8 Steps to Prevent Data Breaches

It’s always extremely painful for an organization when confidential data is exposed. Now that the General Data Protection Regulation (GDPR) has been in effect since May 25, 2018, and the obligation to report data breaches applies, organizations run the risk of being fined heavily if they fail to comply with this reporting requirement. That’s reason enough to take robust measures to prevent data breaches. In this article, you’ll learn more about the steps you can take to prevent data breaches, and we’ll provide practical tips. We’ll also discuss the risk of data breaches caused by malware and what you can do to protect against them.
Data Breach
The GDPR requires organizations that use personal data to ensure that this data is properly secured. This means that both companies and government agencies must take measures to keep the data secure.
Data Breach Reporting Requirement
The fines that the Dutch Data Protection Authority can impose for data breaches (or the unlawful processing of personal data) are severe. The Authority can impose a fine of up to 20 million euros or 4% of global annual revenue on organizations that violate the GDPR.
Avoid a fine!
By taking the right measures, you aim to prevent a data breach. But no matter how many steps you take, it is not possible to reduce the risk to zero. If your organization does experience a data breach, the Dutch Data Protection Authority will assess the breach by evaluating what the organization has done to protect personal data. The fine will be lower—or in some cases may even be waived—if the organization can demonstrate that it has taken appropriate measures to prevent data breaches.
Technological and Organizational
According to the Dutch Data Protection Authority, organizations must take two types of measures to prevent data breaches. On the one hand, they must use technology to prevent breaches; on the other hand, it is also important for organizations to handle personal data responsibly. Here are a number of technological and organizational tips to help you prevent data breaches.
Measures to Prevent a Data Breach
1. Appoint a data protection officer (DPO)
The Data Protection Officer is the person responsible within the organization for policies regarding the protection of personal data. He or she oversees the implementation of and compliance with the General Data Protection Regulation (GDPR). It is advisable for every organization to appoint a DPO, but under the GDPR, this is mandatory in three situations. Appointing a DPO is mandatory for public organizations, organizations that monitor people on a large scale (such as through video surveillance), and organizations that frequently process special categories of personal data.
2. Map out data flows
Make sure you know where personal data is located within the organization and the paths the data takes. This will help you identify the processes in which personal data is processed and, consequently, where the risk of a data breach lies. Don’t forget to include paper records as well. In addition, you can create a processing register to provide a clear overview of all processing activities.
3. Use encryption
By storing and sharing data in encrypted form, you reduce the risk of a data breach and minimize the impact of any potential breach. Encrypted messages can only be read and edited by people who have the correct key. Encryption can ensure that data remains secure even if a data breach occurs.
4. Do not collect unnecessary data
Data that is not required to be retained according to the retention period and is of no use to the organization should be destroyed. This sounds logical, but in practice, organizations tend to retain enormous amounts of data that they no longer need for any purpose. The less data you retain, the lower the risk of a data breach.
5. Ensure strong digital security
Use technical solutions to protect personal data. For example, implement a robust firewall, secure your wireless network, ensure passwords meet certain requirements, use facial recognition (identity management), and choose security software that is always up to date. This provides protection against the malicious intentions of cybercriminals and malware (including ransomware). Read more later in this article about the dangers of ransomware and how to prevent an infection.
6. Be careful with (cloud) storage outside the EU
In the United States, privacy laws are much less stringent than in the European Union. Since the United States is outside the European Union and is therefore not subject to the GDPR, the transfer of personal data is subject to stricter requirements. The transfer of personal data to the United States is permitted provided that appropriate safeguards are put in place to ensure protection.
7. Focus on the weakest link: the employee
Data breaches are often caused by employees. Although malicious intent may be a factor, this is usually not the case. Breaches often occur because employees use public cloud services such as Dropbox. They also sometimes leave USB drives lying around, share unsecured but privacy-sensitive documents, or click on attachments in suspicious emails. By making employees aware of the privacy policy and helping them handle confidential data properly, many data breaches can be prevented.
Protect the organization against ransomware
Ransomware is also known as “hostage software.” Cybercriminals use ransomware as a means of blackmail. If your computer is infected with ransomware, you will no longer have access to your data. Cybercriminals demand money to unlock the computer and restore access to the data. In practice, paying the ransom doesn’t always guarantee that you’ll regain access to your data. It’s also possible that the entire corporate network has been held hostage. As an organization, you naturally want to do everything you can to prevent a ransomware infection. A ransomware attack is also subject to the mandatory data breach reporting requirement.
There are several measures your organization can take to reduce the risk of a ransomware (and other malware) infection. For example, it’s important to ensure that software on devices is always up to date. It also helps to keep the organization’s various computer systems and networks separate and to avoid using outdated network protocols.
So, are we going to start making the workplace safer today?
We're ready when you are. Brainstorm with us. Create with us. Discover with us. We're your full-service IT partner. Let's have a conversation.