GDPR will change how companies work with cloud providers
Full article467 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
We keep seeing errors in the ways companies are safeguarding personally identifiable data in the cloud. Those errors will have massive consequences under Europe's new General Data Protection Regulation.
One of the bigger stipulations in GDPR is that third-party service providers, including companies who run the ever-ubiquitous cloud, will also be responsible for following the correct protocols when it comes to protecting EU citizen data.
Yet just as companies keep throwing everything into the cloud, we are seeing errors in the way they safeguard personally identifiable data.
If you have been following the work of Chris Vickery, you know how easily these errors can be found. Vickery, director of cyber risk research for California-based Upguard, has been finding misconfigured cloud instances all over the internet. Just in the past year, Vickery identified these openly discoverable instances associated with a Florida credit monitoring firm, media behemoth Viacom, and even at the Department of Defense.
Each finding had enough PII to keep privacy officers sleepless for weeks. While they were all based in America, Vickery recently came across a similar breach at French marketing firm Octoly, which caters to European social media influencers.
In a few weeks, Octoly’s response to such a finding will possibly be under much more scrutiny. I talked to Vickery and Upguard CEO Mike Baukes about how they see these security incidents playing out under GDPR, and whether cloud providers will lead the way when it comes to breach response.
Previously on the “Decoding GDPR” podcast: Why GDPR is flipping the thought process around data ownership
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/decoding-gdpr-podcast-episode-2-chris-vickery-mike-baukes-upguard/