Half of small businesses surveyed have no policy in place for storing and disposing of confidential data.
Australian businesses are facing significant challenges in regards to information security, a new report has found.
Information security company Shred-it Australia’s annual study has identified a disconnect between consumers’ expectations of how service providers should manage their personal information securely, and the level of preparedness of these organisations.
The 2018 State of the Industry Report analyses information and data security risks currently threatening Australian enterprises and small businesses and includes survey findings from the Shred-it Security Tracker.
In light of highly publicised consumer data breaches or mishandling of personal information, such as Cambridge Analytica, the public’s concerns about privacy are growing, particularly in key industries such as banking, mobile or internet and health care.
Shred-it Australia’s Country Manager Tom Bell said, “In this environment, business leaders need to reassess how they protect their customers and organisation from potential security risks and breaches.”
Increasingly complex regulatory environment creating training needs
The regulatory environment for consumer data is increasingly complex, with mandatory reporting of breaches under the Notifiable Data Breaches (NDB) and the new EU General Data Protection Regulations (GDPR) framework. The likelihood of eroded customer and community trust resulting from a breach of privacy information is a major business risk.
Yet, according to the report only 50 percent of all respondents have a strong understanding of their legislative requirements. Alarmingly, 50 percent of respondents have no policy at all for storing and disposing of confidential data on electronic devices. Only 32 percent have a policy that is strictly adhered to.
“The research offers a wake-up call to organisations responsible for information security,” concluded Mr Bell. “Businesses need to act now to put in place the policies, practices, training and above all, a culture, to deliver on information security. Their reputation, trust among customers and ultimately, their business success, may depend on it.”
Business.gov.au has a series of online webinars on cyber security for business as part of the Australian Government’s flagship initiative, The Entrepreneurs' Programme.
More from The Business Conversation:
Shipwreck Gourmet Bakery: an opportunity to rise above the rest
The Sydney restaurant chain changing lives through true inclusion
Hutchisons Nursery: award-winning 100 year old South Australian business for sale