.

Not only does this bring increased costs to how the data privacy strategies work, but it also brings in to question the management of these processes. Collaboration will be crucial when updating these policies. There needs to be coordination among the different departments in the organization from the various IT teams handling how data comes in and out of the company to the marketing department who collects data for analytics purposes. Cross collaboration will be key in ensuring the whole company is complying with GDPR, but it will most likely lead to a costly, complex strategy to update the data management across the whole company ecosystem, as well as a cultural shift in how your employees approach working with data and working and sharing data with other departments.

New Leader on Your Security Team


For companies who operate on a large scale, it will become mandatory to add a new leader to your security team: appointment of a Data Protection Officer. This new team member will have to be an expert on data protection practices, as well as be provided with all the necessary resources to comply with GDPR and maintain their knowledge on the industry. This equates to increased costs to the business with a new salary for an expert senior team member, as well as new technologies and resources needed for the DPO to carry out their job.

As organizations work toward implementing strategies to be compliant with GDPR, it is important they take in to account the implications all these changes will have organization-wide. With the need for increased budgets, personnel and technologies, the effort to become GDPR compliant must take in consideration the impact will have on the whole ecosystem and the amount of time and resources needed.