Lack of regs, complacency why Canada lags in security: Vendor
From: IT World Canada
By: Howard Solomon
In this contributed opinion piece, an official of a security supplier says Canadians have to take security more seriously
Canadian organizations need to start taking cyber security seriously to protect their customers’ data and to avoid costly breaches. This includes following the Payment Card Industry Data Security Standard, a mandate for organizations designed to protect cardholder data from fraud, and implementing a cyber-security strategy that protects data loss and prevents targeted cyber-attacks.
The report also revealed that victims on average took 210 days to realize their systems were attacked leaving plenty of time for cybercriminals to collect their loot before anyone even noticed.
So, how can Canadian organizations protect themselves from becoming the next victim?
First, the perception by executives and our political leaders needs to change. Currently, Canada lacks regulations making it mandatory to disclose breaches, which contributes to the perception by executives of many Canadian companies that they are not being targeted. The federal government is currently reviewing a new regulation that would require breach disclosures. This regulation will be a significant step to bringing Canada in line with other nations.
Finally, although all companies processing credit cards are contractually required to comply with the Payment Card Industry Standard, many Canadian companies ignore or avoid becoming compliant because in many cases fines for non-compliance are not being enforced as diligently as they are in other countries. Executives and franchisors need to understand that by not investing in security best practices, including complying with the Payment Card Industry Standard, they are setting themselves up as the path of least resistance for cybercriminals and exposing their organizations or their franchisees to significant risks, costs and fines. The cost of prevention is minimal vs. the cost of a breach.
It’s time for Canadians to step up, take cybercrime seriously and become a leader in the protection of consumer data by ensuring that the proper technology, policies and procedures are implemented and followed. For too long, this issue has been swept under the rug leading to destructive cyber-attacks and financial losses from which are extremely difficult to recover. Our report found nearly every industry, country and type of data was involved in a breach of some kind in 2012. It’s not a question of “if”, only “when.”
| Print article |