By Nick RubleData governance software providers, Varonis, recently conducted a survey focused on getting to the bottom of how businesses handle the storage of sensitive data, and the results were surprising, to say the least. Findings show that a whopping 70 percent of all participating organizations are lacking confidence in just how secure their important data really is – 80 percent of which handle customer, client, vendor and business partner information.
For some reason, these organizations don't feel the need to take the UK Data Protection Act of 1988 very seriously, and that disregard can affect the entire operation in quite a negative manner. For one, there is a penalty of two percent of global revenue that these businesses may be subject to if their lack of security is brought to the attention of officials, and second, they're essentially putting their files up for grabs, to anyone who might want to steal crucial company information.
It seems unlikely at first thought, but think about employees who have been laid off, or those who simply hate their job – odds are, they know how the company carelessly stores its data, which makes it especially easy for them to get right in, grab what they want and get out with minimum effort.
“It's worrying that so many companies are still complacent when it comes to data protection. It means that these organizations would have some serious questions to answer should they suffer a breach,” said director of strategy at Varonis, David Gibson. “It's really not rocket science – if you've got sensitive data and you're not very confident that it's adequately protected, you need to take action,” he added.
Among those whom are lacking confidence in the security of their data, three percent don't have owners assigned for all data, 10 percent don't even know where it's stored, and a negligible, albeit existing percent, do not monitor all data access.
When the UK Data Protection Act was first established in 1988, it seems somewhat acceptable that not all organizations would comply right away, but it's been over two decades since then, and every business should be aware of the Act, or at least the risks they are facing in failing to properly secure their data. Even as recent as 20 years ago, computers weren't used for as much as today – but fact of the matter is, we use computers for nearly everything now – technology has improved dramatically, and likewise, malicious hackers and even the general computer user has become much more tech-savvy.
On a lighter note, of the remaining 30 percent in which had the utmost confidence that their data was thoroughly secured, 60 percent claimed that they were positive as to where it was stored, and 40 percent monitor all access and assign each set of folders and files to a specific owner. Nearly half of said businesses review and revoke permissions on a regular basis – regardless of whether or not an employee just left.