Evento di Lancio: Smart AI Security. Controllo Totale dei Dati. Prenota il tuo posto

chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
Securing Generative AI for Dummies
Securing Generative AI for Dummies
Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

It’s time to take GDPR seriously

Mar 14 2017
Tags
Cloud Best Practices
Cloud Security
Compliance
GDPR
Tools and Tips

The EU General Data Protection Regulation (GDPR) aims to better protect the privacy of personal data for EU citizens. It’s considered the world’s most significant — and aggressive — data privacy law to date, and, with just over a year until it goes into effect in May 2018, it’s time for businesses to start taking it seriously.

Here’s why: it affects businesses in nearly every country in the world. Any company that markets goods or services to EU residents is subject to the GDPR, regardless of where it is located. Companies that violate this regulation can face charges of up to €20 million or four percent of their global revenue, whichever is greater.

To give an example of the impact of the regulation, consider these hypothetical fines that could come from failure to comply:

  • General Mills -$164 million
  • Apple – $8.6 billion
  • HP – $1.9 billion.

These numbers are staggering and should serve as a wake-up call for businesses to start taking steps toward compliance.

Here are a few important steps to take in order to ensure companies are heading in the right direction.

First and foremost, educate your employees.

Our survey at this year’s RSA conference found that 51% of respondents have never even heard of the GDPR, and only 9% have detailed knowledge of the regulation. What’s more, 75% of respondents stated that their employer has neither informed them about GDPR, nor how the regulation might affect work processes. Only 9% stated that their company has offered plenty of information.

These numbers are concerning, and prove that companies aren’t taking the regulation seriously enough. Businesses must educate their employees about the regulation, and how it affects not only company data, but the personal data they share through their devices and the cloud services they use.

On that note…

Know the cloud services used within your organization

Our RSA survey also found that businesses severely underestimate the number of cloud services in use in their organization – over half (53%) of respondents estimated that there are less than 100 cloud services in use. In reality, this number is over ten times higher – our January Netskope Cloud Report found that enterprises are now using, on average, a total of 1,031 cloud services.

Even more concerning, 94.8% of cloud services  are not enterprise ready, meaning they lack necessary security controls.,Because many companies lack visibility into their cloud service  environment, this is an important next step in moving toward GDPR compliance.

Above all, remember this: you’re only as secure as your knowledge of your cloud service ecosystem. If one of your employees is using an unsanctioned, non-GDPR-compliant cloud service, your organization is at risk of failing to comply.

Know what data is in the cloud, both corporate and personal


It’s important that enterprises are aware of both the cloud services in their environment and the data resident in those services.. This is not just limited to corporate data, but also to personal data (e.g., a user’s PHI, PII). One challenge for organizations is that many, if not most, personal data for which the organization is legally responsible are found in emails and unstructured content like documents that are stored  in cloud services not sanctioned by IT. The data are then downloaded and stored on mobile devices and shared with others outside the company, taking it out of the IT department’s direct control.

To become compliant, organizations must have insight into which personal data are processed by users and cloud services, prevent personal data from being stored in ways that violate security policies, and protect personal data when stored or processed through cloud services. Companies will need to implement measures to bring such cloud services under the visibility and control of the organization.

Make sure your cloud services are GDPR ready

Businesses have a long way to go before their cloud services are GDPR-ready. The January Netskope Cloud Report found that 66% of all cloud services do not meet the threshold for GDPR compliance, meaning they lack proper residency, privacy, and security controls to meet the requirements of GDPR. This percentage has decreased from the 75% we found in our June 2016 Cloud Report, but it’s a staggering number given the regulation goes into effect in just over a year.

Digging in further, the January report found that 82% of cloud services do not encrypt data at rest, 66% do not specify that their customers own the data in their terms of service, and 42% do not allow administrators to enforce password controls. Because these features are all required for full GDPR compliance, this is a problem that businesses must address if they want to avoid fines.

Whether you’re a European organization or a multi-national organization with European customers, the GDPR will have major effects on your approach to and use of the cloud. Having visibility into and control of your data are key ingredients in taking steps toward compliance in the coming fourteen months.

Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.