Tackling data security risks under the GDPR

By Lancashire Business View

09 May 2018

andrew-stellakis-q2q-1000x500.jpg
By Andrew Stellakis, managing director, Q2Q IT

It’s been a dot on the horizon for months, but now the 25 May is looming and the GDPR is well and truly in sight, data security has never been so important for SMEs.

The level of scrutiny surrounding cyber security in the media means that a data breach could cause significant reputational damage – a mere glance at the headlines reveals companies being named and shamed for failing to protect sensitive information relating to customers or employees.

And under the GDPR, the consequences for such an error will be even more severe. When it comes to financial penalties, for instance, a data breach could result in fines as high as £17m or 4 per cent of global turnover – whichever is more.

Of course, for smaller businesses with limited time, budgets and human resources, implementing Fort Knox levels of defence isn’t as achievable as for larger corporations. But when it comes to mitigating risks and ensuring that personal data is effectively protected, there are a number of measures that SMEs can take.

Firstly, it’s crucial for companies to understand what sensitive information they hold, the risks out there and the rules governing data processing under the GDPR. It’s only by identifying existing gaps in defences that these can be filled.

Increasing awareness of these issues amongst all employees is essential – an SME’s workforce can either be its most effective shield or biggest vulnerability in the data security battle, so team training is vital.

The security principle of the legislation rules that “appropriate technical and organisational measures” must be taken to protect data.

So, when it comes to guarding against external threats, companies should ensure that robust processes such as file encryption and two-factor authentication are implemented, all software and hardware is regularly updated and cyber-security defences are installed – including firewalls and anti-malware.

SMEs with a Bring Your Own Device (BYOD) approach should be especially vigilant, and introduce a policy to ensure that any laptop, tablet or smartphone used to access business data is adequately protected.

Permissions should also be limited, to ensure only those who need file access to fulfil their role are granted it. Similarly, it’s important for companies to actively minimise the volume of personal data that they store and process – the GDPR rules this must be “limited to what is necessary”, so irrelevant information should not be held for the sake of it.

In the event that a breach does occur, having an effective back-up and data recovery procedure in place is invaluable.

Duplicate versions should be stored off-site or via the cloud and adequately protected, so that data can be restored if the primary files are compromised. For added peace of mind, enlisting an experienced IT provider can also be a cost-effective solution for companies that don’t have the in-house capacity or expertise to tackle data security effectively.

Latest news

1

£453.5m investment to deliver advanced new radar for Royal Air Force Typhoons Typhoon aircraft

£453.5m investment to deliver advanced new radar for Royal Air Force Typhoons

22 Jan 2026

2

Rose departs EG ahead of US IPO EG

Rose departs EG ahead of US IPO

22 Jan 2026

3

Eric Wright Charitable Trust unveils six-year charitable giving strategy Previous funded project supporting young people

Eric Wright Charitable Trust unveils six-year charitable giving strategy

21 Jan 2026

4

IN4 Group acquires Midlands apprenticeship provider ATL Mo Isap, founder and CEO of IN4 Group; Andy Beaden, co-founder and Chairman of IN4 Group; and the founders of GMP Recruitment James Cronin and Mike Pincott.

IN4 Group acquires Midlands apprenticeship provider ATL

21 Jan 2026

5

‘Dithering’ on defence spending puts thousands of jobs at risk, union warns Typhoon production Warton

‘Dithering’ on defence spending puts thousands of jobs at risk, union warns

20 Jan 2026

Background image for hub sign up block

LBV Hub

Leverage Lancashire Business View platforms

Post your news
Post your events
Post your offers
Build your network
Improve your SEO
Gain coverage in the magazine
Sign-up
Events
CMI Level 5 Management and Leadership Course
UCLanAerialCampus.jpg.jpg
LBV Hub Seminars
21 Feb 2025 - 21 Feb 2026

CMI Level 5 Management and Leadership Course

Preston Campus, Preston , PR1 2HE

09:00 - 17:00

RISE - Lancashire's unique leadership programme for women
thumbnail_Emma Weston Illustration WENDY BOWERS RISE Illustrstion.jpg.jpg
LBV Hub Seminars
22 Oct 2025 - 18 Mar 2026

RISE - Lancashire's unique leadership programme for women

East Lancashire Chamber of Commerce, Clayton le Moors, BB5 5JR

09:30 - 15:30

Employment Rights Act Update for Businesses: What Employers Need to Know for 2026
Employment Rights Act Update for Businesses.png.png
LBV Hub Webinar
27 Jan 2026 - 27 Jan 2026

Employment Rights Act Update for Businesses: What Employers Need to Know for 2026

Online via Zoom, Preston, PR5 6AW

09:30 - 10:30

The Marketing Meetup: Lancashire (January)
LBV Hub Networking
27 Jan 2026

The Marketing Meetup: Lancashire (January)

Six Connections, Slater Terrace, Burnley, BB11 4SA

18:00 - 20:00

Chamber Breakfast – February
Logo.jpg.jpg
LBV Hub Networking
03 Feb 2026 - 03 Feb 2026

Chamber Breakfast – February

The Olive Branch, Lancaster, LA1 4XQ

08:00 - 10:00

Business Breakfast Networking Event
LBV Hub Networking
04 Feb 2026 - 04 Feb 2026

Business Breakfast Networking Event

Media Factory, University of Lancashire, Preston, PR1 2HE

08:00 - 10:30

E-commerce in 2026: From stores to systems
PTC banner Feb 26.jpg.jpg
LBV Hub Networking
10 Feb 2026 - 10 Feb 2026

E-commerce in 2026: From stores to systems

Society1, Coworking Space, Preston, PR1 3LT

18:00 - 19:30

Degree apprenticeship information sessions for businesses
student centre entrance.jfif.jpg
LBV Hub Webinar
10 Feb 2026 - 13 Feb 2026

Degree apprenticeship information sessions for businesses

University of Lancashire, Virtual event, -

10:00 - 09:30

Future Forward Business and Skills Summit
Future Forward Business & Skills Summit
LBV Hub Networking
20 Feb 2026

Future Forward Business and Skills Summit

Lancashire Energy HQ , Blackpool, FY4 2QS

08:00 - 11:00

Tech without the turmoil: How Finance Leaders can drive smarter digital decisions
MHA-BTI Logo_black (002).jpg.jpg
LBV Hub Networking
05 Mar 2026 - 27 Dec 2025

Tech without the turmoil: How Finance Leaders can drive smarter digital decisions

Farington Lodge Hotel, Stanifield Lane, Farington, Preston, PR25 4QR

08:00 - 10:00

Payroll Update 2026 Samlesbury Hall
payroll.jpg.jpg
LBV Hub Seminars
06 Mar 2026 - 06 Mar 2026

Payroll Update 2026 Samlesbury Hall

Samlesbury Hall, Preston, PR5 0UP

08:00 - 10:00

Payroll Update 2026 Red Hall Hotel
Payroll calculator new.jpg.jpg
LBV Hub Seminars
13 Mar 2026 - 13 Mar 2026

Payroll Update 2026 Red Hall Hotel

Red Hall Hotel, Bury, BL9 5NA

08:00 - 10:00

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more LBV124 Online Graphic
Subscribe now

Weekly news bulletin