Data protection knowledge expands through experience

Pro

31 January 2012

The 2012 data protection survey carried out by the Irish Computer Society has found that more than two thirds of respondents reported an increased knowledge of data protection requirements "through first-hand experience of data breaches rather than training and policy/procedures."

The survey also revealed that over the last 12 months, nearly half of respondents reported that their companies had experienced a data breach. Of these breaches, 58% were caused by a staff member, proportionally more a result of internal failure and lack of awareness, rather than from external data theft.

Some 34% of respondents rated their companies as placing too low a priority on data protection, while 28% believed that the greatest threat to an organisation’s assets came from negligent employees. A worrying 33% claimed that they did not know whether their company had a formal data protection policy.

 

advertisement



 

The ICS Data Protection Survey 2012 examined awareness of data protection and instances of data breaches among Irish companies. The survey involved over 300 IT administration and management staff, revealing an increased knowledge in Irish businesses of data protection requirements and data security issues and was carried out advance of its annual Data Protection conference on Thursday, 9 February 2012.

"Employees might appreciate the importance of data security, but organisations need to instil a culture of compliant data management," said Hugh Jones, professional services consultant, ICS. "Clear policies and procedures are vital, with regular refresher training and timely reviews to ensure that staff are complying with the structures. It is as much a case of protecting the organisation’s commercial reputation, as it is of protecting the individual’s privacy".

Nearly half of those surveyed said that they felt they had not received adequate data protection training, with some reporting that they had received none at all. While only 3% believed that more punitive penalties should be put in place for breaches of data protection legislation, over half of respondents expressed a belief that formal training and awareness programmes should be conducted on a regular basis to educate the end-user about data protection best practice.

To address this issue, new legislation passed in late January, and scheduled to take effect by 2014 will require medium and large companies to implement a formalised data protection training programme and appoint a designated data protection officer.

TechCentral Reporters

Read More:


Back to Top ↑