SlideShare a Scribd company logo
1 of 38
December 2017
Cyber security breakfast
briefing
Glenn Nicol, Corporate Partner
Chair’s welcome
Housekeeping
@pkfFrancisClark
#CyberSecurity17
Programme
GDPR – Ben Travers, Stephens Scown LLP
GDPR tools – Russell Cosway, Gydeline
Cyber Essentials / IASME accreditation –
Richard Wilding, PKF Francis Clark
Cyber insurance – Jonathan Cox, Paveys
Ben Travers, Stephens Scown
GDPR
GDPR Tools
Russell Cosway – December 2017
Tools landscape . . .
• Date/Who/DPO
• Process Name/Purpose
• Legal Basis
• Data Source/Locations
• Who is impacted?
• Description
• How is data deleted?
• What risks/mitigations
• Date of review
Data Protection Impact Assessment (DPIA)
What does Gydeline do?
• Checks for compliance against every word of the regulation
• Enables proof of accountability
• Changes as the regulation changes
• Identifies specific actions
• Makes GDPR simpler to understand
Links
• gydeline.com/dpia
• gydeline.com/datamap
FCDEC2017 – 25% discount on lifetime of subscription
End
www.gydeline.com
hello@gydeline.com
Richard Wilding, Head of Cyber Services
Cyber Essentials / IASME
accreditation
20
Why PKF Francis Clark
• Trusted advisers – experienced auditors
• We offer assurance not consultancy
 Offer assurance to set well known standards
approved by Government and NCSC
 Cyber Essentials and IASME are constantly
updated and monitored for quality control
• Some additional services can be offered
www.website.com
General Data Protection Regulations
2018
• GDPR has 2 main sides to it
• The two main areas of GDPR that
organisations need to look at
 Data subject rights and the need for
‘informed consent’
 Good standards of information security
• Cyber Essentials is a great first step
• IASME demonstrates a wider governance
system for data controls
Cyber Essentials
• Self-assessment questionnaire for the company to complete
• Covers 5 key areas/71 questions
• We provide upfront assistance (1 days needed) to support
how to complete and progress
• It is submitted via a secure portal for us to assess
• Basic vulnerability scan performed
• Assessor feedback provided
• Once successful can use the Cyber Essentials logo for 12m
• Limited insurance provided/can help reduce further cyber
insurance
Cyber Essentials PLUS
• We audit and test the 5 key control areas
• Includes detailed vulnerability and limited penetration
testing
• A report is then issued
• Once successful can use the Cyber Essentials PLUS
logo for 12m
• Can help to reduce cyber insurance further
IASME (Information Assurance for Small and Medium Enterprises)
• IASME – two levels standard and gold
• 180 questions (including those in Cyber Essentials)
• Includes GDPR specific questions
• Akin to ISO27001
• A report is then issued
• Once successful can use the IASME logo for 12m
25
Next steps
• See brochure in pack
• Complete form
• Chat with us after this event
• Contact your PKF Francis Clark adviser or e-
mail: cyber@pkf-francislark.co.uk
Disclaimer & copyright
c) copyright PKF Francis Clark, 2017
You shall not copy, make available, retransmit, reproduce, sell, disseminate, separate, licence, distribute, store electronically, publish, broadcast or otherwise
circulate either within your business or for public or commercial purposes any of (or any part of) these materials and / or any services provided by PKF Francis
Clark in any format whatsoever unless you have obtained prior written consent from PKF Francis Clark to do so and entered into a licence.
To the maximum extent permitted by applicable law PKF Francis Clark excludes all representations, warranties and conditions (including, without limitation, the
conditions implied by law) in respect of these materials and /or any services provided by PKF Francis Clark.
These materials and /or any services provided by PKF Francis Clark are designed solely for the benefit of delegates of PKF Francis Clark.
The content of these materials and / or any services provided by PKF Francis Clark does not constitute advice and whilst PKF Francis Clark endeavours to
ensure that the materials and / or any services provided by PKF Francis Clark are correct, we do not warrant the completeness or accuracy of the materials and
/or any services provided by PKF Francis Clark; nor do we commit to ensuring that these materials and / or any services provided by PKF Francis Clark are up-
to-date or error or omission-free.
Where indicated, these materials are subject to Crown copyright protection. Re-use of any such Crown copyright-protected material is subject to current law and
related regulations on the re-use of Crown copyright extracts in England and Wales.
These materials and / or any services provided by PKF Francis Clark are subject to our terms and conditions of business as amended from time to time, a copy
of which is available on request.
Our liability is limited and to the maximum extent permitted under applicable law PKF Francis Clark will not be liable for any direct, indirect or consequential loss
or damage arising in connection with these materials and / or any services provided by PKF Francis Clark, whether arising in tort, contract, or otherwise,
including, without limitation, any loss of profit, contracts, business, goodwill, data, income or revenue. Please note however, that our liability for fraud, for death
or personal injury caused by our negligence, or for any other liability is not excluded or limited.
PKF Francis Clark is a trading name of Francis Clark LLP. Francis Clark LLP is a limited liability partnership, registered in England and Wales with registered
number OC349116. The registered office is Sigma House, Oak View Close, Edginswell Park, Torquay TQ2 7FF where a list of members is available for
inspection and at www.pkf-francisclark.co.uk. The term ‘Partner’ is used to refer to a member of Francis Clark LLP or to an employee. Registered to carry on
audit work in the UK and Ireland, regulated for a range of investment business activities and licensed to carry out reserved legal activity of non-contentious
probate in England and Wales by the Institute of Chartered Accountants in England and Wales. Partners acting as insolvency practitioners are licensed in the
UK by the Institute of Chartered Accountants in England and Wales. A partner appointed as Administrator or Administrative Receiver acts only as agent of the
insolvent entity and without personal liability. Francis Clark LLP is a member firm of the PKF International Limited network of legally independent firms and does
not accept responsibility or liability for the actions or inactions on the part of any other individual member firm or firms.
Insurance Aspects of Cyber
 Insurance Cover – Cyber &/or Crime
 The Threats
 Why Do Businesses Need Cyber Insurance?
 Claims
 Reducing risk
 Q&A
Cyber &/or Crime
Cyber Liability Insurance provides
businesses with protection against financial
loss resulting from the loss of personal
and/or corporate data.
Cover addresses the first and third-party
risks ranging from the loss of a single laptop
or file to the hacking of a companies
website or network.
Security
Breach
Data
Breach
Operational
failure
Main policy triggers:
Crime Insurance provides businesses with protection against financial loss
resulting from criminal or fraudulent taking, obtaining or appropriation of money,
securities, funds or property.
The ThreatsTHREATS
NEGLIGENT EMPLOEE
Send wrong data
Loss of hardware (mobile theft)
Victim of Phishing, Vishing
OUTSIDERS
Denial of Service
Theft of Data
Hactivism
Crime Syndicate
Denial of Service
Theft of Data
Government Agencies Industrial Espionage
Denial of Service
Malware
Extortion
Shut Down Infrastructure
Advanced Persistent Threats
Credit / Banking details
Government ID
Personally Identifiable Info
Protected Health Info
Corporate Information
SOCIAL NETWORKING
Twitter
Facebook
LinkedIn
ROGUE EMPLOYEE
Physical Theft
Steal Data
Competitive advantage
Sell to criminals
Extortion
VENDORS
Cloud
Data Centers
Outside Providers
Network Interruption
Theft of Data due to Security Failures
Unauthorized Access of Data
Loss of Data
Network Interruption
Physical Theft of Servers
Theft of Data due to Security Failure
Network Interruption
Backdoor Intrusion
Employees
Negligent Employees
Rogue Employees
It’s all about Balance Sheet Protection….
• First Response Costs
• TP Liability
• Fines
• Loss of Revenue
• Brand / Reputational Damage
• Loss of Intellectual Property
• Contractual Liability
• Share Price
Cyber claims received by AIG EMEA (2013-
2016)
By industry
* Construction, Food & Beverage, Information Services, Other Services, Transportation,
Agriculture & Fisheries, Energy and Real Estate
By type
Cyber claims received by AIG EMEA (2013-
2016)
Claims Examples
Cloud Service
provider accidentally
de commissioned live
server (PI claim?)
Confidential Waste
Bins stolen
Older server
handed to bogus
courier
Legal papers
(EPL issues) sent
to wrong person
Details of delayed
products and refund
option sent to 250
people in error
IT consultant
providing HR
services
attempted hack
Insurance brokers
Krypto locked
Claims Examples
A fraudster hacked into the company’s email system to gain information
about its organisational structure. During telephone calls with a member
of staff in the finance department the fraudster mimicked the voice of the
company CEO. It was strongly suspected that the fraudsters listened to
his voice on a webcast and had practiced it to perfection.
The requested payments were supposedly for a confidential acquisition
that only senior management knew about and the fraudster provided
forged invoices containing forged signatures to the member of staff
contacted.
Hacking & Impersonation
Reducing the risk to your business
• Ensure your software is up to date and that you have the latest anti-virus software
installed as updates are released frequently to help combat the most recent cyber
threats.
• Staff training is essential. Educate your employees on how to recognise suspicious
emails and browse the internet safely. Cyber awareness should be included in part of
your induction process and revisited in regular refresher sessions.
• Ensure you have an incident response plan in place which you can call upon in the
event of a breach or interruption. This should include technical measures that enable
the recovery of systems, operations and data, and a communication strategy if
necessary.
• If you are looking for additional advice and guidance on prevention, we would
recommend the Cyber Essentials website, a government-backed cyber security
certification scheme that sets out a good baseline of security suitable for all
organisations across all sectors.
Reducing Risk
Identify Analyse Control Transfer
Any Questions?
Glenn Nicol, Corporate Partner
Chair’s close

