Faster-than-expected cloud adoption has upped the ante for protection of sensitive data

3 min read
Curated from cso.com.au →

Three weeks out from GDPR, businesses are still shoving sensitive data into the cloud without necessarily having appropriate security

Massive cloud-based companies may be tweaking their data governance to minimise exposure to the EU general data protection regulation (GDPR), but surging use of public-cloud services for storing sensitive data reaffirms the importance of data audit and triage as the clock ticks towards GDPR’s May 25 implementation deadline.

Despite suggestions that many executives regret hasty cloud investments, revenues for public cloud providers will outpace expectations to grow 21.4 percent this year alone, according to recent Gartner modelling that suggested those revenues would be led by continuing growth in the software as a service (SaaS) market – which will, Gartner predicts, reach 45 percent of all application software spending by 2021.

“In many areas, SaaS has become the preferred delivery model,” Gartner research director Sid Nag said in a statement. “SaaS users are increasingly demanding more purpose-built offerings engineered to deliver specific business outcomes.”

One of those outcomes will be improved governance, particularly with GDPR set to come into effect worldwide just over three weeks from now. That legislation puts onerous restrictions on any organisation handling sensitive data about EU citizens – which should, if the results of a recent McAfee study are anything to go by, strike fear into the hearts of risk managers everywhere.

McAfee’s 2018 Cloud Security report flagged the growing need for compliance efforts – particularly pressing since all but 16 percent of the 1400 surveyed respondents admit that they store sensitive data in the cloud.

Australian companies were somewhat less likely to trust the public cloud with their sensitive data, with 20 percent saying they store no sensitive data in the cloud and just 21 percent storing all of it in the cloud.

US companies were the most enthusiastic users of cloud services for sensitive data – 33 percent said they did so – while German and UK companies were the most conservative, with 25 percent of respondents saying they stored no sensitive data in the cloud.

Some 61 percent of respondents said they kept personal customer information in cloud services, while 42 percent stored payment card information; 41 percent, internal documentation; 41 percent, personal staff information such as bank details; and 37 percent, government identification information.

McAfee’s analysis of its findings linked compliance investments with the looming requirements of GDPR, noting that organisations “that are more confident in the ability of their cloud providers are more likely to have plans to increase their overall cloud investments in the coming year, while those less confident plan to keep their investments at the current level.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at cso.com.au →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.