Cybersecurity failings are rife amongst UK SMEs

UK-based SMEs are not doing enough to ensure the data they hold is secure, it has been reported.

Findings from a newly-published report show that more than two out of three SMEs considered that there was room for improvement in protecting their business data, while four out of 10 questioned said they did not have a cybersecurity policy in place.

The figures were published with just six months remaining until the General Data Protection Regulation (GDPR) comes into force in May 2018.

GDPR sets tough new standards for organisations’ data protection procedures, with steep penalties for those found to be non-compliant or guilty of a breach.

A key requirement of GDPR is that businesses which hold sensitive data on a large scale will need to appoint a data protection officer. At the moment, just 84 per cent of businesses questioned said they had a dedicated employee responsible for IT and cybersecurity.

Individuals will receive a number of new rights under the GDPR – which will also strengthen some of the existing rights offered under the Data Protection Act.

According to the Information Commissioner’s Office (ICO), once the new legislation takes effect, individuals will have the following rights:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling

Whilst many of the principles from the DPA will remain, the GDPR will bring with it several new concepts and approaches, which have been described as a “game changer for everyone”.

Businesses in particular will be adversely affected – as many will need to implement organisation-wide changes to ensure that any personal data is processed in compliance with the GDPR’s requirements.

One notable change is that companies that currently rely on ‘consent’ as a legal basis for processing personal data will need to assess the consents that they currently hold and the mechanisms through which such consents are provided in future. This is because ‘implied consent’ will no longer be deemed valid under the GDPR.

It is crucially important that businesses ensure they are fully compliant with the new regime, as enforcement powers will also increase under the GDPR – meaning that non-compliance may result in harsher ICO investigations than was previously the case.

The ICO has published full guidance to the GDPR on its website here.

Link: Overview of the GDPR

Link: UK SMEs are negligent – and complacent – when it comes to cybersecurity

Loading Quotes...

Latest News

10
Jun
Be prepared for changes to VAT penalties and VAT interest charges

Changes to charges and penalties applied to late submission of VAT returns will …
Read more…


10
Jun
Penalties for misuse of Coronavirus Job Retention Scheme

New legislation allows HM Revenue & Customs (HMRC) to recover Coronavirus …
Read more…


Don’t pay more tax
than you need to

Register for our newswire

Our regular Newswire mailings are designed to keep you up to date with the latest industry news and events.

Register here

Client Login
Complete our Client
Satisfaction Survey

Spring Statement 2022

Exactly two years since the first lockdown was announced, the eyes of the public were firmly...

Read full our summary