KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
In the spring of 2020, SolarWinds Orion, popular system monitoring and management software widely used by the U.S. government and thousands of private companies, was hacked and infiltrated with malware.
Later in the year, it was found that as a result of the hack, sensitive data was compromised within many enterprises including the Securities Exchange Commission (SEC), Pentagon, Department of Homeland Security, State Department, Department of Energy, National Nuclear Security Administration, Department of Justice, and the U.S. Treasury. Additionally, Fortune 500 companies, downstream of such agencies and their services, were also affected.
The widespread theft of intellectual property and personal information – affecting both individuals and businesses – is concerning. It warrants a heightened awareness, followed by action, to control the risk of future data compromises.
On January 28 we celebrated Data Privacy Day, an internationally recognized initiative focusing on raising awareness of the importance of protecting the privacy of personal data online. And it could not have come at a better time.
Also Read: PDPA Compliance Singapore: 10 Areas To Work On
Public and private networks are still recovering from the SolarWinds breach, along with a sustained legacy of cybersecurity breaches that put our data at risk.
Data Privacy Day was part of a global effort to build awareness about the importance of data, its privacy, and to encourage proactive planning to protect it. In the years ahead, this event will continue to serve the same purpose.
Sensitive data is everywhere. It can be found on our phones, in connected devices, and within a wide and deep array of data repositories found everywhere nowadays. Hacks and compromises are malignant and come from where you’d least expect, when you’d least expect them. An effective defense starts with a strong awareness of the criticality of your data and its privacy.
The prevalence of cybersecurity risk and the importance of strong data privacy protections are supported by an overwhelming sentiment from businesses and individuals alike. For example:
An important question then is how should we protect our data and adequately manage cybersecurity risk?
Adopting a privacy framework helps manage risk while creating a culture of privacy. There are several notable frameworks to consider. These include:
The CMMC program deserves spotlight consideration as it is new and noteworthy in the context of cybersecurity and the protection of intellectual property critical to national security.
The CMMC framework consists of five maturity levels – Level 1 through 5. Each level is a progression from basic cyber hygiene (level 1) up to an advanced level (level 5). CMMC sets formal standards for the maturity – the level of institutionalization – of cybersecurity practices within an organization. Under this framework, businesses that handle sensitive data cannot get by with ad hoc or ill-defined protections. They must formalize their practices such that effective protection is baked into their day-to-day operations.
The CMMC framework applies wide and deep to all contractors – prime contractors as well as subcontractors – who conduct business with the DoD. Contractors must attain at least the basic Level 1 certification. Previously firms could self-attest as to their cyber security compliance. Now contractors must achieve certification via a certified and independent third-party auditor prior to being awarded a defense contract.
This action by the DoD to raise the bar for all of their contractors is apropos in the wake of such events as the SolarWinds software hack. It calls attention to the importance of cybersecurity and data privacy.
Also Read: What Does A Data Protection Officer Do? 5 Main Things
All we learned by our reflections on Data Privacy Day, and the factoids above, these are important takeaways – not just for the present, but importantly for the future, as we march forward at a time when risks to our privacy are at the forefront of public discussion and concern.
Even beyond Data Privacy Day, enterprises and individuals must continuously reflect on their own blueprint of protection to safeguard data privacy. Such a blueprint is best built using established frameworks to safeguard data and networks and instill a culture where security is everyone’s job.
For hackers, when one door of vulnerability closes, another opens. Our data is always vulnerable to compromise. Safekeeping of data relies on our awareness and our proactive measures to manage and successfully control cybersecurity risk and ensure privacy.