Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Leadership and ManagementCybersecurity News

Compliance and Congress – How to Build an Effective Cyber Strategy

By Dhaval Jadav, Chuck Wilson
cyber-pro
February 7, 2019

The growing threat of cyberattacks is a huge cause for concern. According to some of the country’s foremost intelligence experts, the U.S. may encounter a massive cyberattack on the horizon. An attack of this scale is predicted to cause damage comparable to a Category 5 hurricane, where everything from vehicles to pacemakers could be compromised. The country needs to be ready – and not just the public sector. Private businesses, regardless of size, would be taking an extreme risk if the necessary precautions are not put into place.

The literal and perceptional damage caused by security breaches can be astronomic, as we have seen from high-profile leaks at Sony, Equifax and Yahoo. When developing a strategy, you have to be able to properly assess the amount of overall damage that your business could suffer.

With new legislation such as the California Consumer Privacy Act (CCPA), or AB 375 (which is similar to the European General Data Protection Regulations, or GDPR) going into effect in 2020, businesses of all sizes are working to maintain compliance and avoid security leaks at all costs.

 

Building A Strategy

When developing a cybersecurity strategy, there are a few important questions to consider:

  1. How difficult is it to gain access to my company or customer information?
  2. How much actual damage to my customers, company and/or public reputation can be caused if a data breach occurs?
  3. Are we following best practices for protecting client data that we have been given access to?
  4. Do we have an enterprise risk management approach? How do we prioritize risks?
  5. Do we have an incident response plan in place if a breach was discovered?

 

For example, if your company has very strong network and firewall protocols that adequately deter cyberattacks, but also has access to sensitive and potentially damaging customer information – you are only implementing a half-measure.

The overall risk that your company is facing is directly correlated to the amount of damage that a potential attacker can inflict with your customers’ data, as well as the public image of your company due to negligence, noncompliance or plain bad luck. In fact, the perception of an insecure network or known negligence toward securing customer data can do as much, if not more, irreparable damage to a company or brand than an actual security breach.

What many small to medium-sized businesses underestimate is the amount of information that they actually have from customers, and how the push to cloud-computing is only adding to the complexity of properly securing sensitive information. The more companies utilize cloud-based services to record transactions, financial data, personal preferences, search histories and medical records, the more devastating a security breach can be.

 

Getting Compliant

A single leak can bring down even the largest and most powerful of companies. Once the trust of the customer is lost it is exponentially more difficult to regain it. With this in mind, companies of all sizes need to take the necessary steps to not only be compliant with legislation, but also be proactive in developing systems that can defend themselves from claims of negligence. Being compliant does not always equate to having a defendable due diligence security posture.

Small businesses are going to be among the hardest hit by regulations such as GDPR and CCPA becoming more commonplace, and I fear that noncompliance due to lack of resources could be a serious issue. When having an online presence and customer database is essentially required for any business today, many smaller operations do not have the available resources to become compliant, or may not even identify that their business would require changes due to new regulations.

So, what options does an organization have if they are not already preparing a cybersecurity strategy or do not have an in-house team? Quite a few, actually. These options start with asking the aforementioned questions, and then by asking the following to determine which parts of the system or processes need the most attention:

  • Are the security risks being quantified? Is there a network security issue?
  • What type of information is being transmitted or collected? Is data classification used?
  • What is your encryption policy? How encrypted, if at all, is the stored data?
  • Do all of your employees with access to client data know your cyber-protection practices? With this question it is important to note that phishing is the largest threat vector, accounting for around 95% of all security incidents.
  • Are those security basics in place?
  • How well is “cyber-hygiene” managed?

 

All of these questions can be answered by cybersecurity experts who help determine the level of attention required for each aspect of a compliant cybersecurity strategy. One size does not fit all in the world of cybersecurity. Determining potential vulnerabilities is different for every operation, and will vary in complexity based on the type and quantity of information that is associated with the business.

In addition to professional assistance, there are a few best practices that a company can implement to improve their privacy policy, as well as customer and visitor notification policies.

 

Being transparent when using cookies on your website.

Have a consent statement “pop-up” on your website explaining not only that your website uses cookies, but how your organization is using that information. The statement needs to notify the visitor that your website uses cookies, how to change their settings to deactivate them and explicitly say what the cookies are used for. A great resource for creating a consent statement can be found here.

 

How you are monitoring visitor behavior.

In the same vein as the cookies notification, simply stating that you collect personal data is no longer adequate. Within your privacy policy you have to let your users know exactly what data you collect and process.

 

Notification of the sharing (but never selling) of your customer data. 

Notifying a web user of data sharing is typically seen when a company has user data that is then shared with a third-party partner. For instance, an organization that collects user or member data may then share it with “authorized partners” that facilitate a better experience for the users. Having this stated in a privacy policy and consent statement, along with acknowledging the compliancy of all “authorized partners,” is highly recommended.

 

Regardless of industry, size or revenue, a cyber strategy is absolutely required because the more interconnected everything becomes, the more vulnerable we become to cyberattacks. With increased vulnerability comes more regulations. Businesses and organizations will need all the help they can get to ensure data security and compliance with future regulations.

 

This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security magazine. Subscribe here.

 

KEYWORDS: cyber risk management cybersecurity strategy data breach data privacy GDPR security compliance small and medium business (SMB) security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dhaval Jadav is the Chief Executive Officer at alliantgroup, America’s leading provider of tax credits and incentives to U.S. businesses. Jadav co-founded alliantgroup in 2002, and since its inception, his passion to serve businesses and the CPA firms that advise them has resulted in alliantgroup helping U.S. businesses claim more than $7 billion in tax credits and incentives.
Chuck Wilson is the Executive Director of the National Systems Contractors (NSCA) and he has served in this capacity since 1996. Before being named executive director of NSCA, he served on the organization’s Board of Directors from 1988-1995. NSCA is a not-for-profit association representing the commercial low-voltage electronic systems industry, including systems contractors/integrators, product manufacturers, consultants, sales representatives, architects, specifying engineers and other allied professionals.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Security Enterprise Services
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Technologies & Solutions
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

July 17, 2025

Tech in the Jungle: Leveraging Surveillance, Access Control, and Technology in Unique Environments

From animal habitats to bustling crowds of visitors, a zoo is a one-of-a-kind environment for deploying modern security technologies.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • spartan-cyber

    5 Basic Rules to Build an Effective Security Awareness Program

    See More
  • George Gerchow podcast

    Listen to George Gerchow, CSO at Sumo Logic, discuss how to build a seamless cybersecurity strategy

    See More
  • 5mw Anderson

    5 minutes with Heath Anderson - Building an effective governance, risk management and compliance program

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!