GDPR is Here, So What’s Next for Cybersecurity Professionals?

Today marks the implementation of the EU’s General Data Protection Regulation (GDPR). Two years of educating, planning and preparing, not to mention significant investment, to meet compliance requirements has led to this moment.
It’s a new era for data protection in Europe and beyond: extensive rights for citizens and responsibilities for organizations aimed at improving privacy and mitigating the risk of cyber-attacks and data breaches. Yet, with this slated ‘gold standard’ of protection now in place, what comes next for cybersecurity professionals, particularly for the CISO who has been leading efforts to be compliant from a security standpoint?
The work for GDPR has just begun Now that the implementation date has arrived, it would be simple for CISOs and cybersecurity professionals to see GDPR as job done. Yet the task to comply with GDPR does not finish today. Cybersecurity professionals will play an intrinsic role to ensure compliance is maintained long term.
For example, cyber professionals will always be monitoring for any abuse, illegal access or breaches and then working with the legal team and Data Protection Officer to report it to DPAs (or publicly if needed) should one occur.
In addition, while Fortune 500 firms have invested a combined $7.8bn in preparing for the regulation, the majority of organizations are still working towards being fully compliant. Our research launched last weekfound that 85% of companies are not ready for the legislation, with one in four unlikely to be fully compliant this year.
For CISOs of firms that aren’t compliant the ‘what next’ is more of the same, but with increased urgency: leading their organization to build their “privacy by design” and “secure by default” processes while balancing prevent/protect and detect/response capabilities.
Additional legislation While Europe’s attention has been heavily focused on GDPR, there are other regulations which CISOs and cybersecurity professionals must manage. Most notably is the Networks and Information Security (NIS) Directive, which aims to improve the EU’s preparedness for cyber-attacks, particularly on critical infrastructure such as energy, utilities, finance, healthcare, digital infrastructure and transport. This regulation means that CISOs operating in these industries and the public sector will have to implement high defenses against cyber-attacks.
While GDPR focuses on personal data, this regulation is about system-level infrastructure, and so will be a great challenge for the relevant CISOs. We may also envisage the trends around AI and IoT as big issues to handle in a near future.


