enterprisesecuritymag

APRIL 2020ENTERPRISE SECURITY| | 9All of this rests on your employees and contractors reporting breaches to you straight away. Also, having processes in place for this to be done it is essential to have a culture that encourages reporting. Where employees are anxious about reporting for fear of repercussions, breaches can get hidden. People may not admit to a breach, especially where it involved human error, if they think they will be disciplined. Internal league tables showing the number of breaches by team or department can create a culture where the number of breaches is key--the fewer reported internally the better and those teams with a high number of reports are seen as failing.But is that really the case? Are those lower reporting areas really better at avoiding data breaches and so demonstrating higher compliance levels? Or are they merely better at hiding the errors and being less honest, hoping that their breaches will not be so serious they are found out?It is important for organisation to look into the reasons behind low levels of breach reporting. As well as the potential difficulties failure to report internally can cause, given the duty to report and the possibility of reputational damage down the line, it is also bad business practice. Organisations can learn from low-level breaches and near misses. They can use those lessons to improve practices and processes to avoid a more serious breach occurring. It is often the case that a reportable breach doesn't come out of the blue; there may have been numerous smaller non-reportable breaches of the same type before. An example would be when non-sensitive personal information is sent to the wrong postal address, the recipient realises they have received the letter in error and sends it back unopened. This is not a reportable breach, but it does give the organisation the opportunity to examine what went wrong. Was it human error in inputting the address? Is there a problem with the system not updating addresses promptly? or Is one part of the organisation being told of a new address and this not being shared where it is needed? Learning from the low-level breaches and near misses can help you find and fix the weaknesses in processes before a major issue occurs.Having an internal culture of openness around breaches, where everyone is encouraged to report is essential. Whilst there is always the possibility of disciplinary action for breaches caused by egregious human error, staff should be reassured that generally self-reporting would be a mitigating factor for them and is to be encouraged. Staff should be encouraged to be open and honest, to work with the data protection and information security teams to mitigate breaches and to proactively suggest process improvements to prevent breaches. Senior management should be encouraged to view an increased level of breach reporting as a useful tool to look for trends and issues before they become major problems, and not view an increased number as a problem in itself.There's a role for the Data Protection Officer to play here--where the organisation has one in explaining why an increase in reports of breaches and near misses can be an opportunity for improvements rather than necessarily a cause for concern. ESEach organisation needs to keep comprehensive records of breaches, the risk assessments they have carried out of those breaches, and the mitigations undertaken to contain or neutralise the breach
< Page 8 | Page 10 >