More Related Content

What's hot

Cyber Insurance - Setting the scene - The Scene
Cyber Insurance  - Setting the scene - The SceneCyber Insurance  - Setting the scene - The Scene
Cyber Insurance - Setting the scene - The SceneKoen Van Loo
 
Cyber liability and cyber security
Cyber liability and cyber securityCyber liability and cyber security
Cyber liability and cyber securityHelen Carpenter
 
Langes directorsupdate magpi_september13
Langes directorsupdate magpi_september13 Langes directorsupdate magpi_september13
Langes directorsupdate magpi_september13 davidjac
 
Security and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to KnowSecurity and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to KnowTechSoup
 
Verizon's DBIR-A look into each industry
Verizon's DBIR-A look into each industryVerizon's DBIR-A look into each industry
Verizon's DBIR-A look into each industrySOCRadar Inc
 
10 Reasons to buy Cyber Liability Insurance
10 Reasons to buy Cyber Liability Insurance 10 Reasons to buy Cyber Liability Insurance
10 Reasons to buy Cyber Liability Insurance Hubbard Insurance Group
 
The Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTThe Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTCompliancy Group
 
Be An IT Hero - 10 Reasons to Move to the Cloud
Be An IT Hero - 10 Reasons to Move to the CloudBe An IT Hero - 10 Reasons to Move to the Cloud
Be An IT Hero - 10 Reasons to Move to the CloudUS Medical IT
 
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...Raj Goel
 
How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides Jim Kaplan CIA CFE
 
Network Security and Privacy Liability - Four Reasons Why You need This Cove...
Network Security and Privacy Liability  - Four Reasons Why You need This Cove...Network Security and Privacy Liability  - Four Reasons Why You need This Cove...
Network Security and Privacy Liability - Four Reasons Why You need This Cove...CBIZ, Inc.
 

