Skip to content
Friday 28 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,807.80
+0.14%
DAX
26,491.93
+0.47%
CAC 40
8,391.52
+0.86%
STOXX 50
6,466.89
+0.66%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
Tuesday 29 March 2016 9:57 am

Cyber security: Why the EU General Data Protection Regulations will be game changing for unreported cybercrime

By: Hayley Kirton

Add as a preferred source on Google

A report by the Institute of Directors (IoD) and Barclays recently highlighted that one quarter of organisations had suffered a breach in the last twelve months, although only 28 per cent had reported it to the authorities. It is believed that the actual numbers of attacks could be higher.

The fact is that there are still a large number of organisations simply not aware of incidents, or that don’t have the technology or processes in place to identify or respond to a data breach involving personal information. In many instances, attackers can go undetected and access sensitive information for months before being discovered.

Moreover, the scope of where personally identifiable information (PII) resides – from phone numbers to IP addresses and credit card details – is often far wider than many organisations may have considered.

However with the impending EU General Data Protection Regulations (GDPR) expected to come into effect in early 2018, this will need to change. The race is on for organisations to start preparing now with an IT infrastructure and processes which will protect personal data and meet GDPR requirements.

Read more: Firms failing to tackle social media security threats

Under these new laws, if there is a data breach, they will have to inform the authorities "without undue delay and, where feasible, not later than 72 hours after becoming aware of it". Failure to comply will come with fines which could be up to four per cent of an organisation's annual revenue.

One of their biggest challenges is to get a handle on how and where they collect, process and store PII. Specific databases, HR and financial software can be identified easily. Working out their corresponding security strategies is a challenge but well understood. However, it’s not only applications such as these that store personally identifiable information; normal user activities like logging into social media, online banking or remote access also produce PII in the form of access credentials, cookies and geolocation data and get recorded in system and application logs.

Since organisations have obligations to store log files for years – depending on the industry and compliance regulations – over time a hacker or, even a malicious insider, could collect many different forms of data to create an holistic picture of an individual.

Read more: Cyber experts not sharing as much as they should

We may not be able to change this user behaviour, but organisations can take steps to mitigate the risk by collecting information in a way that is secure, encrypted and anonymised to ensure it cannot be linked to an individual. With targeted attacks on the rise, they also need to improve the way they are able to detect unusual behaviour, with monitoring tools that can identify, for example, if a user’s account has been hijacked, so that attacks don’t go undetected for months.

As organisations can only report what they know about, visibility of where data is, and unusual activity, will be key.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Opinion

Categories

  • Opinion

Trending Articles

  • Pensioners to hand over bank statements in government benefits crackdown

  • Jamie Carragher: HMRC petitions for Sky Sports star to be declared bankrupt

  • Brewdog founder James Watt hits out at ‘total silence’ over new venture

  • Lloyds Bank and Halifax users unable to use app in latest outage

  • Economists urge Bank of England to halt bond sales as borrowing costs climb

More from Morning Wire

  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • Thumba Announces Strategic Partnership With Testhouse to Accelerate AI-Powered Quality Engineering Innovation

    Business Wire
  • TikTok loses court battle over £12.7m child privacy fine

    Tech
    Tiktok appeals to overturn US ban in a broader battle for tech regulation
  • Brits fear AI is slipping out of human control after ‘rogue’ systems escape tests

    Tech
    Dario Amodei, CEO of Anthropic, speaking at a tech conference podium, wearing a suit and addressing the audience.
  • Sia Accelerates Its Expansion in Australia with the Acquisition of Seven Consulting

    Business Wire
  • Thames Water faces fresh threat to survival after pensions regulation breach

    Water
    Thames Water infrastructure with pipes and maintenance workers, highlighting water management efforts in London
  • How Britain can stay clear of rivals as home of overseas sport club owners

    Sport Business
    Football fans protest holding Love United Hate Glazer and Glazers Out Ratcliffe Out banners.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook