Skip to content
Data Privacy

Wake Up Call: The Privsec Enforcement Problem

Bill Mew claims that there is a real enforcement issue because the situation is similar to the "Wild West" on Data Privacy Day 2023. Learn more right now.


Im Rahmen einer dreiteiligen Artikelserie zum Datenschutztag 2023 (siehe die begleitenden Artikel vonJakub LewandowskiundThomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Richtlinien, Rahmenbedingungen und Vorschriften sind nur dann hilfreich, wenn sie eingehalten werden – genauso wie Vorschriften und Gesetze ohne Durchsetzung bedeutungslos sind. Das Problem im Bereich Datenschutz und Cybersicherheit besteht darin, dass dort, wo Vorschriften gelten sollten, diese häufig ignoriert werden, und dass dort, wo Gesetze eingeführt wurden, deren Durchsetzung verstärkt werden muss.

CISOs (Chief Information Security Officers) haben eine undankbare Aufgabe. Die Mitarbeiter zögern meist, sich an die von einem CISO durchgesetzten Maßnahmen zur Cyberhygiene zu halten, doch wenn ihre mangelnde Disziplin zu einer Sicherheitsverletzung führt, sind diese Kollegen nur allzu schnell dabei, dem CISO die Schuld zu geben. Hinzu kommt, dass zwar kostspielige und komplexe Vorschriften einzuhalten sind und strenge Regeln für die Meldung von Sicherheitsverletzungen gelten, die Behörden jedoch, anstatt bei der Bewältigung von Vorfällen zu helfen oder die tatsächlichen Täter zu fassen, die Meldungen lediglich dazu nutzen, die Höhe der Bußgelder festzulegen.

Functional, Cultural Mismatch

Auf Nachfrage würden die meisten Mitarbeiter zustimmen, dass Cyberbedrohungen ein erhebliches Problem darstellen, doch in ihrer täglichen Arbeit konzentrieren sie sich auf umsatz- oder gewinnorientierte ROI-Kennzahlen (Return on Investment). Anhand dieser Kennzahlen werden ihre individuelle Leistung und die ihrer Abteilung gemessen, und darauf sind auch die unternehmensweiten Anreizsysteme ausgerichtet.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that regulation without enforcement is not just pointless but counter-productive. After all, only responsible companies will comply with these regulations, and for them, it represents a cost or compliance tax. Meanwhile, irresponsible ones often choose not to abide by the rules. If they believe that there is little or no risk of enforcement, then this is a cost-saving and risk-free source of competitive advantage.

Die Nichteinhaltung von Vorschriften ist weit verbreitet und geht von der Unternehmensspitze aus, was sich in häufigen Schlagzeilen über Datenvorfälle bei Big-Tech-Unternehmen oder gegen diese verhängte Bußgelder widerspiegelt. Solche Bußgelder scheinen keine abschreckende Wirkung zu haben, sondern werden von Big-Tech-Unternehmen und vielen anderen, die das Pech hatten, einen Datenvorfall zu erleiden, vielmehr als zusätzliche Geschäftskosten angesehen.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a lagging indicator of misfortune for responsible firms rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a 451 zu 1 Stimmensanktioniert. Als sie schließlich durch weitere Lobbyarbeit von Regulierungsbehörden aus ganz Europa nach einer zweijährigen Verzögerung zum Handeln gezwungen wurde, war die gegen Facebook verhängte Geldbuße so niedrig, dass sie auf Drängen der anderen Regulierungsbehörden (um das Zehnfache) erhöht werden musste.

The EU Ombudsman Emily O’Reilly eventually opened an inquiry into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Irish Council of Civil Liberties (ICCL) criticised the EU for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of „Cyber-Übungen“ to test cybersecurity and incident response capabilities but is also championing the Notwendigkeit globaler Regeln to crack down on cybercrime.

Die durch alle Formen der Cyberkriminalität entstandenen Schäden, einschließlich der Kosten für Recovery und Behebung, beliefen sich Schätzungen zufolge im Jahr 2015 auf insgesamt 3 Billionen US-Dollar und im Jahr 2021 auf 6 Billionen US-Dollar; bis 2025 könnten sie jährlich bis zu 10,5 Billionen US-Dollar erreichen.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s nicht lohnt. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of sie schwerwiegende Probleme möglicherweise noch verschlimmert.

While almost all nations have signed up for United Nations agreements on combatting crime, including Cyberkriminalität, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most Cyberkriminalität originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s dem „Cyber Incident Reporting for Critical Infrastructure Act“ and in the EU with 2018’s der Richtlinie über die Sicherheit von Netz- und Informationssystemen. Still, there are also a Vielzahl weiterer Vorschriften that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The Büro der Vereinten Nationen für Drogen- und Verbrechensbekämpfung is promoting a Cybercrime Programme which has the following aims:

  • Steigerung der Effizienz und Wirksamkeit bei der Ermittlung, Strafverfolgung und gerichtlichen Aufarbeitung von Cyberkriminalität, insbesondere der sexuellen Ausbeutung und des Missbrauchs von Kindern im Internet, im Rahmen eines starken Menschenrechtsrahmens.
  • Eine effiziente und wirksame langfristige, regierungsweite Reaktion auf Cyberkriminalität, einschließlich nationaler Koordinierung, Datenerhebung und wirksamer rechtlicher Rahmenbedingungen, die zu einer nachhaltigen Bekämpfung und einer stärkeren Abschreckung führt.
  • Eine verstärkte nationale und internationale Kommunikation zwischen Regierung, Strafverfolgungsbehörden und der Privatwirtschaft sowie eine bessere Aufklärung der Öffentlichkeit über die Risiken der Cyberkriminalität.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • Die Mitarbeiter halten sich selten ausreichend an die Regeln der Cyberhygiene
  • Die Aufsichtsbehörden gehen nicht proaktiv gegen Verstöße vor und bekämpfen diese nicht
  • Kriminelle werden immer selbstbewusster, agieren immer aggressiver und gehen immer raffinierter vor
  • Die Polizei ist nicht in der Lage, gegen Kriminelle vorzugehen, die von sicheren Rückzugsorten aus operieren
  • Und wenn etwas schiefgeht, sind die CISOs automatisch die Sündenböcke.

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience