Cybersecurity 101: What Does the Law Say? November 8, 2023 – Posted in: Cyber Security, IT Support – Tags: cybersecurity 101, GDPR, it support
Surely you can’t be held responsible if a malicious criminal steals something from you? Unfortunately under the law you can!
Failing to take reasonable steps to protect the data your customers or suppliers entrust you with makes you culpable in the eyes of the law if it’s compromised. A key piece of legislation on this is the GDPR – General Data Protection Regulation. Not to be confused with the PECR – Privacy and Electronic Communications Regulations.
PECR covers what data you are permitted to hold, for how long, and what you are permitted to do with it. It also covers what rights people have to ask you about the data you hold on them.
GDPR outlines the expectations the law has on how you gather and store personal data. The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR). The key tenants are you everyone responsible for using personal data must make sure the information is:
- used fairly, lawfully and transparently
- used for specified, explicit purposes
- used in a way that is adequate, relevant and limited to only what is necessary
- accurate and, where necessary, kept up to date
- kept for no longer than is necessary
- handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
Failure to comply with the law could result in a significant fine for your business. The chance of you being randomly investigated is low, but should you be breached the ICO will look into it. And as we have discussed in our previous Cybersecurity 101 articles, the chances of being targeted are not insignificant.
The final bullet point is the one we are focused on here. The wording of that section of the law is that:
Each controller must implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that the processing of personal data complies with the requirements of this Part… The technical and organisational measures implemented … must be reviewed and updated where necessary.
If you hold data on customers or suppliers, including email addresses, names, job titles then you are a data controller. So what are appropriate technical and organisational measures?
One item states: In particular, the measures implemented to comply … must ensure that, by default, personal data is not made accessible to an indefinite number of people without an individual’s intervention.
Another states: Each controller and each processor must implement security measures appropriate to the risks arising from the processing of personal data.
Due to the nature of a law which is trying to future proof there are very few direct instructions outlined. If you were to state, for example all data must be password protected and someone were to invent a new, better, more secure option to protect the data, your law would be preventing the latest and best methods being used. On the other hand this can leave you unsure what you need to do.
Cyber Essentials
One of the most useful guides to what would be considered sufficient is the government’s own Cyber Essentials scheme. Whether you are planning to become accredited or not, it covers the key points to keep you secure. A brief outline of the key points it covers are:
- Do you have an asset register? This is one of the first questions – do you know what you have?
- Do you have a list of all software/firmware used in your organisation? Again, do you know what you are using?
- Do you have a list of all the cloud services used in your organisation? Information is key, do you know where all your data is being held?
- Do you have automatic updates enabled and do you use software that is no longer in support? Staying patched and up to date is a key component of any security plan.
- Have you been through your devices and disabled or removed the software you don’t use? And have you made sure that all accounts on your devices and cloud services are only business ones? Users sometimes sign into personal Google accounts on business PCs, this could lead to them syncing your business passwords with their home computer.
- Do all mobile devices that access your company emails or files have a locking mechanism (pin, password, face or fingerprint)?
- Default passwords – have you changed the default passwords on your equipment?
- Unique logins – all users should have a unique login and usernames and passwords should not be shared.
- Strong passwords – do you have a policy? Do you help staff follow it?
- Multi-Factor Authentication – have you enabled MFA on all cloud based accounts and services?
- User accounts – is there a process to make sure new users are only given access to what they need in order to do their jobs?
- Having Firewalls and Antivirus software, and Backing up data are also key points the scheme outlines.
You may be thinking – my IT Company should deal with most of this. For some items you’d be right, but have you checked? And do you know which ones you are expected to manage?
Reporting to the ICO
In terms of your obligations if you are breached, the law states that if a controller becomes aware of a serious personal data breach in relation to personal data for which the controller is responsible, the controller must notify the Commissioner of the breach without undue delay. Where the notification to the Commissioner is not made within 72 hours, the notification must be accompanied by reasons for the delay.
There are three key points to consider in relation to reporting a breach:
- Once you have notified the Commissioner part of their investigation will be into whether you could, or should have prevented it. The ICO is more and more prepared to fine people who have not taken all reasonable steps to secure their data.
- Note that the obligation to report is within 72 hours of the breach not of you discovering it. Not knowing about a breach is not necessarily considered a reasonable excuse for delay in notification, if the ICO considers that you should reasonably have had something in place to warn you of a breach.
- Once you have notified the Commissioner, you will likely be obliged to notify everyone who could have been impacted. Emailing your entire customer list to tell them that you were breached and their data may have been stolen is not good for your business image.
If you are looking for help reviewing your IT security give one of our Techs a call on 01245 265 100 or drop us an email on . In our next Cybersecurity 101 article we start to look at how you can protect your business.