The Encryption Burden of GDPR and the New York DFS

The Encryption Burden of GDPR and the New York DFS

The persistently growing threat of cyber attack has begun to spur government agencies to enact security guidelines.  These guidelines will have a mounting effecting on private industry.

The most pertinent additions to these official protocols are the European Union’s General Data Protection Regulations (GDPR) and the New York Department of Financial Services (NYDFS) Cybersecurity Regulation. The rules codified by these documents affect IT practices in areas from data loss prevention, to compliance assurance, to data classification.

Both of these sets of protocols will come into effect in the coming period. The first articles of the new DFS regulations have been applicable since March 2017 with encryption requirements coming into effect by next January.   GDPR will become European law in May 2018.

And the new rules?

While the technicalities of these two documents differ, both broadly address similar issues.

The guidelines set forth rules on often neglected information security points.  Both require access privileges to data to be to be limited, and based on actual need. GDPR and DFS both lay down notification rules, requiring a company to report data breaches within 72 hours of the organization becoming aware of the incident.

Compliance is also big topic.

Both GDPR and DFS require regular submissions of compliance statements to the relevant authorities. This means that security officers of private organizations will be compelled to go over many aspects of company IT with a fine tooth comb to insure that the new rules are being implemented. For this reason these regulations have become a major concern for IT security officers, according to their own testimony.

But the real kicker:

The new regulations, both in their own way, require large scale encryption methods for company data.  GDPR for instance requires sensitive identification and personal details to be put through anonymisation and pseudonymisation. The DFS regulations go a step further requiring encryption for potentially compromising data both in transit and at rest.

Even GDPR is structured to strongly encourage broad encryption. Penalties and fines placed on a company for negligence resulting in a cyber-attack are based on the investment the organization places in security measures. And a solid encryption plan can get a company off the hook.

This will be the single biggest challenge to compliance with the new guidelines.

Broad or “blanket” encryption is a large scale effort for any organization and its effects can severely hinder company operations by affecting team collaboration, interfacing security protocols with existing systems, as well as requiring additional operations training.

The smart solution to encryption:

Data encryption may indeed be the most important factor in complying with both GDPR and DFS.   However, this move does not have to result in hobbling company operations and overburdening IT with encryption tasks and maintenance.

Content aware discovery, which uses proprietary machine learning and artificial intelligence tools to hone in on sensitive data, increases accuracy and, most importantly, efficiency in data encryption is the smart solution.      item_2015_icon_3

Visibility: Accurately, discover sensitive data; detect and address broken business process, or insider threats including sensitive data breach attempts.

Protection: Automate data protection, breach prevention and incident response both on and off the network; for example, find and quarantine sensitive data within files exposed on user workstations, FileShares and cloud storage.

Notification: Alert and educate users on violations to raise awareness and educate the end user about cybersecurity and corporate policies.

Education: Start target cyber-security training; e.g., identify end-users violating policies and train them.

  • Employees and organizations have knowledge and control of the information leaving the organization, where it is being sent, and where it is being preserved.
  • Ability to allow user classification to give them influence in how the data they produce is controlled, which increases protection and end-user adoption.
  • Control your data across your entire domain in one Central Management Dashboard with Universal policies.
  • Many levels of control together with the ability to warn end-users of possible non-compliant – risky activities, protecting from malicious insiders and human error.
  • Full data discovery collection detects sensitive data anywhere it is stored, and provides strong classification, watermarking, and other controls.
  • Delivers full technical controls on who can copy what data, to what devices, what can be printed, and/or watermarked.
  • Integrate with GRC workflows.
  • Reduce the risk of fines and non-compliance.
  • Protect intellectual property and corporate assets.
  • Ensure compliance within industry, regulatory, and corporate policy.
  • Ability to enforce boundaries and control what types of sensitive information can flow where.
  • Control data flow to third parties and between business units.