Skip to content
Data Privacy

Wake Up Call: The Privsec Enforcement Problem

Bill Mew claims that there is a real enforcement issue because the situation is similar to the "Wild West" on Data Privacy Day 2023. Learn more right now.


Como parte de una serie de tres artículos con motivo del Día de la Protección de Datos de 2023 (véanse los artículos adjuntos deJakub LewandowskiyThomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Las políticas, los marcos normativos y las normas solo resultan útiles si se cumplen, del mismo modo que las normativas y las leyes carecen de sentido si no se hacen cumplir. El problema en el ámbito de la protección de datos y la ciberseguridad es que, allí donde deberían aplicarse las normas, a menudo se ignoran, y allí donde se han promulgado leyes, es necesario reforzar su cumplimiento.

Los CISO (directores de seguridad de la información) tienen una tarea ingrata. El personal suele mostrarse reacio a cumplir las medidas de ciberhigiene que el CISO intenta imponer, pero cuando su falta de disciplina da lugar a una filtración, estos compañeros se apresuran a echarle la culpa al CISO. Además, aunque hay que cumplir normativas costosas y complejas, así como normas estrictas sobre la notificación de filtraciones, las autoridades, lejos de ayudar a gestionar cualquier incidente o a capturar a los verdaderos delincuentes, se limitan a utilizar los informes para determinar la imposición de multas.

Functional, Cultural Mismatch

Si se les preguntara, la mayoría de los empleados estarían de acuerdo en que las amenazas cibernéticas son un problema importante, pero en su trabajo diario se centran en indicadores de rendimiento centrados en los ingresos o en el beneficio, como el ROI (retorno de la inversión). Estos son los indicadores con los que se mide su rendimiento individual y el de su unidad, y en los que se basan las políticas de incentivos de toda la empresa.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that una normativa sin aplicación no solo carece de sentido, sino que resulta contraproducente. Al fin y al cabo, solo las empresas responsables cumplirán estas normas y, para ellas, esto supone un coste o un «impuesto de cumplimiento». Por su parte, las empresas irresponsables suelen optar por no respetar las normas. Si creen que el riesgo de que se apliquen las sanciones es escaso o nulo, esto se convierte en una fuente de ventaja competitiva que les permite ahorrar costes y está libre de riesgos.

El incumplimiento de la normativa está muy extendido y proviene de las altas esferas, como demuestran los frecuentes titulares sobre incidentes relacionados con los datos que sufren las grandes empresas tecnológicas o las multas que se les imponen. Dichas multas no parecen surtir efecto disuasorio, sino que las grandes empresas tecnológicas y muchas otras que han tenido la mala suerte de sufrir un incidente relacionado con los datos las consideran un coste adicional de su actividad empresarial.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a indicador rezagado de la mala suerte de las empresas responsables rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a votación de 451 a 1. Cuando nuevas presiones por parte de los reguladores del resto de Europa la obligaron a actuar tras un retraso de dos años, la multa que impuso a Facebook fue tan baja que tuvo que ser incrementada (diez veces) ante la insistencia de los demás reguladores.

The EU Ombudsman Emily O’Reilly eventually abriendo una investigación into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Consejo Irlandés de Libertades Civiles (ICCL) criticó a la UE for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of cybersecurity ‘fire drills’ to test cybersecurity and incident response capabilities but is also championing the need for global rules to crack down on cybercrime.

Se estima que los daños causados por todas las formas de ciberdelincuencia, incluidos los costes de Recovery y reparación, ascendieron a 3 billones de dólares en 2015 y a 6 billones de dólares en 2021, y podrían alcanzar los 10,5 billones de dólares anuales para 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including la ciberdelincuencia, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most la ciberdelincuencia originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s Cyber Incident Reporting for Critical Infrastructure Act and in the EU with 2018’s Directive on Security Network and Information Systems. Still, there are also a host of other regulations that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The Oficina de las Naciones Unidas contra la Droga y el Delito is promoting a Cybercrime Programme which has the following aims:

  • Mayor eficiencia y eficacia en la investigación, el enjuiciamiento y la resolución judicial de los delitos informáticos, especialmente la explotación y el abuso sexual de menores en Internet, dentro de un marco sólido de derechos humanos.
  • Una respuesta eficiente y eficaz a largo plazo por parte de todo el Gobierno frente a la ciberdelincuencia, que incluya la coordinación nacional, la recopilación de datos y marcos jurídicos eficaces, y que conduzca a una respuesta sostenible y a una mayor disuasión.
  • Se ha reforzado la comunicación a nivel nacional e internacional entre el Gobierno, las fuerzas del orden y el sector privado, al tiempo que se ha incrementado la concienciación de la ciudadanía sobre los riesgos de la ciberdelincuencia.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • El personal rara vez aplica las medidas de higiene cibernética de forma adecuada
  • Las autoridades reguladoras no actúan de forma proactiva a la hora de detectar y combatir los incumplimientos.
  • Los delincuentes están ganando en confianza, intensidad y sofisticación.
  • La policía no puede actuar contra los delincuentes que operan desde refugios seguros
  • Y los CISO son el chivo expiatorio por defecto cuando las cosas salen mal

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience