Protect data while respecting compliance

The consequences of a corporate or business data breach can be catastrophic for companies of all sizes. The resulting damage to reputation, customers and profits is the tip of the iceberg.

Companies could pay the price of heavy fines imposed by new and strict regulations.

Because firewalls are no longer sufficient to protect data, companies must implement multiple levels of protection on each network endpoint to build their defenses and focus on compliance requirements.

The increase in cyber attacks has caused the birth of new and strict regulations on data security, of great importance for companies all over the world. New directives such as the General Data Protection Regulation (GDPR) of the European Union are not only important for companies based in the EU, but apply to all companies that collect data from European residents.

The GDPR legislation informs companies of the presence of important sanctions in the event of non-compliance following an attack. These sanctions add to the economic loss caused by the data breach itself.

Main requirements of the GDPR

By collecting data, companies must comply with compliance regulations. This also includes subjects who purchase goods and services and monitor customer habits for the purpose of using such data. For example, any online monitoring of activities aimed at improving the identification of the ideal customer. Even if your business takes place beyond the EU borders, all devices that access customer data must be secure.

Meeting the requirements on document retention, conducting impact assessments and processing reports related to violations is time-consuming. The addition of a new device to a corporate network determines compliance with the corporate criteria and monitoring by a SIEM (Systems Information and Event Manager) tool that keeps track of critical issues, activates recovery procedures and supports the processing of compliance reports.

 

Companies must provide notification of a violation to the data protection association without unjustified delay, if possible within 72 hours. If this term is not respected, a justified reason must be given. This new requirement was introduced in order to protect the rights of individuals to be informed about how their personal data are used and to understand whether companies that store such data have procedures, tools and products suitable for monitoring and identifying risks, as well as block any attacks in order to protect customer data.

The new legislation introduces a multi-level approach to the sanctioning system that will be regulated by the gravity of the infringement. The maximum fine to be paid could be around 4% of the company's annual turnover, up to the amount of 20 million euros. As mentioned for some countries, eg Netherlands, even heavier penalties have been introduced, up to 11% of annual turnover.

Ensure compliance of printers

When it comes to printer protection there are progressive actions to take to ensure endpoint compliance, in preparation for the introduction of these new regulations.

Preparation for compliance inspections

Ensure real monitoring of all IT infrastructure including endpoint devices such as printers.
It is also necessary to schedule periodic evaluations aimed at maintaining compliance with the criteria in each endpoint device of the entire printer fleet.

Performing a full inspection

Identify all devices that can access company and customer data, as well as assess the integrated security level.
It is recommended to use a security management tool that immediately identifies new devices and automatically applies corporate security policy settings.

Safety predisposition

Implement the right criteria so that the compliance requirements are the prerequisites for the introduction of devices and services in the network. Make sure you are able to monitor all devices, with monitoring and vulnerability assessment tools for the entire network.
Do you have questions or just want more information? Contact us »
  • Interventions within 24 hours
  • Printer technical assistance
  • Multifunctional technical assistance
  • Specialized consultancy services
  • Photocopier technical assistance
  • Plotter technical assistance
  • Fax technical assistance
  • Managed Print Services
  • Toners and Cartridges at competitive prices
  • Sales of printers, multifunctional, peripherals
  • Computer sales, notebook monitors, servers
  • Dealers Canon, Epson, OKI and Samsung