EU fines for data breach fail to safeguard against breaches: IM

A year after the publication of the European Commission's draft revision to data protection legislation, which includes fines of up to one million Euros or two per cent of annual revenue for a data breach, penalties appear to be having had little effect on most firms' approach to information security, according to Iron Mountain.

It reckons that for the majority of companies, the threat of fines has little impact on their company’s data protection policies to protect sensitive information.

That said, the majority of firms are either already insuring or are looking at insuring their business against the financial impact of a data breach. Comments Christian Toon, head of information risk at Iron Mountain Europe: “Businesses of all sizes are failing to take appropriate steps to protect information. It seems many would rather insure against the cost of a breach than take steps to prevent it.”

PwC and Iron Mountain have launched an online tool to help businesses assess their exposure to information risk. The tool allows businesses to assess where they sit on an information risk maturity index, which represents a balanced approach to preventing information risk, including measures that evaluate strategy, people, communications and security. Their index is based on a set of indicators that, if put in place and frequently monitored, will help protect the digital and paper information held by an organisation.

Businesses can assess their exposure to information risk online at http://www.ironmountain.co.uk/risk-assessment

    Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.