Targeted phishing emails and other online scams are increasing both in number and complexity. With the imminent arrival of the General Data Protection Regulation in May 2018, spotting the warning signs is more imperative than ever – and non-compliance is simply not an option.
Criminals are now attempting cyberattacks through many different channels – phone, email, social media and utilising Social engineering to complicate the defence of Cyber Crime.
Social engineering is the art of manipulating people so they give up confidential information. The types of information these criminals are seeking can vary, but when individuals are targeted the criminals are usually trying to trick you into giving them your passwords or bank information, or access your computer to secretly install malicious software–that will give them access to your passwords and bank information as well as giving them control over your computer.
Criminals use Social engineering tactics because it is usually easier to exploit your natural inclination to trust than it is to discover ways to hack your software. For example, it is much easier to fool someone into giving you their password than it is for you to try hacking their password.
Security is all about knowing who and what to trust. Knowing when, and when not to, to take a person at their word; when to trust that the person you are communicating with is indeed the person you think you are communicating with; when to trust that a website is or isn’t legitimate; when to trust that the person on the phone is or isn’t legitimate; when providing your information is or isn’t a good idea.
In order to ensure that your company remains within the legal parameters, make sure that whatever medium you are using to either store or transmit personal data – in particular, data relating to your clients – is secure and encrypted. Avoid free cloud-based systems like Dropbox or Google Drive to communicate with clients or receive confidential data. They are not secure or encrypted, and you are effectively in legal and often, regulatory breach by using them for client-related activity as their servers are based in the cloud and most likely in the United States. Services such as our own Insta Digital cloud which are fully encrypted and hosted on ISO27003 accredited servers here in the UK are essential for compliance.
Regulation is coming
There is an added imperative to take your data protection obligations seriously with the EU General Data Protection Regulation (GDPR) becoming law in the UK and across Europe in May 2018, which will continue to apply to all businesses exporting goods or services into the European Single Market, regardless of any future legal and regulatory settlement reached by the UK with the EU.
The GPDR has many major requirements. The biggest risk for law firms is the notification of a breach to the Information Commissioner’s Office (ICO) within 72 hours. The ICO will want to know:
- what systems and information has been compromised
- that your firm has isolated the cyber attack so that data is no longer being compromised
- worked out what personal data has been compromised and how
- what steps you are taking to
- how you will ensure it doesn’t happen again.
If firms have already not begun work on achieving compliance with the GPDR, they will find it impossible to achieve full compliance by May 2018. At this point, it’s a matter of working out how uncompliant you wish to be. You will have to cherry pick what you can and cannot afford to comply with, and put the rest in place as quickly as possible.
Contact Us Today for a no obligation chat about Data and Cyber Security