What's hot (20)

Funsec3e ppt ch11
Funsec3e ppt ch11Funsec3e ppt ch11
Funsec3e ppt ch11
 
Cyber Insurance - Setting the scene - The Scene
Cyber Insurance  - Setting the scene - The SceneCyber Insurance  - Setting the scene - The Scene
Cyber Insurance - Setting the scene - The Scene
 
BEA Presentation
BEA PresentationBEA Presentation
BEA Presentation
 
Cyber liability and cyber security
Cyber liability and cyber securityCyber liability and cyber security
Cyber liability and cyber security
 
Langes directorsupdate magpi_september13
Langes directorsupdate magpi_september13 Langes directorsupdate magpi_september13
Langes directorsupdate magpi_september13
 
Security and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to KnowSecurity and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to Know
 
Cyber Liability Risk
Cyber Liability RiskCyber Liability Risk
Cyber Liability Risk
 
Forensic3e ppt ch07
Forensic3e ppt ch07Forensic3e ppt ch07
Forensic3e ppt ch07
 
Verizon's DBIR-A look into each industry
Verizon's DBIR-A look into each industryVerizon's DBIR-A look into each industry
Verizon's DBIR-A look into each industry
 
10 Reasons to buy Cyber Liability Insurance
10 Reasons to buy Cyber Liability Insurance 10 Reasons to buy Cyber Liability Insurance
10 Reasons to buy Cyber Liability Insurance
 
The Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTThe Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOT
 
Be An IT Hero - 10 Reasons to Move to the Cloud
Be An IT Hero - 10 Reasons to Move to the CloudBe An IT Hero - 10 Reasons to Move to the Cloud
Be An IT Hero - 10 Reasons to Move to the Cloud
 
Verizon DBIR 2021
Verizon DBIR 2021Verizon DBIR 2021
Verizon DBIR 2021
 
CyberSecurity Update Slides
CyberSecurity Update SlidesCyberSecurity Update Slides
CyberSecurity Update Slides
 
Do you have an identity theft protection plan
Do you have an identity theft protection planDo you have an identity theft protection plan
Do you have an identity theft protection plan
 
Protecting Donor Privacy
Protecting Donor PrivacyProtecting Donor Privacy
Protecting Donor Privacy
 
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
 
The Basics of Cyber Insurance
The Basics of Cyber InsuranceThe Basics of Cyber Insurance
The Basics of Cyber Insurance
 
How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides
 
Network Security and Privacy Liability - Four Reasons Why You need This Cove...
Network Security and Privacy Liability  - Four Reasons Why You need This Cove...Network Security and Privacy Liability  - Four Reasons Why You need This Cove...
Network Security and Privacy Liability - Four Reasons Why You need This Cove...
 

Similar to Cyber Security breakfast briefing - Exeter

Breakfast Briefings - Funding R&D - November 2017
Breakfast Briefings - Funding R&D - November 2017Breakfast Briefings - Funding R&D - November 2017
Breakfast Briefings - Funding R&D - November 2017PKF Francis Clark
 
Breakfast Briefing - April 2018
Breakfast Briefing - April 2018Breakfast Briefing - April 2018
Breakfast Briefing - April 2018PKF Francis Clark
 
Cyber Security and GDPR breakfast briefing June 2019
Cyber Security and GDPR breakfast briefing June 2019Cyber Security and GDPR breakfast briefing June 2019
Cyber Security and GDPR breakfast briefing June 2019PKF Francis Clark
 
Breakfast Briefing - Equity is not just for Punks: practicalities and princip...
Breakfast Briefing - Equity is not just for Punks: practicalities and princip...Breakfast Briefing - Equity is not just for Punks: practicalities and princip...
Breakfast Briefing - Equity is not just for Punks: practicalities and princip...PKF Francis Clark
 
Breakfast Briefings - October 2018
Breakfast Briefings - October 2018Breakfast Briefings - October 2018
Breakfast Briefings - October 2018PKF Francis Clark
 
Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017
Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017 Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017
Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017 PKF Francis Clark
 
Finance in Cornwall 2017 - Start Up Session
Finance in Cornwall 2017 - Start Up SessionFinance in Cornwall 2017 - Start Up Session
Finance in Cornwall 2017 - Start Up SessionPKF Francis Clark
 
Plymouth - Essential 6-monthly Finance Directors' Update - June 2017
Plymouth - Essential 6-monthly Finance Directors' Update - June 2017 Plymouth - Essential 6-monthly Finance Directors' Update - June 2017
Plymouth - Essential 6-monthly Finance Directors' Update - June 2017 PKF Francis Clark
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Jim Kaplan CIA CFE
 
Breakfast Briefings - December 2017
Breakfast Briefings - December 2017Breakfast Briefings - December 2017
Breakfast Briefings - December 2017PKF Francis Clark
 
Breakfast briefing - Business and Share valuations
Breakfast briefing - Business and Share valuationsBreakfast briefing - Business and Share valuations
Breakfast briefing - Business and Share valuationsPKF Francis Clark
 
Bodmin - Essential 6-monthly Finance Directors' Update - June 2017
Bodmin - Essential 6-monthly Finance Directors' Update - June 2017 Bodmin - Essential 6-monthly Finance Directors' Update - June 2017
Bodmin - Essential 6-monthly Finance Directors' Update - June 2017 PKF Francis Clark
 
Taunton - Essential 6-monthly Finance Directors' Update - June 2017
Taunton - Essential 6-monthly Finance Directors' Update - June 2017 Taunton - Essential 6-monthly Finance Directors' Update - June 2017
Taunton - Essential 6-monthly Finance Directors' Update - June 2017 PKF Francis Clark
 
Data breaches - Is Your Law Firm in Danger
Data breaches - Is Your Law Firm in DangerData breaches - Is Your Law Firm in Danger
Data breaches - Is Your Law Firm in DangerZitaAdlTrk
 
Cloud data security and GDPR compliance
Cloud data security and GDPR complianceCloud data security and GDPR compliance
Cloud data security and GDPR complianceSalim Benadel
 
Exeter - Essential 6-monthly Finance Directors' Update - June 2017
Exeter - Essential 6-monthly Finance Directors' Update - June 2017 Exeter - Essential 6-monthly Finance Directors' Update - June 2017
Exeter - Essential 6-monthly Finance Directors' Update - June 2017 PKF Francis Clark
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?PECB
 
Cybersecurity crisis management a prep guide
Cybersecurity crisis management   a prep guideCybersecurity crisis management   a prep guide
Cybersecurity crisis management a prep guideJoAnna Cheshire
 
SMCR The Chicken & The Pig with GRC2020 & SureCloud
SMCR The Chicken & The Pig with GRC2020 & SureCloudSMCR The Chicken & The Pig with GRC2020 & SureCloud
SMCR The Chicken & The Pig with GRC2020 & SureCloudSureCloud
 
International Tax Risk.May2011
International Tax Risk.May2011International Tax Risk.May2011
International Tax Risk.May2011sarogers99
 

Similar to Cyber Security breakfast briefing - Exeter (20)

Breakfast Briefings - Funding R&D - November 2017
Breakfast Briefings - Funding R&D - November 2017Breakfast Briefings - Funding R&D - November 2017
Breakfast Briefings - Funding R&D - November 2017
 
Breakfast Briefing - April 2018
Breakfast Briefing - April 2018Breakfast Briefing - April 2018
Breakfast Briefing - April 2018
 
Cyber Security and GDPR breakfast briefing June 2019
Cyber Security and GDPR breakfast briefing June 2019Cyber Security and GDPR breakfast briefing June 2019
Cyber Security and GDPR breakfast briefing June 2019
 
Breakfast Briefing - Equity is not just for Punks: practicalities and princip...
Breakfast Briefing - Equity is not just for Punks: practicalities and princip...Breakfast Briefing - Equity is not just for Punks: practicalities and princip...
Breakfast Briefing - Equity is not just for Punks: practicalities and princip...
 
Breakfast Briefings - October 2018
Breakfast Briefings - October 2018Breakfast Briefings - October 2018
Breakfast Briefings - October 2018
 
Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017
Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017 Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017
Bournemouth- Essential 6-monthly Finance Directors' Update - June 2017
 
Finance in Cornwall 2017 - Start Up Session
Finance in Cornwall 2017 - Start Up SessionFinance in Cornwall 2017 - Start Up Session
Finance in Cornwall 2017 - Start Up Session
 
Plymouth - Essential 6-monthly Finance Directors' Update - June 2017
Plymouth - Essential 6-monthly Finance Directors' Update - June 2017 Plymouth - Essential 6-monthly Finance Directors' Update - June 2017
Plymouth - Essential 6-monthly Finance Directors' Update - June 2017
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10)
 
Breakfast Briefings - December 2017
Breakfast Briefings - December 2017Breakfast Briefings - December 2017
Breakfast Briefings - December 2017
 
Breakfast briefing - Business and Share valuations
Breakfast briefing - Business and Share valuationsBreakfast briefing - Business and Share valuations
Breakfast briefing - Business and Share valuations
 
Bodmin - Essential 6-monthly Finance Directors' Update - June 2017
Bodmin - Essential 6-monthly Finance Directors' Update - June 2017 Bodmin - Essential 6-monthly Finance Directors' Update - June 2017
Bodmin - Essential 6-monthly Finance Directors' Update - June 2017
 
Taunton - Essential 6-monthly Finance Directors' Update - June 2017
Taunton - Essential 6-monthly Finance Directors' Update - June 2017 Taunton - Essential 6-monthly Finance Directors' Update - June 2017
Taunton - Essential 6-monthly Finance Directors' Update - June 2017
 
Data breaches - Is Your Law Firm in Danger
Data breaches - Is Your Law Firm in DangerData breaches - Is Your Law Firm in Danger
Data breaches - Is Your Law Firm in Danger
 
Cloud data security and GDPR compliance
Cloud data security and GDPR complianceCloud data security and GDPR compliance
Cloud data security and GDPR compliance
 
Exeter - Essential 6-monthly Finance Directors' Update - June 2017
Exeter - Essential 6-monthly Finance Directors' Update - June 2017 Exeter - Essential 6-monthly Finance Directors' Update - June 2017
Exeter - Essential 6-monthly Finance Directors' Update - June 2017
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?
 
