general data protection regulation for sme kurt … · 2018. 6. 27. · • blockchain developer...

24
GENERAL DATA PROTECTION REGULATION FOR SME KURT CALLEWAERT BRUSSELS 21/06/2018

Upload: others

Post on 20-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

GENERAL DATA PROTECTION REGULATION FOR SME

KURT CALLEWAERT

BRUSSELS 21/06/2018

Page 2: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

WHO

Kurt Callewaert

[email protected] 0473 340465

• Lecturer Applied Computer Sciences

• Research manager

• Computer & Cyber Crime Professional

• Blockchain Developer & Architect

• Postgraduate DPO

Page 3: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

Enterprises turnover from e-commerceby country

http://ec.europa.eu/eurostat/statistics-explained/index.php/E-commerce_statistics

B2C = on average 35%

Page 4: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt
Page 5: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

GDPR survey of 660 European CIO’s

https://www.ontrackdatarecovery.nl/nieuws/datavernietiging-europese-privacyregels/

Page 6: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

• 25 May 2018• Extra-territorial reach• Core principles:

• Lawfulness, fairness, transparancy Accuracy• Purpose limitation Retention• Data minimisation Integrity and confidentiality

• Consent• Data subject rights

• Right to be forgotten Right to data portability• Right to object to direct marketing Subject access requests• Profiling and automated decision making

• Privacy notices• Accountability• Data protection officer• Data security• Processors• Transfers outside the Union• Sanctions

GDPR in one slide

Page 7: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

SME’s and security policy?

Page 8: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

http://ec.europa.eu/eurostat/statistics-explained/index.php/ICT_security_in_enterprises

Enterprises with a security policy

Page 9: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

Enterprises with a security policyby country

Page 10: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

European survey on SME policy

http://ec.europa.eu/eurostat/statistics-explained/index.php/ICT_security_in_enterprises

Page 11: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

ISO survey of 27001 certifications11

ISO 27001 certifications

United Kingdom RomaniaItaly GermanySpain NetherlandsPoland Czech RepublicHungary BulgariaTurkey SlovakiaFrance SerbiaIreland GreeceSwitzerland AustriaSweden PortugalCroatia Russian FederationBelgium SloveniaNorway FinlandLithuania DenmarkIceland LatviaAlbania ArmeniaBosnia and Herzegovina CyprusThe Former Yugoslav Republic of Macedonia Ukraine

Page 12: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

WHY SHOULD THE SME ACT?

• Compliancy with GDPR (sensitive personal data)

• Company reputation damage

• Continuity

• Competition

innovative creative entrepreneurial

Page 13: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

• Accountant

• Customer / contractor

• IT supplier

• Bank

• Assurance

• Professional association

innovative creative entrepreneurial

WHO IS THE SME’S TRUSTED ADVISOR?

Page 14: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

OUR ADVICE TO THE SME: SET UP AN ISMS

INFORMATION SECURITY MANAGEMENT SYSTEM

Page 15: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

CYBERSECURITY AUDIT PROGRAM NIST CSF

Page 16: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovatief creatief ondernemend

ACCESS CONTROL

Page 17: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

PRACTICAL SOLUTIONS: SECURE CLOUD STORAGE

1. Usable security2. Private cloud storage3. Possibility to integrate with server-side encryption or client-

side encryption4. Multi-version backup

Page 18: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

PRACTICAL SOLUTIONS: SECURE MAIL

1. Usable security2. Most of the encrypted email solutions are not usable3. PGP, S/MIME4. Usability studies show this

1. 1999: Why Johny can’t encrypt

2. 2006: Why Johny still can’t encrypt

3. 2013: Confused Johny

4. 2015: Why Johny still, still can’t encrypt5. Other protocols / tools

Page 19: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

PRACTICAL SOLUTIONS: DEVICE ENCRYPTION

1. Use the standard tools for your OS for laptops2. Be careful: encryption should not be “security theatre”

Page 20: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

PRACTICAL SOLUTIONS: DATABASE ENCRYPTION

1. Very DBMS and version dependent2. Very dependent on your clients and specific architecture3. An ERP system comes with a database that you cannot control

yourself4. Threat model ? Who do you trust or not ?5. If any client can send SQL (or web services) to the server, what

is the point of encrypting the database content ?

Page 21: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

PRACTICAL SOLUTIONS: NETWORK ENCRYPTION

1. Choose the correct protocols2. Network segmentation (IoT)3. VPN

Page 22: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

PRACTICAL SOLUTIONS: MONITORING IDS/IPS

1. Monitoring is key for good security2. Monitoring as a service to SME’s3. Host intrusion detection, network intrusion detection4. Monitoring all the security tools: firewall, antispam, web

filtering, email filtering, host agents (HIDS),

Page 23: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

AWARENESS TRAINING

* Phishing* Social Engineering* Strong Passwords

Page 24: GENERAL DATA PROTECTION REGULATION FOR SME KURT … · 2018. 6. 27. · • Blockchain Developer & Architect ... 3. 2013: Confused Johny 4. 2015: Why Johny still, still can’t encrypt

innovative creative entrepreneurial

ISMS4SME IMPROVEMENT