enterprisesecuritymag

| | NOVEMBER 2022ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONBy Dimitar Mutafchiev, Data Protection Officer/Head of Data Protection Section, DSK BankIn the foreseeable future, it is more likely than not, for the management of business activity, that relies on processing relatively large amounts of data and/or information ­ personal or otherwise protected - to find itself in a situation to deal with a full-scale data related crisis. This is realistic evaluation of the facts and logical conclusion from data driven trends for business development from the past two decades, rather than a pessimistic view of the world. So - what can we do to address this?Well ­ if you have asked yourself that question for the first time now and you are not in charge of a data processing related company, that has been established last week ­ you are probably going to have pretty unpleasant experience both short and long term. In the past 10 years, managers around the globe had plenty of opportunities to conclude that the situation that we are now in is coming for sure ­ boom in data collection and processing across the board, regulatory changes aimed to address that by enhancing security and data protection by implementing more stringent rules to comply with, rapid and sustainable long-term increase in cyber-attacks related risks, several high-profile cases of cyber-attacks in different sectors, which resulted in multimillion loses and deterioration of consumer trust. So, let's explore the world in which managers saw the signs and took actions. BASE LINE The basic design, around which the overall data breach incident response philosophy should be built, is the idea that crisis, by definition, happens as a surprise. So lengthy and heavy procedures and complicated decision-making algorithms are not a good idea. It is better to purposefully increase the level of management and employee awareness and understanding on topics such as information security, data protection and regulatory framework, in which the company operates. his can be achieved through advanced training programs and continuous communication that this is a priority. My opinion is that you need an initial response action list that can fit into one page and with enough flexibility to account the variables. It is also critical to identify the people, who have the talent and knowledge to manage the crisis, and include them into first responders' team. A few examples, that need to be predefined, that I consider rudimental for successful crisis management ­ clear and fast reporting lines so the people that need to know ­ knows; small knowledgeable and talented management team that is capable to draft initial action plan in short notice and have the authority to execute it; introduce communication tools so everyone in the team receives prompt information updates and are in line with overall development; keep the action plan simple and focused on the immediate threat; begin investigating the DATABREACHMANAGEMENTDimitar Mutafchiev
< Page 7 | Page 9 >