Cybersecurity crisis management a prep guide
Cybersecurity crisis management   a prep guideCybersecurity crisis management   a prep guide
Cybersecurity crisis management a prep guide
 
SMCR The Chicken & The Pig with GRC2020 & SureCloud
SMCR The Chicken & The Pig with GRC2020 & SureCloudSMCR The Chicken & The Pig with GRC2020 & SureCloud
SMCR The Chicken & The Pig with GRC2020 & SureCloud
 
International Tax Risk.May2011
International Tax Risk.May2011International Tax Risk.May2011
International Tax Risk.May2011
 

More from PKF Francis Clark

Solicitors' Property, Taxes and SRA Update
Solicitors' Property, Taxes and SRA UpdateSolicitors' Property, Taxes and SRA Update
Solicitors' Property, Taxes and SRA UpdatePKF Francis Clark
 
Breakfast briefing Spaceport Cornwall and Innovate UK
Breakfast briefing   Spaceport Cornwall and Innovate UKBreakfast briefing   Spaceport Cornwall and Innovate UK
Breakfast briefing Spaceport Cornwall and Innovate UKPKF Francis Clark
 
Truro Breakfast Briefing - Grants
Truro Breakfast Briefing - GrantsTruro Breakfast Briefing - Grants
Truro Breakfast Briefing - GrantsPKF Francis Clark
 
Truro December Breakfast briefing - Grants - a last hurrah!
Truro December Breakfast briefing - Grants - a last hurrah!Truro December Breakfast briefing - Grants - a last hurrah!
Truro December Breakfast briefing - Grants - a last hurrah!PKF Francis Clark
 
Exeter - Essential 6-monthly Finance Directors' Update - November 2019
Exeter - Essential 6-monthly Finance Directors' Update - November 2019Exeter - Essential 6-monthly Finance Directors' Update - November 2019
Exeter - Essential 6-monthly Finance Directors' Update - November 2019PKF Francis Clark
 
Plymouth - Essential 6-monthly Finance Directors' Update - November 2019
Plymouth - Essential 6-monthly Finance Directors' Update - November 2019Plymouth - Essential 6-monthly Finance Directors' Update - November 2019
Plymouth - Essential 6-monthly Finance Directors' Update - November 2019PKF Francis Clark
 
Bristol - Essential 6-monthly Finance Directors' Update - November 2019
Bristol - Essential 6-monthly Finance Directors' Update - November 2019Bristol - Essential 6-monthly Finance Directors' Update - November 2019
Bristol - Essential 6-monthly Finance Directors' Update - November 2019PKF Francis Clark
 
Fast Growth - Navigating the tax & funding cycle
Fast Growth - Navigating the tax & funding cycleFast Growth - Navigating the tax & funding cycle
Fast Growth - Navigating the tax & funding cyclePKF Francis Clark
 
Bodmin - Essential 6-monthly Finance Directors' Update - November 2019
Bodmin - Essential 6-monthly Finance Directors' Update - November 2019Bodmin - Essential 6-monthly Finance Directors' Update - November 2019
Bodmin - Essential 6-monthly Finance Directors' Update - November 2019PKF Francis Clark
 
Taunton - Essential 6-monthly Finance Directors' Update - November 2019
Taunton - Essential 6-monthly Finance Directors' Update - November 2019Taunton - Essential 6-monthly Finance Directors' Update - November 2019
Taunton - Essential 6-monthly Finance Directors' Update - November 2019PKF Francis Clark
 
Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019
Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019
Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019PKF Francis Clark
 
Breakfast briefing F&D 'waste not want not' October 2019
Breakfast briefing   F&D 'waste not want not' October 2019Breakfast briefing   F&D 'waste not want not' October 2019
Breakfast briefing F&D 'waste not want not' October 2019PKF Francis Clark
 
Breakfast briefing Local Investment Strategy
Breakfast briefing   Local Investment StrategyBreakfast briefing   Local Investment Strategy
Breakfast briefing Local Investment StrategyPKF Francis Clark
 
Property Sector Annual Update 2019
Property Sector Annual Update 2019Property Sector Annual Update 2019
Property Sector Annual Update 2019PKF Francis Clark
 
Exeter - Breakfast Briefing - Debt Finance
Exeter - Breakfast Briefing - Debt Finance Exeter - Breakfast Briefing - Debt Finance
Exeter - Breakfast Briefing - Debt Finance PKF Francis Clark
 
Breakfast Briefing - August 2019
Breakfast Briefing - August 2019Breakfast Briefing - August 2019
Breakfast Briefing - August 2019PKF Francis Clark
 
Exeter - Academy Update Seminar 2019
Exeter - Academy Update Seminar 2019Exeter - Academy Update Seminar 2019
Exeter - Academy Update Seminar 2019PKF Francis Clark
 
Bodmin - Academy Update Seminar 2019
Bodmin - Academy Update Seminar 2019Bodmin - Academy Update Seminar 2019
Bodmin - Academy Update Seminar 2019PKF Francis Clark
 

More from PKF Francis Clark (20)

Green Business Green Cornwall
Green Business Green CornwallGreen Business Green Cornwall
Green Business Green Cornwall
 
