By Jervis Hui, Senior Product Marketing Manager, Netskope
With the impending May 25, 2018, date for GDPR compliance coming up, Netskope worked with the Cloud Security Alliance (CSA) to survey IT and security professionals for a recently released report covering GDPR preparation and challenges. According to one of our recent Netskope Cloud Reports, only about 25 percent of all cloud services across SaaS and IaaS are GDPR-ready. And with the ubiquity of cloud and web services, organizations face steep challenges with just SaaS, IaaS, and web alone, not to mention the myriad of other issues they need to address for the GDPR.
To help better understand the challenges, CSA and Netskope asked over 1,000 respondents questions that covered topics like their ability and confidence to achieve compliance, specific plans and tools being used to meet GDPR requirements, what they consider to be the most challenging elements of GDPR in terms of compliance, and its impact on company plans for the adoption of new technologies, provider relationships, and budgets. Key findings of the report include:
- Eighty-three percent of companies do not feel very prepared for GDPR, with companies in the APAC region feeling less prepared than other regions.
- Fifty-nine percent of companies are making it a high priority. Even so more than 10 percent of companies still have no defined plan to prepare for GDPR.
- Seventy-one percent of the respondents feel confident that their organizations will meet GDPR compliance in time.
- Thirty-one percent of companies have well-defined plans for meeting compliance, 85 percent have something in place, and 73 percent have begun executing that plan.
- The GDPR’s “right to erasure,” (53%) “data protection by design and by default,” (42%) and “records of processing activities” (39%) were cited as being among the biggest challenges organizations face in achieving compliance.
- Documentation of data-collection policies (68%), codes of conduct (56%), and third-party audits and assessments (55%) are among the most common tools being used to demonstrate GDPR compliance.
The results seem to indicate that while organizations are in the midst of implementing programs, solutions, and processes to comply with the GDPR, many were still feeling under-prepared as of the survey dates of January 25-February 21, 2018. The interpretation of the articles and how DPAs will enforce the GDPR probably only exacerbated organizations’ feelings of under-preparedness. The good thing is that 70 percent of respondents indicated that they either felt ‘somewhat confident’ or ‘very confident’ that their respective organizations would be ready to meet GDPR compliance by the May deadline.
Across Netskope customers and prospects, we’ve seen many security teams work across their organizations, collaborating with legal, compliance, and technology teams to implement policies and solutions to meet GDPR guidelines. While cloud and web services present more risk vectors for data loss and threats, securing the use of these services allows for continued productivity gains and flexibility by employees. The full GDPR Preparation and Challenges Survey Report contains more information on how organizations are preparing for the GDPR.
Download the full report to get more specifics and see how others compare to your current GDPR compliance plans.