When GDPR comes into force in May 2018, your business will be at risk of action from the ICO if you suffer a breach

You will have probably already heard a lot about the General Data Protection Regulation (GDPR) in the media and with less than 9 months until businesses are required to comply, SMEs need to be planning ahead now.

Although it may seem like another onerous addition to the list of responsibilities for the business owner, this is an important one to take note of.In our recent research, we found that only fifteen per cent of SMEs are concerned about regulatory action as a result of cyber crime.

However, with the prospect of large fines and mandatory breach notifications, we can expect to see this shoot up the agenda when the regulations hit next year. The challenges of a short notification window mean that not only may you face a fine if you experience a breach, but you will also be required to notify your customers that a cyber incident has taken place.

You will only have 72 hours to analyse the potential damage before making a public declaration. This short window to notify is the real crux of the issue. so it’s important to have an incident response plan in place should you experience a breach.

Without a plan in place, three days is an incredibly short amount of time to employ the necessary parties following an incident. In some cases, not only will forensic investigators need to be working around the clock to determine the extent of the issue, but you may need to employ lawyers and get public relations advice to figure out how to most effectively communicate this to customers. In short, what is already a headache will become even more pressurised, and small businesses that are already short on resources will be in serious trouble.

If you are worried about where to start or how to become compliant speak to one of our GDPR specialist consultants who can provide you with advice, on data protection, what to audit, which policies need defining, staff training and ongoing support to help your organisation stay compliant.