ICO Expectations & Role

May 23, 2017 10:20am

  • Cyber security is a board level issue not an IT one
  • Is the ICO becoming a powerful regulator that can issue large fines?
  • Less discretion given to companies who fall victim to an attack if simple security measures are not in place
  • Scope to levy higher fines if the organisation has not already provided guidance to all customers on how to verify communications
  • The obligation to notify the ICO of a ‘Personal Data Breach’ no later than 72 hours after having become aware of it
  • Resources must be invested in crafting and maintaining incident management plans
  • The 12 steps to compliance success recommended by the ICO
  • Q&A