The impact of mandatory breach notifications on UK plc
What do the latest EU plans mean for the UK and will it make the European enterprise a safer place?


The argument being that the enterprise will learn from any mistakes post-breach regardless of whether the public are aware of that breach or not. My response was that if the media does discover a 'hidden breach' and there is every chance that it would, then the reputational damage would be far worse than just adopting a transparent attitude and admitting the fact up front. As for the impact upon practical data security implementation, surely logic dictates that if you know that a breach must be disclosed you will not only be more vigilant to prevent it (and that translates to being more likely to allocate sufficient budget in times of recession) but more responsive to change following any incident.
I'm therefore 100 per cent behind Brewer when he says that "no organisation should wait for new legislation to obligate them into maintaining a transparent IT security strategy" as you might imagine.
Not everyone within the IT security industry is so supportive of the new EU proposal. A good example here would be Jarno Limnell, director of cyber security at Stonesoft who puts forward an argument that increasing the regulatory and legal requirement isn't necessarily the best way to mitigate risk. "The rules proposed by the European Union reflect the misunderstanding that currently prevails in Europe, namely that everything, in this case cyber threats, can be solved by creating more statutes, directives and restrictions," Limnell insists.
"This is neither the right nor the most efficient way to improve European cyber security," he adds. What Limnell suggests as an alternative, is for another of the EU proposals to take centre stage, namely that every European state has its own CERT.
"What is needed is for each European country to have an authoritative cyber agency, such as CERT, with very skilled personnel, who take cyber security threats and challenges seriously," Limnell says.
He adds that from a constitutional perspective the same agency should become both investigative and punitive in its role. I don't disagree on the CERT issue. Indeed, collaboration and information -sharing is key to fighting cyber crime as anyone involved with law enforcement or security research will readily admit. Limnell's argument is that breach reporting can be done discreetly, in private if you like, with all the necessary data being shared between the various national CERTs and the end result will be the same: improved security and an improved chance of catching the bad guys.
This is where we must agree to differ I fear, as suggesting that by making a company feel 'safe' that it's brand will not be damaged by disclosure will be more encouragement for it to come forward than the risk of a big fine and ultimate public disclosure anyway (assuming that some kind of annual security auditing was required to regulate the process in the first place) makes little sense to me.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Yes, there has to be situational awareness regarding the cyber threat, but I'm not convinced that this will only come if reporting remains private. After all, ask yourself this: how many companies are volunteering their breach data to the authorities today?
Pan-European regulation seems to be the only way forward. This would put all countries and all companies on an even footing and provide an opportunity for more secure business practises across the board. Cyber crime doesn't recognise borders so why should cyber crime regulation? Importantly, and I really do think this is the overriding factor here, enterprises will be seen to be putting their houses in order and that equates to increased consumer trust.
Ultimately, data security is not just an IT issue but an integral business concern that should be at the very heart of every organisation with full board-level support. The proposed pan-European mandatory breach notifications, along with the requirement to share information between nation state CERTs, seems best placed to ensure this becomes the case.
Davey is a three-decade veteran technology journalist specialising in cybersecurity and privacy matters and has been a Contributing Editor at PC Pro magazine since the first issue was published in 1994. He's also a Senior Contributor at Forbes, and co-founder of the Forbes Straight Talking Cyber video project that won the ‘Most Educational Content’ category at the 2021 European Cybersecurity Blogger Awards.
Davey has also picked up many other awards over the years, including the Security Serious ‘Cyber Writer of the Year’ title in 2020. As well as being the only three-time winner of the BT Security Journalist of the Year award (2006, 2008, 2010) Davey was also named BT Technology Journalist of the Year in 1996 for a forward-looking feature in PC Pro Magazine called ‘Threats to the Internet.’ In 2011 he was honoured with the Enigma Award for a lifetime contribution to IT security journalism which, thankfully, didn’t end his ongoing contributions - or his life for that matter.
You can follow Davey on Twitter @happygeek, or email him at davey@happygeek.com.
-
Forcing Apple to allow alternative app stores might cause major security risks
Analysis Apple will be forced to allow third-party marketplaces on its devices, but some experts have raised serious security concerns
By Solomon Klappholz
-
Why bolstering your security capabilities is critical ahead of NIS2
NIS2 regulations will bolster cyber resilience in key industries as well as improving multi-agency responses to data breaches
By ITPro
-
New EU vulnerability disclosure rules deemed an "unnecessary risk"
News The vulnerability disclosure rules in the Cyber Resilience Act could also cause a “chilling effect” on security researchers
By Ross Kelly
-
Are you ready for NIS2?
WEBINAR Find out what you should be doing to prepare for the EU’s latest data protection regulation and UK equivalent with our free webinar
By ITPro
-
EU regulators are digging their heels in despite big tech’s Data Act pushback
Analysis EU regulators are no strangers to big tech regulatory push back, so why do companies still persist?
By Ross Kelly
-
Microsoft's EU Data Boundary will begin staggered rollout in January 2023
News Public sector and commercial customers will be the first to benefit when the rollout begins on 1 January across all of Microsoft's core services
By Ross Kelly
-
EU watchdog fights against rules permitting Europol's ‘unlawful’ data practices
News The pushback follows allegations that Europol was allowed to write its own rules when it came to handling sensitive data
By Connor Jones
-
EU to introduce strict IoT security regulation
News Manufacturers will be required to assess all risks, and notify the EU of issues within 24hrs
By Rory Bathgate