Solicitors' Property, Taxes and SRA Update
Solicitors' Property, Taxes and SRA UpdateSolicitors' Property, Taxes and SRA Update
Solicitors' Property, Taxes and SRA Update
 
Breakfast briefing Spaceport Cornwall and Innovate UK
Breakfast briefing   Spaceport Cornwall and Innovate UKBreakfast briefing   Spaceport Cornwall and Innovate UK
Breakfast briefing Spaceport Cornwall and Innovate UK
 
Truro Breakfast Briefing - Grants
Truro Breakfast Briefing - GrantsTruro Breakfast Briefing - Grants
Truro Breakfast Briefing - Grants
 
Truro December Breakfast briefing - Grants - a last hurrah!
Truro December Breakfast briefing - Grants - a last hurrah!Truro December Breakfast briefing - Grants - a last hurrah!
Truro December Breakfast briefing - Grants - a last hurrah!
 
Exeter - Essential 6-monthly Finance Directors' Update - November 2019
Exeter - Essential 6-monthly Finance Directors' Update - November 2019Exeter - Essential 6-monthly Finance Directors' Update - November 2019
Exeter - Essential 6-monthly Finance Directors' Update - November 2019
 
Plymouth - Essential 6-monthly Finance Directors' Update - November 2019
Plymouth - Essential 6-monthly Finance Directors' Update - November 2019Plymouth - Essential 6-monthly Finance Directors' Update - November 2019
Plymouth - Essential 6-monthly Finance Directors' Update - November 2019
 
Bristol - Essential 6-monthly Finance Directors' Update - November 2019
Bristol - Essential 6-monthly Finance Directors' Update - November 2019Bristol - Essential 6-monthly Finance Directors' Update - November 2019
Bristol - Essential 6-monthly Finance Directors' Update - November 2019
 
Fast Growth - Navigating the tax & funding cycle
Fast Growth - Navigating the tax & funding cycleFast Growth - Navigating the tax & funding cycle
Fast Growth - Navigating the tax & funding cycle
 
Bodmin - Essential 6-monthly Finance Directors' Update - November 2019
Bodmin - Essential 6-monthly Finance Directors' Update - November 2019Bodmin - Essential 6-monthly Finance Directors' Update - November 2019
Bodmin - Essential 6-monthly Finance Directors' Update - November 2019
 
Taunton - Essential 6-monthly Finance Directors' Update - November 2019
Taunton - Essential 6-monthly Finance Directors' Update - November 2019Taunton - Essential 6-monthly Finance Directors' Update - November 2019
Taunton - Essential 6-monthly Finance Directors' Update - November 2019
 
Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019
Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019
Bournemouth - Essential 6-monthly Finance Directors' Update - November 2019
 
Breakfast briefing F&D 'waste not want not' October 2019
Breakfast briefing   F&D 'waste not want not' October 2019Breakfast briefing   F&D 'waste not want not' October 2019
Breakfast briefing F&D 'waste not want not' October 2019
 
Breakfast briefing Local Investment Strategy
Breakfast briefing   Local Investment StrategyBreakfast briefing   Local Investment Strategy
Breakfast briefing Local Investment Strategy
 
Property Sector Annual Update 2019
Property Sector Annual Update 2019Property Sector Annual Update 2019
Property Sector Annual Update 2019
 
Exeter - Breakfast Briefing - Debt Finance
Exeter - Breakfast Briefing - Debt Finance Exeter - Breakfast Briefing - Debt Finance
Exeter - Breakfast Briefing - Debt Finance
 
Breakfast Briefing - August 2019
Breakfast Briefing - August 2019Breakfast Briefing - August 2019
Breakfast Briefing - August 2019
 
Exeter - Academy Update Seminar 2019
Exeter - Academy Update Seminar 2019Exeter - Academy Update Seminar 2019
Exeter - Academy Update Seminar 2019
 
Bodmin - Academy Update Seminar 2019
Bodmin - Academy Update Seminar 2019Bodmin - Academy Update Seminar 2019
Bodmin - Academy Update Seminar 2019
 
London Conference 2019
London Conference 2019London Conference 2019
London Conference 2019
 

Recently uploaded

Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Anamaria Contreras
 
Darshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfDarshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfShashank Mehta
 
Jewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreJewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreNZSG
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...SOFTTECHHUB
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environmentelijahj01012
 
20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdfChris Skinner
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckHajeJanKamps
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsIndiaMART InterMESH Limited
 
digital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingdigital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingrajputmeenakshi733
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryEffective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryWhittensFineJewelry1
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdfChris Skinner
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...Operational Excellence Consulting
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024Adnet Communications
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxRakhi Bazaar
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFChandresh Chudasama
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...ssuserf63bd7
 

Recently uploaded (20)

Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.
 
Darshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfDarshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdf
 
Jewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreJewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource Centre
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environment
 
20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deck
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan Dynamics
 
digital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingdigital marketing , introduction of digital marketing
digital marketing , introduction of digital marketing
 
WAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdfWAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdf
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryEffective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDF
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
 

Cyber Security breakfast briefing - Exeter

  • 1. December 2017 Cyber security breakfast briefing
  • 2. Glenn Nicol, Corporate Partner Chair’s welcome
  • 4. Programme GDPR – Ben Travers, Stephens Scown LLP GDPR tools – Russell Cosway, Gydeline Cyber Essentials / IASME accreditation – Richard Wilding, PKF Francis Clark Cyber insurance – Jonathan Cox, Paveys
  • 6. GDPR Tools Russell Cosway – December 2017
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 13. • Date/Who/DPO • Process Name/Purpose • Legal Basis • Data Source/Locations • Who is impacted? • Description • How is data deleted? • What risks/mitigations • Date of review Data Protection Impact Assessment (DPIA)
  • 14.
  • 15. What does Gydeline do? • Checks for compliance against every word of the regulation • Enables proof of accountability • Changes as the regulation changes • Identifies specific actions • Makes GDPR simpler to understand
  • 16. Links • gydeline.com/dpia • gydeline.com/datamap FCDEC2017 – 25% discount on lifetime of subscription
  • 17.
  • 19. Richard Wilding, Head of Cyber Services Cyber Essentials / IASME accreditation
  • 20. 20 Why PKF Francis Clark • Trusted advisers – experienced auditors • We offer assurance not consultancy  Offer assurance to set well known standards approved by Government and NCSC  Cyber Essentials and IASME are constantly updated and monitored for quality control • Some additional services can be offered
  • 21. www.website.com General Data Protection Regulations 2018 • GDPR has 2 main sides to it • The two main areas of GDPR that organisations need to look at  Data subject rights and the need for ‘informed consent’  Good standards of information security • Cyber Essentials is a great first step • IASME demonstrates a wider governance system for data controls
  • 22. Cyber Essentials • Self-assessment questionnaire for the company to complete • Covers 5 key areas/71 questions • We provide upfront assistance (1 days needed) to support how to complete and progress • It is submitted via a secure portal for us to assess • Basic vulnerability scan performed • Assessor feedback provided • Once successful can use the Cyber Essentials logo for 12m • Limited insurance provided/can help reduce further cyber insurance
  • 23. Cyber Essentials PLUS • We audit and test the 5 key control areas • Includes detailed vulnerability and limited penetration testing • A report is then issued • Once successful can use the Cyber Essentials PLUS logo for 12m • Can help to reduce cyber insurance further
  • 24. IASME (Information Assurance for Small and Medium Enterprises) • IASME – two levels standard and gold • 180 questions (including those in Cyber Essentials) • Includes GDPR specific questions • Akin to ISO27001 • A report is then issued • Once successful can use the IASME logo for 12m
  • 25. 25 Next steps • See brochure in pack • Complete form • Chat with us after this event • Contact your PKF Francis Clark adviser or e- mail: cyber@pkf-francislark.co.uk
  • 26. Disclaimer & copyright c) copyright PKF Francis Clark, 2017 You shall not copy, make available, retransmit, reproduce, sell, disseminate, separate, licence, distribute, store electronically, publish, broadcast or otherwise circulate either within your business or for public or commercial purposes any of (or any part of) these materials and / or any services provided by PKF Francis Clark in any format whatsoever unless you have obtained prior written consent from PKF Francis Clark to do so and entered into a licence. To the maximum extent permitted by applicable law PKF Francis Clark excludes all representations, warranties and conditions (including, without limitation, the conditions implied by law) in respect of these materials and /or any services provided by PKF Francis Clark. These materials and /or any services provided by PKF Francis Clark are designed solely for the benefit of delegates of PKF Francis Clark. The content of these materials and / or any services provided by PKF Francis Clark does not constitute advice and whilst PKF Francis Clark endeavours to ensure that the materials and / or any services provided by PKF Francis Clark are correct, we do not warrant the completeness or accuracy of the materials and /or any services provided by PKF Francis Clark; nor do we commit to ensuring that these materials and / or any services provided by PKF Francis Clark are up- to-date or error or omission-free. Where indicated, these materials are subject to Crown copyright protection. Re-use of any such Crown copyright-protected material is subject to current law and related regulations on the re-use of Crown copyright extracts in England and Wales. These materials and / or any services provided by PKF Francis Clark are subject to our terms and conditions of business as amended from time to time, a copy of which is available on request. Our liability is limited and to the maximum extent permitted under applicable law PKF Francis Clark will not be liable for any direct, indirect or consequential loss or damage arising in connection with these materials and / or any services provided by PKF Francis Clark, whether arising in tort, contract, or otherwise, including, without limitation, any loss of profit, contracts, business, goodwill, data, income or revenue. Please note however, that our liability for fraud, for death or personal injury caused by our negligence, or for any other liability is not excluded or limited. PKF Francis Clark is a trading name of Francis Clark LLP. Francis Clark LLP is a limited liability partnership, registered in England and Wales with registered number OC349116. The registered office is Sigma House, Oak View Close, Edginswell Park, Torquay TQ2 7FF where a list of members is available for inspection and at www.pkf-francisclark.co.uk. The term ‘Partner’ is used to refer to a member of Francis Clark LLP or to an employee. Registered to carry on audit work in the UK and Ireland, regulated for a range of investment business activities and licensed to carry out reserved legal activity of non-contentious probate in England and Wales by the Institute of Chartered Accountants in England and Wales. Partners acting as insolvency practitioners are licensed in the UK by the Institute of Chartered Accountants in England and Wales. A partner appointed as Administrator or Administrative Receiver acts only as agent of the insolvent entity and without personal liability. Francis Clark LLP is a member firm of the PKF International Limited network of legally independent firms and does not accept responsibility or liability for the actions or inactions on the part of any other individual member firm or firms.
  • 28.  Insurance Cover – Cyber &/or Crime  The Threats  Why Do Businesses Need Cyber Insurance?  Claims  Reducing risk  Q&A
  • 29. Cyber &/or Crime Cyber Liability Insurance provides businesses with protection against financial loss resulting from the loss of personal and/or corporate data. Cover addresses the first and third-party risks ranging from the loss of a single laptop or file to the hacking of a companies website or network. Security Breach Data Breach Operational failure Main policy triggers: Crime Insurance provides businesses with protection against financial loss resulting from criminal or fraudulent taking, obtaining or appropriation of money, securities, funds or property.
  • 30. The ThreatsTHREATS NEGLIGENT EMPLOEE Send wrong data Loss of hardware (mobile theft) Victim of Phishing, Vishing OUTSIDERS Denial of Service Theft of Data Hactivism Crime Syndicate Denial of Service Theft of Data Government Agencies Industrial Espionage Denial of Service Malware Extortion Shut Down Infrastructure Advanced Persistent Threats Credit / Banking details Government ID Personally Identifiable Info Protected Health Info Corporate Information SOCIAL NETWORKING Twitter Facebook LinkedIn ROGUE EMPLOYEE Physical Theft Steal Data Competitive advantage Sell to criminals Extortion VENDORS Cloud Data Centers Outside Providers Network Interruption Theft of Data due to Security Failures Unauthorized Access of Data Loss of Data Network Interruption Physical Theft of Servers Theft of Data due to Security Failure Network Interruption Backdoor Intrusion Employees Negligent Employees Rogue Employees
  • 31. It’s all about Balance Sheet Protection…. • First Response Costs • TP Liability • Fines • Loss of Revenue • Brand / Reputational Damage • Loss of Intellectual Property • Contractual Liability • Share Price
  • 32. Cyber claims received by AIG EMEA (2013- 2016) By industry * Construction, Food & Beverage, Information Services, Other Services, Transportation, Agriculture & Fisheries, Energy and Real Estate
  • 33. By type Cyber claims received by AIG EMEA (2013- 2016)
  • 34. Claims Examples Cloud Service provider accidentally de commissioned live server (PI claim?) Confidential Waste Bins stolen Older server handed to bogus courier Legal papers (EPL issues) sent to wrong person Details of delayed products and refund option sent to 250 people in error IT consultant providing HR services attempted hack Insurance brokers Krypto locked
  • 35. Claims Examples A fraudster hacked into the company’s email system to gain information about its organisational structure. During telephone calls with a member of staff in the finance department the fraudster mimicked the voice of the company CEO. It was strongly suspected that the fraudsters listened to his voice on a webcast and had practiced it to perfection. The requested payments were supposedly for a confidential acquisition that only senior management knew about and the fraudster provided forged invoices containing forged signatures to the member of staff contacted. Hacking & Impersonation
  • 36. Reducing the risk to your business • Ensure your software is up to date and that you have the latest anti-virus software installed as updates are released frequently to help combat the most recent cyber threats. • Staff training is essential. Educate your employees on how to recognise suspicious emails and browse the internet safely. Cyber awareness should be included in part of your induction process and revisited in regular refresher sessions. • Ensure you have an incident response plan in place which you can call upon in the event of a breach or interruption. This should include technical measures that enable the recovery of systems, operations and data, and a communication strategy if necessary. • If you are looking for additional advice and guidance on prevention, we would recommend the Cyber Essentials website, a government-backed cyber security certification scheme that sets out a good baseline of security suitable for all organisations across all sectors. Reducing Risk Identify Analyse Control Transfer
  • 38. Glenn Nicol, Corporate Partner Chair’s close

Editor's Notes

  1. Organisations need to realise that GDPR is here and waiting is not longer an option. The key message is to get started.
  2. GDPR applies to most organisations and the approach to it needs thinking about. So get started.
  3. A first step is to assess where you are.
  4. Take action, whether on security, consent or breach. Get started.
  5. Take action and follow advice of the regulator. Having effective documentation is a good start.
  6. We have heard about the threats from hackers and the challenges presented by GDPR. There are many consultants about and choosing a good consultant can pose significant challenges. (I can mention C3IA here to keep them happy) Choosing the assurance route allows boards to measure the organisations security and compliance against set standards which are well recognised. In fact these are mandatory for most Government contracts. These standards are regularly updated to ensure that the latest threats and best practice are taken into account. Later I will briefly detail the 3 standards but we can also offer additional ‘bolt on’ services such as training and vulnerability scanning.
  7. GDPR is due in May 2018 which does not leave a lot of time for business to put the required controls in place. Everyone who collects data is required to be compliant. This applies to both controllers and processors who, under the new rules, have much the same responsibilities. The rights of the data subjects are significantly enhanced and you will need a data retention policy as well as privacy statements and data privacy impact assessments. A lawyer is best placed to advise in the remit. Other areas for a lawyer are those revolving around explicit permission from data subjects with regard to receiving marketing information. GDPR also mandates good data security revolving around Confidentiality, Integrity and Availability. Confidentiality No one should have access to data they do not need to see in the course of their normal job. Data should be adequately protected from being breached by outsiders. Integrity. You should be able to show that the data is correct and has not been unlawfully manipulated in any way. Availability. Your systems need to be robust to ensure that the data is available when required. Cyber Essentials is a good first step and starts to address data security. It can help mitigate fines from the ICO should you suffer a breach. The IASME governance standard adds a number of topics to Cyber Essentials which will be required for GDPR compliance, such as assessing business risks, training staff, dealing with incidents and handling operational issues.