Keeping up with the changes can be overwhelming for many organisations. Increasing number of cybersecurity tools required which need to be kept up to date, requires IT and Security Operations specialists to analyse the alerts and data from all the tools. Round the clock expertise is needed to stay ahead of today’s advanced attacks.
- Hiring and retaining cybersecurity experts is challenging
- Competitive market for skilled experts
- Can be expensive and a distraction from core business
Threats have evolved in a way that prevention technologies can no longer stop every attack on their own. While prevention is still vital, you also need human experts to help detect, investigate, and neutralize the most advanced attacks.
For businesses transacting in the UK, there are many regulations that apply when using an electronic device to communicate. The UK General Data Protection Regulation (UK GDPR), or the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) which sit alongside the Data Protection Act and the less obvious ones like the Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015, which lays out requirements for information that must me included in your communications.
- Guide to the UK General Data Protection Regulation (UK GDPR) | ICO Data Protection Act 2018 (legislation.gov.uk)
- Guide to Privacy and Electronic Communications Regulations | ICO The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2020 (legislation.gov.uk)
- The Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015 (legislation.gov.uk)
- and others....
These give people specific privacy rights and obligations in relation to electronic communications. Also be mindful of the provisions inside the companies act of directors duties, record keeping and disclosure. As an information owner, you're responsible for managing your organisation's security risks and fulfilling your lawful requirements with things like disclosure in business communications from the companies act (like having legal email signatures) and retaining of email records.
The UK ICO identify theses legal requirements as aligning to the Cyber Essentials Scheme. If you do business with EU organisations they may insist on compliance to NIS2 & DORA these have, security, compliance and criminal fines for non compliance.
Cyber Essentials certified organisations are 92% less likely to make a claim on their cyber insurance than those without it. https://www.gov.uk/government/publications/cyber-essentials-supply-chain-commitment-joint-statement/cyber-essentials-supply-chain-commitment-joint-statement