No idea.

But let’s be honest, everyone will be making wild speculations at this point, just as ‘experts’ in every other field will be. The only thing for certain, is that the UNcertainty will be used by security vendors to try to scare UK companies into buying something.

This one is unrelated, but is actually very good and you should read it first; Brexit: The Implications for the Insurance Industry.

Two of the pending EU laws in the pipeline that will be most cited are the Payment Services Directive 2 (PSD2) and the General Data Protection Regulation (GDPR). While both of these do not relate to information security per se, security is an enormously important component of each, and penalties will be commensurate with the egregiousness of the data misuse/loss.

The UK would have had to make these law within the next 2 -3 years, but now what? If we’re not IN the EU, do we have to follow the EU rules? Can’t we just do our own thing, like the US?

Well yes, we could, all we’d have to do is adopt something like Safe Harbor and all EU countries would be more than happy to do business with us. Right?

I don’t think so somehow.

Clearly the UK would never put itself in that position [praying silently], and seeing as both PSD2 and GDPR are fully supported by the UK, I would very much doubt any UK-only law would be markedly different. But ANY difference will still complicate things for UK businesses. It will likely require UK organisations to be far more pro-active in the demonstration of their compliance than would otherwise be necessary.

And if there’s one thing that no organisation I have ever come across is good at, it’s the demonstration of good security practices.

Not one.

Luckily for us, there is absolutely nothing in ANY regulation of which I am aware that requires anything more than ‘appropriate’ controls. From the GDPR for example; “Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing.

This is the greatest thing about my chosen career; Information security cares nothing for law, regulation, compliance, geography, or politics, it’s about a piece of data, on a computer, that someone wants to steal. Everything else is just reporting.

However, getting to the point where the demonstration of compliance is business as usual, is extremely difficult. Not complicated, just difficult. It’s actually very simple, all you have to do is get the CEO/BoD to care about it and it will happen. Easy, right?

UK organisations had 2 years from May 25th to demonstrate compliance with the GDPR, now [potentially] they have to demonstrate their equivalent compliance to every EU business with whom they want to transact. And you thought answering RFPs was bad now!

Nothing will change anytime soon, but in the meantime, just do what you know you should have doing all along, but start now.

Don’t know how, ask.

Thanks to the more unscrupulous vendors, security is becoming as complex as the law. Privacy therefore is at the top of the list of sticky topics because it also involves both the law and security. More countries are effecting privacy laws than ever before, but just like in a regular business, functionality and security must be balanced to be effective.

I’m not going to list all of the ongoing privacy issues in the press, but the biggest two currently are; the Prism/whistleblowing/NSA scandal, and the EUs Data Protection Directive. While worlds apart in their impact and aims, they still raise a question that I’ve not seen addressed very often. Probably because there is no one right answer, but the question of how much privacy is too much should not be ignored or any semblance of balance is impossible. Also, it seems that unless we’re bashing the perceived bullies (Government, big business), there’s not much interest in this side of things.

So, Prism, summarised and paraphrased, is an anti-terrorism program that has unprecedented access to enormous amounts of personal data.

Proponents state that it’s necessary for national security, opponents state that it’s an abuse of power / attack on civil liberties and so on. But who’s right? If you choose a side – and to the extreme – you are either saying it’s OK for the Government to do whatever it takes to defend its people, and that the end justifies the means, or you’re saying that an individuals right to privacy outweighs the security of a nation. Clearly both of these positions are nonsense, but what is the right answer? It has to be somewhere in between., right?

However, to get the middle, both sides need to accept responsibility; Government for not becoming Big Brother-esque, and individual citizens for paying the price in personal privacy for the freedoms and conveniences we frequently take for granted.

For example, if you ask any victim of a terrorist attack, a hate crime, harassment, or a stalker-ex, whether or not they would have traded complete loss of privacy to avoid their pain, and I think the answer is a given.

However, now ask ME whether or not I would entirely relinquish MY privacy to prevent this from happening to someone else – which I would do in a heartbeat -, and you now have the gist of why this issue is so contentious (some are already calling it – terribly un-originally – Prism-gate). People want security, but they don’t want to accept the cost for it, which in todays plugged-in/online/Internet/information age, that cost is their privacy.

As for the EU Data Protection Directive, that’s about the far less glamorous subject of making sure organisations protect the data in their possession, and while less life-threatening, leads to the same question. This time it’s about [for example] the ability of an organisation to sell you stuff that you want, or didn’t even know you wanted but now you can’t live without (like the iPhone). They want to sell you stuff, you want your data protected or removed altogether.

Personally I want organisations to know EXACTLY what I like and don’t like. That way I’ll get less spam and pop-up ads regarding adult nappies/diapers and erectile dysfunction, and more on amazing gadgets and toys that will make my life complete. This requires absolutely enormous amounts of data, and is a true use of Big Data.

Not everyone agrees.

However, WE choose to plug in, we’re not forced. I have Linkedin, Facebook, Twitter, and more online bank / credit card accounts than I know what to do with. Sadly the accounts are mostly empty, but that’s not the point, which is why I have chosen these methods of communication and convenience to make my life better. Which they do…vastly.

We are not owed this functionality, we have a choice to use it or not. If you want it, you must pay for it.

How many of you read the privacy notices, or terms & conditions when you sign up for online services? No, me either, so I’m not going to complain if they go ahead and do exactly what they told me they were going to do.

I cannot speak to the law or politics, nor can I wax philosophically on human nature, but what I can talk to is personal accountability. You are owed nothing, except that which you earn. From your income, to your rights, to your karma, you get back what you put in. So perhaps what we should all do instead of complain, or demand that heads roll, is be a little more circumspect in our online interactions:

  1. Don’t post inappropriate comments on FB/Twitter or ANY form of social media or email. Assume that this information will NEVER go away;
  2. Limit your online banking and purchasing to known-good sites, check for HTTPS in the URL (secure transmission) , and CHOOSE A GOOD PASSWORD!;
  3. Make sure ALL of your online credit card / bank accounts have fraud and theft protection;
  4. Sign up for credit and identity monitoring services (I have two running, one US and one UK);
  5. Read the Terms & Conditions!;
  6. Do not even TAKE revealing or compromising pictures of yourself, or others, on any online-capable device …EVER (I think if I was to do that it would qualify as an offence against humanity, or maybe even a WMR (Weapon of Mass Revulsion));
  7. When you’re done with an online vendor, delete the account, and write to them invoking your right to erasure;
  8. Read my blog! 🙂

Personally, I LOVE the fact that London is full of cameras, I’m doing nothing wrong, and I feel better about my wife being out when it’s dark. I don’t care if some spotty geek in Fort Mead, MD is reading my personal email, or my FB posts, I’m not being seditious, or inappropriate, and if they derive pleasure reading about my wife and me discussing our 2012 taxes, good luck to him/her.

I want safety in the streets, safety for my country, AND the convenience of all that being online gives me, and if my privacy is the price I must pay, so be it. I trust the ‘official’ watchers infinitely more than the criminals or terrorists, but it’s MY responsibility to give NO-ONE access to more than I can afford to lose.

[If you liked this article, please share! Want more like it, subscribe!]

Finally, some common sense is starting to prevail;

http://www.huntonprivacyblog.com/2013/06/articles/hunton-webinar-on-the-proposed-eu-regulation-developing-a-more-creative-approach/

Detractors say that this is diluting the original intent of the directive, but as I have seen so many times in PCI, if you don’t make it achievable, you cannot enforce it fairly.

Risk based approach is always the way…