Posts

Showing posts with the label risk

Data Breach Guide

A data breach occurs when an incident exposes protected information such as personal data. The breach may involve loss or theft of a customer or employee list, an unencrypted hard drive, lost thumb drive, exposed attendee list, which may be containing names, credit card numbers, national identification/passport numbers, personal images or videos, personal health information, emails, NHIF or NSSF numbers. A data breach may be intentional or accidental. A threat actor may hack your data bases or an employee may accidentally expose that information. The concern about cyber attacks is widespread, which can have a crippling impact on businesses, but the main cause of breaches remains non-cyber incidents and human error. The stakes are high if you suffer a data breach. Hundreds of data reaches have been reported around the world. In 2019, Techweez reported a Safaricom Ltd data breach perpetrated by an employee who downloaded and offered a third party personal data affecting 11.5m customers. ...

Cultivating Ethical Cultures through Technology: The Case for a Policy Management System

Image
  Digitizing policy management can help an organisation achieve culture change through accountability. A digital system provides a centralized, automated, and transparent approach to policy and procedures management that is very supportive of accountability frameworks.  Here are some ways to achieve accountability using a digital policy management system: 1. Centralized policy management : A digital system allows an organization to store all its policies and procedures in a single, central location.  This ensures that all employees have access to the most up-to-date policies and procedures, reducing the risk of non-compliance due to outdated or inaccessible policies. 2. Automated policy updates and notifications : A digital policy management system can automatically update policies and procedures and notify employees when changes are made.  This ensures that employees are always aware of changes to policies and procedures, reducing the risk of non-complianc...

Three Things to Consider when Setting Up Data Compliance

Image
This article seeks to highlight three items that we consider to be important when it comes to #data compliance. It is based on the work that we are doing to support organisations implement or strengthen data compliance systems.  1. Apply the age-old #compliance frameworks when implementing data compliance.  The framework is tried and tested and provides a useful implementation framework that covers: - policies and procedures (including code of conduct and #ethics ), - effective #communication (hotline), - training, - compliance office (outsourced or in-house), - #audit and monitoring, - consequence/accountability management, and - third party transactions. You will note that registration with the Office of the Data Protection Commissioner (ODPC) is not listed as an element on its own. Registration is a necessary but not sufficient aspect of compliance. In fact, we consider registration, particularly the declarations made in that process, as exposing  organisations ...