Showing posts with label Data Privacy. Show all posts
Showing posts with label Data Privacy. Show all posts

Monday, 8 January 2018

How secure you are?

You are as secure as careful you are.

Stay vigilant, watchful and attentive! Use your common sense and instincts.

If anything seems weird…, stop action, refuse to continue your work, raise your hand!




Watch out! Don't get hooked by an e-mail scam Watch how easy it is to loose your password, data, and ... security.





Don’t get hooked by an e-mail scam


Phishing email messages, websites, and phone calls are designed to steal money, data or information.

Whenever any suspicious e-mail or phone comes, follow 4 steps to make sure this is not phising:

SPOOFING: carefully check sender’s address. On mobile device click on the display name to show the address.

URGENCY: you should be worried if there is a call to actions? Always check the link first, where it really can drive you, instead simply quickly clicking on it.

VERIFY: in case you are not sure if the sender is the “safe”, contact the person by doing a forward or using other phone number. Do not simply reply to the e-mail.

ROBUST PROCESSES: first and foremost, ensure that you follow your processes. If sender is asking you for any deviation, it needs to have all valid steps and approvals. Never agree on doing anything without being sure.




Trust your instinct. If it doesn’t feel right, question it.



';--have you been pwned?


Carefully check the sender’s address – on mobile devices click on the display name to show the address.

Always hover over the links to display the URL. What appears to be the URL is a link, so it can be deceiving.

The content of the email will try to entice you to click on the link. It will call to action. You will feel a sense of urgency.


Do not forget to follow the security steps! Check your e-mail here: https://haveibeenpwned.com/



Invoice fraud – check twice, or pay the price


Invoice fraud occurs when a fraudster tricks an organisation into changing the bank account payee details for a payment.

Fraudsters pretend to be a regular supplier of the organisation.

As funds are often transferred quickly, this makes the recovery of the money difficult.

Look out for requests to:

  • Change payee account details for a regular payment already set up with a supplier, particularly if the request is for an immediate payment.
Take time to consider:
  • If a request to alter bank details or transfer money was expected or if it was received out of the blue from an existing supplier.
  • Is there a PO for the supply, can anyone confirm that goods / services were actually ordered and delivered?
Always verify requests to change bank details or set up new payment instructions by contacting the supplier directly. Use established contact details on file before implementing changes

Making fake statements is easy as 1-2-3. You can even find many instructions on youtube!


Inside job


Money and information are very often stolen by people within the organisation. There are many reasons why it happens. In many instances it is all because greed, however it is not only that.

To be safer always have eyes and ears open for the behaviours or activities of concern, and suspicious behaviour patterns that might indicate a potential insider risk:

  • Hostile attitudes and extremist views towards the company
  • Becoming withdrawn or appear vulnerable
  • Not eager to use vacations
  • Unauthorised handling of sensitive material
  • Being miserable, too nervous, etc.


Monday, 13 February 2017

465 days to GDPR

From May 2018 a new data protection law, the General Data Protection Regulation (GDPR), will apply through the EU. The GDPR introduces a number of significant changes including a step change in sanctions with fines of up to 4% of annual worldwide turnover. There are more than a year remaining before the GDPR is implemented and the changes needed to comply with it are significant.



Consider the below to get your organisation ready for this!

Steering Group
Organise a Readiness Steering Group who will lead the organisation and all its functions to implement the GDPR. It should be chaired by General Counsel and includes attendees from group companies, and / or all functions. Consider engagement of data protection specialists from law firm, to help develop a compliance plan.

Workshops and detailed gap analysis
Plan a serious of workshops during the first half of the year to obtain input from each of the functions about their current data collection, processing and compliance processes. The workshops, along with other information submitted by each functions (such as existing procedures), will be used to complete the findings of a detailed gap analysis by end of June. Remind your colleagues that each function will remain responsible throughout for the allocation of appropriate resource to prepare for GDPR compliance based on its gap analysis.

Implementation Plan
The Steering Group will further work with each function to finalise an implementation plan by end of the year, taking into account operational and cost implications of the options available to becoming GDPR compliant. The implementation plan and the work to deliver it should be monitored and reported on by the Steering Group.

Approach to be taken

While the primary objective of the project is to enable compliance with the GDPR the Steering Group should be conscious of the need to take proper account of commercial objectives and where possible should also use this as an opportunity to deliver synergies and improvements by taking a consistent approach across your organisation!

Remember business is first!

Read more on GDPR http://www.eugdpr.org/