Get a free application, infrastructure and malware scan report - Scan Your Website Now

Subscribe to our Newsletter
Try AppTrana WAAP (WAF)

Managed WAF

Starts at $99

Guided onboarding, monitoring of latency, false positives, and DDoS attacks, custom rules, and more

Try Free For 14 Days

Why Companies Should Care about Data Privacy?

Posted DateMarch 23, 2020
Posted Time 4   min Read
Last Modified : [last-modified]

Data Privacy Day is here and it reminds us – businesses, organizations, and individuals – the need to think Privacy First and of the distance that we need to cover for establishing data protection and privacy.

In this article, we discuss in detail why data privacy is a pressing concern especially for businesses, and some best practices to ensure the highest levels of privacy protection.

Understanding Data Privacy

Data privacy is essentially about handling all data/ information related to a person/ entity’s identity (such as name, passport number, social security number, biometric records, financial information, etc.) with the utmost respect for confidentiality and anonymity. Examples of such data:

Why Should Companies Care About Data Privacy?

It is no news that we are generating several quintillions of data every day. It is almost a given these days for businesses to leverage data for a range of purposes across the organization. The challenge is to strike a balance between the use of personal data for business purposes with the individual’s right to privacy. With the ever-increasing number, frequency, size, magnitude, and sophistication of data breaches, privacy protection of data is emerging as undeniably one of the most pressing and defining concerns of the modern digital era; a concern that is starting to extend beyond the IT and cybersecurity spaces.

“New day, new data breach”, shows how far behind businesses, even the most tech-forward ones like Facebook and Yahoo, are in terms of fulfilling data privacy obligations towards the individuals – customers/ users/ clients, employees, vendors, partners, etc. Even when businesses are using personal data with the permission of the individuals in question, as mandated by privacy laws, there is a gross violation of customer/ employee/ stakeholder trust when data breaches occur along with the violation of the privacy protection laws such as GDPR, HIPAA, CCPA, etc.

Organizations often think that they need not bother about data privacy if there is no legislation in this regard in their country/ region. Every company, irrespective of its nature, location, or size, must take action immediately, make the right investments, and fortify its security posture and privacy protection as governments/ courts may not wait for legislation. Take Facebook’s example – they were slapped a USD 5 billion fine in February 2019 by the US Federal Trade Commission (FTC) for failing to protect customer data from third parties.

GDPR Fines by country at a glance – the world’s toughest data protection law:

Data Privacy

Image Source: eqs.com

The cost of data breaches and breaches of data privacy are hefty. There are, of course, financial costs such as fines, class-action lawsuits, loss of productivity, escalation costs, etc. But there are heavy reputational losses owing to the erosion of brand image, customer trust, loyalty, goodwill, etc. Larger organizations, with the resources at their disposal, may be able to resurrect themselves from such losses but many small and medium organizations are unable to make a comeback and often shut down.

Improving Data Privacy

Unlike other assets and resources, data is scattered within and outside the organization’s boundaries. So, ensuring data privacy and protection is no easy task. Simply increasing investments or buying an expensive security solution do not make the cut; there needs to be a company-level compliance program with well-documented KPIs that is embedded in the company’s culture. Steps must be taken to improve the granular architectural control of data by focusing on three important components of the organization’s culture – people, processes, and technology.

Indusface GDPR Data Processing Addendum – Now Part of Service Terms

People-Related Best Practices

  • Fully interview, educate and sensitize all stakeholders, internal and external, who have access to and use corporate data be it, customer data, employee data, or partner data.
  • Continuously communicate changes or reviews made to compliance policies, standards, practices, and laws to all internal and external stakeholders and ensure that they are making requisite changes to the workflows.
  • Educate, educate, and educate everyone in the organization, whether they work with data or not, to help them understand the importance of data privacy and protection. Help them understand the role they play in keeping the security posture strong and the steps they need to take to ensure they are not compromising the security of the company’s data or IT architecture.
  • Build trust with customers and other stakeholders by being transparent about not just how data is used, but also of major privacy failings and how the company plans to rectify the situation.

Process-Related Best Practices

  • Build a fully transparent system where you have a 360-degree view of how data flows within your company. Using a track and trace program for your corporate data, you will be able to document points of access, modification, distribution, etc.
  • Design a robust security strategy that enables you to monitor workflows, secure risky points of access, modification, and distribution of data, and gain control of data storage and backups.

Technology-Related Best Practices

  • Use an intelligent data discovery and classification tool to automate the task of data tagging, segmentation and improve traceability of data
  • Implement a robust multi-factor authentication system across your organization
  • Minimize data security risks by ensuring data is encrypted in transit and at rest
  • Implement an effective Data Leakage Prevention (DLP) solution and enforce data retention policies strictly
  • Use a WAF solution in blocking mode to prevent hackers from stealing sensitive data by exploiting your Internet-facing Web applications

It is not too late to begin your data privacy protection journey. Use the best practices outlined above to become an ethical, responsible, and trustworthy steward of data.

Stay tuned for more relevant and interesting security articles. Follow Indusface on FacebookTwitter, and LinkedIn.

web application security banner

Karthik Krishnamoorthy

Karthik Krishnamoorthy is a senior software professional with 28 years of experience in leadership and individual contributor roles in software development and security. He is currently the Chief Technology Officer at Indusface, where he is responsible for the company's technology strategy and product development. Previously, as Chief Architect, Karthik built the cutting edge, intelligent, Indusface web application scanning solution. Prior to joining Indusface, Karthik was a Datacenter Software Architect at McAfee (Intel Security), and a Storage Security Software Architect at Intel Corporation, in the endpoint storage security team developing security technology in the Windows kernel mode storage driver. Before that, Karthik was the Director of Deep Security Labs at Trend Micro, where he led the Vulnerability Research team for the Deep Security product line, a Host-Based Intrusion Prevention System (HIPS). Karthik started his career as a Senior Software Developer at various companies in Ottawa, Canada including Cognos, Entrust, Bigwords and Corel He holds a Master of Computer Science degree from Savitribai Phule Pune University and a Bachelor of Computer Science degree from Fergusson College. He also has various certifications like in machine learning from Coursera, AWS, etc. from 2014.

Share Article:

Join 47000+ Security Leaders

Get weekly tips on blocking ransomware, DDoS and bot attacks and Zero-day threats.

We're committed to your privacy. indusface uses the information you provide to us to contact you about our relevant content, products, and services. You may unsubscribe from these communications at any time. For more information, check out our Privacy Policy.

Related Posts

Data Privacy
10 Important Data Privacy Questions You Should be Asking Now

Learn the important questions that you should start analyzing to build robust data privacy and security policies.

Read More

AppTrana

Fully Managed SaaS-Based Web Application Security Solution

Get free access to Integrated Application Scanner, Web Application Firewall, DDoS & Bot Mitigation, and CDN for 14 days

Get Started for Free Request a Demo

Gartner

Indusface is the only cloud WAAP (WAF) vendor with 100% Customer Recommendation for 3 consecutive years.

A Customers’ Choice for 2022 and 2023 - Gartner® Peer Insights™

The reviews and ratings are in!