Strong security defense starts with prioritizing, limiting data collection

2 min read

Dow Jones, parent of The Wall Street Journal, is among the latest companys to expose highly sensitive data, including the identities of global government officials, politicians and political influencers, on the public cloud. This high-profile breach was alarming for many reasons, the largest of which is that the authorized third party responsible for instigating the breach shouldn’t have had direct access to the 2.4 million records that were unnecessarily stored in a centralized database.

Companies that require access to, or answers from, sensitive personal data have a responsibility to install strict access controls. Leveraging technology that can carefully limit corporate access to the individual records that an authorized party needs ensures that information never has to be stored all in one place.

Organizations such as Dow Jones that store and manage large volumes of data in centralized database are presented with an inherent vulnerability, putting the company at risk when a breach of this magnitude occurs.

As cybercrime, user fraud and other security threats become more prevalent and detrimental, the ability to confidently know who you’re dealing with online has become ubiquitous, but what most companies tend to overlook is the responsibility and liability that they automatically assume when they collect and store personal data in order to validate their constituents. As a result, some businesses hold large volumes of personal data because they believe it’s necessary for comprehensive identity and credential verification, but this practice can be risky, especially for companies with weak or limited data protection protocols in place.

Data breaches have costly repercussions, including loss of customers, compromised intellectual property, loss of brand trust and, of course, meaningful revenue declines that result, but regulatory penalties can be the most expensive of all consequences.

For example, violating GDPR’s strict rules around data privacy can warrant fines of up to €20M, or 4 percent of the worldwide annual revenue of a company. The introduction of this EU law in May 2018 prompted some U.S.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at information-management.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.