Skip to content
Wednesday 26 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,886.16
+0.29%
DAX
26,266.14
0.00%
CAC 40
8,439.20
0.00%
STOXX 50
6,455.63
0.00%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
Tuesday 29 March 2016 9:57 am

Cyber security: Why the EU General Data Protection Regulations will be game changing for unreported cybercrime

By: Hayley Kirton

Add as a preferred source on Google

A report by the Institute of Directors (IoD) and Barclays recently highlighted that one quarter of organisations had suffered a breach in the last twelve months, although only 28 per cent had reported it to the authorities. It is believed that the actual numbers of attacks could be higher.

The fact is that there are still a large number of organisations simply not aware of incidents, or that don’t have the technology or processes in place to identify or respond to a data breach involving personal information. In many instances, attackers can go undetected and access sensitive information for months before being discovered.

Moreover, the scope of where personally identifiable information (PII) resides – from phone numbers to IP addresses and credit card details – is often far wider than many organisations may have considered.

However with the impending EU General Data Protection Regulations (GDPR) expected to come into effect in early 2018, this will need to change. The race is on for organisations to start preparing now with an IT infrastructure and processes which will protect personal data and meet GDPR requirements.

Read more: Firms failing to tackle social media security threats

Under these new laws, if there is a data breach, they will have to inform the authorities "without undue delay and, where feasible, not later than 72 hours after becoming aware of it". Failure to comply will come with fines which could be up to four per cent of an organisation's annual revenue.

One of their biggest challenges is to get a handle on how and where they collect, process and store PII. Specific databases, HR and financial software can be identified easily. Working out their corresponding security strategies is a challenge but well understood. However, it’s not only applications such as these that store personally identifiable information; normal user activities like logging into social media, online banking or remote access also produce PII in the form of access credentials, cookies and geolocation data and get recorded in system and application logs.

Since organisations have obligations to store log files for years – depending on the industry and compliance regulations – over time a hacker or, even a malicious insider, could collect many different forms of data to create an holistic picture of an individual.

Read more: Cyber experts not sharing as much as they should

We may not be able to change this user behaviour, but organisations can take steps to mitigate the risk by collecting information in a way that is secure, encrypted and anonymised to ensure it cannot be linked to an individual. With targeted attacks on the rise, they also need to improve the way they are able to detect unusual behaviour, with monitoring tools that can identify, for example, if a user’s account has been hijacked, so that attacks don’t go undetected for months.

As organisations can only report what they know about, visibility of where data is, and unusual activity, will be key.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Opinion

Categories

  • Opinion

Trending Articles

  • Andy Burnham hints at tax rises in Autumn Budget

  • Budget 2026: Which taxes will Burnham and Healey hike?

  • Burnham shelves Thames Water administration plans over costs

  • As it happened: Stocks rally; US to unveil ‘economic D-Day’ Iran sanctions

  • As it happened: FTSE 100 jumps in best streak since May; Vistry, Melrose lead risers

More from Morning Wire

  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
  • Thumba Announces Strategic Partnership With Testhouse to Accelerate AI-Powered Quality Engineering Innovation

    Business Wire
  • TikTok loses court battle over £12.7m child privacy fine

    Tech
    Tiktok appeals to overturn US ban in a broader battle for tech regulation
  • Sia Accelerates Its Expansion in Australia with the Acquisition of Seven Consulting

    Business Wire
  • Brits fear AI is slipping out of human control after ‘rogue’ systems escape tests

    Tech
    Dario Amodei, CEO of Anthropic, speaking at a tech conference podium, wearing a suit and addressing the audience.
  • How Britain can stay clear of rivals as home of overseas sport club owners

    Sport Business
    Football fans protest holding Love United Hate Glazer and Glazers Out Ratcliffe Out banners.
  • Thames Water faces fresh threat to survival after pensions regulation breach

    Water
    Thames Water infrastructure with pipes and maintenance workers, highlighting water management efforts in London
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook