• About
  • Subscribe
  • Contact
Wednesday, May 7, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Resources Blogs

Readying the enterprise's data protection strategy in 2023

allantan by allantan
January 6, 2023

Readying the enterprise's data protection strategy in 2023

Share on FacebookShare on Twitter

FutureCIO has covered data protection for some time now. In 2020, Gartner predicted that by 2023 65% of the world’s population will have its personal data covered under modern privacy regulations, up from 10% in 2020.

IDC noted that the growing prevalence of cloud-based services means greater volumes of data are being collected and analysed. At the same time, as cyber threats increase in number and sophistication, consumers are more aware of and sensitive to data breaches.

While rules and regulations regarding where and how data is stored and transmitted are changing, businesses recognise that their customers cannot tolerate disruptions to the digital infrastructures that undergird their work and daily lives, noted the analyst.

In this series on Readying the enterprise's data protection strategy in 2023, we look at how data protection is evolving in Asia Pacific and around the world.

Describe the state of data protection in 2022. How has it evolved over the last 5 years?

David Lenz

“Data privacy and protection rules have become far more complicated as we become more interconnected globally. Much of companies’ data today resides in the cloud, which means they have a globally distributed data infrastructure.”

David Lenz

“Both businesses and public cloud providers need a firm grasp on compliance and data sovereignty issues and a better understanding of what is in the petabytes of data they’re storing and the regulations around every element of that data,” said David Lenz, vice president, Asia Pacific at Arcserve.

For his part, Dirk de Vos, APAC channels director with GitLab, voiced out that to some degree - business leaders have long known that protecting data is critical. But what’s changed over the last five years is that security is now top of mind for consumers as well, and that is putting more pressure and scrutiny on IT teams.

Dirk de Vos

“You only have to follow the news to see how important data protection has now become and the penalty for not securing your customers' data. By now, not just CSOs but also every CIO should have changed the way they think about customer data - looking not just at its value to the business, but what value it might hold to hackers as well.”

Dirk de Vos

He added that the rapid digitisation brought on by Covid has also had huge ramifications for data protection practices as speed to market has become a key differentiator. GitLab’s 2022 DevSecOps Survey found that 60% of developers globally are now releasing code faster than ever before. This is why DevSecOps adoption is fast growing.

Related:  PodChats for FutureCIO: Strategies for more effective real-time security

De Vos said it is imperative to secure data from the first line of code to the APIs that are connecting to third-party tools, AKA data protection across the entire software development life cycle (SDLC), or risk of brand damage and huge financial penalties.

Grant Orchard, field CTO, Asia Pacific and Japan with HashiCorp observed that over the last five years there has been a big uptick in vendor capabilities providing data protection to customers.

This, however, has not translated into the wide-scale adoption of these technologies and practices.

Grant Orchard

“As an industry, we need to do more to educate the market to drive a focus on protecting data, rather than implementing controls for the infrastructure that data resides on, or within.”

Grant Orchard

He cited the example of a continued approach to encrypting data at rest by encrypting the storage that it resides on. This is helpful for protecting against certain threats but doesn't protect from on-network attacks in the way that field-level encryption or tokenisation does.

Raghu Nandakumara, head of industry solutions at Illumio, observed globally new privacy and cybersecurity requirements. This suggests that the data protection landscape is constantly evolving. He cited the recent Privacy Legislation Amendment Bill to increase penalties for large-scale data breaches to AU$50 million as one example.

Raghu Nandakumara

“The majority of changes we’ve seen over the past five years have been part of a concerted effort to harmonise data protection legislation across the Asia Pacific region. Most countries already have some form of data protection and privacy requirements in place, but we’re increasingly seeing these modelled around the General Data Protection Regulation – the European Union’s data protection and privacy rules.”

Raghu Nandakumara

He opined that the biggest trend observed in data protection is a shift away from consent-based models towards accountability of data processors. The aim is to ensure that data is consistently handled and protected, regardless of jurisdiction.

Related:  Forescout warns against security threats to exposed critical infrastructure 

“We’ve also seen changes to improve consistency around breach notification and reduce the variation in requirements and reporting timeframes across countries. Ultimately, if we can make regulation more consistent across borders then it becomes easier for organisations to focus on building resilience and recovering from data breaches, rather than complying with ever-changing legislation,” he suggested.

Matthew Oostveen, VP & CTO, Asia Pacific & Japan for Pure Storage, said outside of legislation, the cybersecurity landscape is also rapidly evolving, with attacks becoming more advanced and sophisticated. Cybercriminals are finding more innovative means to steal data, and among these, ransomware has emerged as a top security concern as attacks get bigger, bolder, and more costly for organisations.

He noted that in the past, the approach to data protection was to safeguard systems if something happens. He warned that this is insufficient to explain that a reactive approach, where security is merely seen as an afterthought, fails to consider latent threats and cannot detect malicious activities until they have caused significant damage.

Matthew Oostveen

“In today's complex cyber threat landscape, it is critical to discover threats and vulnerabilities early on to stay one step ahead of cybercriminals and prevent attacks from occurring in the first place.”

Matthew Oostveen

“There is an urgency to modernise our approach towards data protection: proactively preventing data storage system failures before they occur through routine upgrades, better technology, and predictive analytics,” concluded Oostveen.

* Editor’s note: Click on the links below for the series

Data protection in 2023’s cloud-first world

Readying the enterprise’s data protection strategy in 2023

Bringing automation into production in 2023

Tags: Arcservedata protectionGartnerGitLabHashiCorpIDCIllumioPure Storage
allantan

allantan

Allan is Group Editor-in-Chief for CXOCIETY writing for FutureIoT, FutureCIO and FutureCFO. He supports content marketing engagements for CXOCIETY clients, as well as moderates senior-level discussions and speaks at events. Previous Roles He served as Group Editor-in-Chief for Questex Asia concurrent to the Regional Content and Strategy Director role. He was the Director of Technology Practice at Hill+Knowlton in Hong Kong and Director of Client Services at EBA Communications. He also served as Marketing Director for Asia at Hitachi Data Systems and served as Country Sales Manager for HDS’ Philippines. Other sales roles include Encore Computer and First International Computer. He was a Senior Industry Analyst at Dataquest (Gartner Group) covering IT Professional Services for Asia-Pacific. He moved to Hong Kong as a Network Specialist and later MIS Manager at Imagineering/Tech Pacific. He holds a Bachelor of Science in Electronics and Communications Engineering degree and is a certified PICK programmer.

No Result
View All Result

Recent Posts

  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses
  • Weak password reuse crisis remains

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl