24-hour breach notification 'unfeasible'

Powered by SC Magazine
 

EU Commission says victims to be notified one day after breaches.

The proposed European 24-hour breach notification law will further swamp an already over-worked British regulator.

The proposed changes would require that breaches should be notified of within 24 hours "where feasible".

“They need to know if it is workable, possible or deliverable as every case must be feasible," Field Fisher Waterhouse Stewart Room said.

“They have created a new regime that says you should report within 24 hours, regardless of what it will achieve. The regulator is already swamped with disclosures and this will see even more.”

The changes were detailed in January by Viviane Reding, vice-president of the European Commission in charge of justice, fundamental rights and citizenship.

Reding said the "scandal" of data breaches would be removed with victims "informed as soon as possible, within 24 hours on major breaches", although she failed to declare how a major breach would be determined.

Room revealed last year that public and private sector businesses would be hit by mandatory-disclosure legislation as a result of the changes to the Data Protection Directive.

Research from LogRhythm published in April found that of 200 IT decision-makers at UK businesses, 87 per cent would be unable to identify individuals affected by a breach within 24 hours, while 13 per cent said it would take them between one week and a month to pinpoint which customer data was affected. Six per cent did not believe they would ever be able to accurately obtain this information.

Speaking to SC Magazine, Ross Brewer, vice-president and managing director for international markets at LogRhythm, said the research showed that security in organisations was in a "woeful state of affairs".

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


24-hour breach notification 'unfeasible'
 
 
 
Top Stories
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1788

Vote
Do you support the abolition of the Office of the Information Commissioner?