Tackling data security risks under the GDPR

By Lancashire Business View

09 May 2018

andrew-stellakis-q2q-1000x500.jpg
By Andrew Stellakis, managing director, Q2Q IT

It’s been a dot on the horizon for months, but now the 25 May is looming and the GDPR is well and truly in sight, data security has never been so important for SMEs.

The level of scrutiny surrounding cyber security in the media means that a data breach could cause significant reputational damage – a mere glance at the headlines reveals companies being named and shamed for failing to protect sensitive information relating to customers or employees.

And under the GDPR, the consequences for such an error will be even more severe. When it comes to financial penalties, for instance, a data breach could result in fines as high as £17m or 4 per cent of global turnover – whichever is more.

Of course, for smaller businesses with limited time, budgets and human resources, implementing Fort Knox levels of defence isn’t as achievable as for larger corporations. But when it comes to mitigating risks and ensuring that personal data is effectively protected, there are a number of measures that SMEs can take.

Firstly, it’s crucial for companies to understand what sensitive information they hold, the risks out there and the rules governing data processing under the GDPR. It’s only by identifying existing gaps in defences that these can be filled.

Increasing awareness of these issues amongst all employees is essential – an SME’s workforce can either be its most effective shield or biggest vulnerability in the data security battle, so team training is vital.

The security principle of the legislation rules that “appropriate technical and organisational measures” must be taken to protect data.

So, when it comes to guarding against external threats, companies should ensure that robust processes such as file encryption and two-factor authentication are implemented, all software and hardware is regularly updated and cyber-security defences are installed – including firewalls and anti-malware.

SMEs with a Bring Your Own Device (BYOD) approach should be especially vigilant, and introduce a policy to ensure that any laptop, tablet or smartphone used to access business data is adequately protected.

Permissions should also be limited, to ensure only those who need file access to fulfil their role are granted it. Similarly, it’s important for companies to actively minimise the volume of personal data that they store and process – the GDPR rules this must be “limited to what is necessary”, so irrelevant information should not be held for the sake of it.

In the event that a breach does occur, having an effective back-up and data recovery procedure in place is invaluable.

Duplicate versions should be stored off-site or via the cloud and adequately protected, so that data can be restored if the primary files are compromised. For added peace of mind, enlisting an experienced IT provider can also be a cost-effective solution for companies that don’t have the in-house capacity or expertise to tackle data security effectively.

Latest news

1

GCAP ‘set for £6bn funding boost’ Tempest new

GCAP ‘set for £6bn funding boost’

19 May 2026

2

Anti-drone weapon tested in Lancashire is deployed on Middle East Operations BAE Systems tests

Anti-drone weapon tested in Lancashire is deployed on Middle East Operations

19 May 2026

3

Preston haircare brand FYC secures Alexandra Mardell partnership Alexandra Mardell

Preston haircare brand FYC secures Alexandra Mardell partnership

19 May 2026

4

Barnfield celebrates 50 years of building Tim Webber from Barnfield Construction

Barnfield celebrates 50 years of building

19 May 2026

5

Leaders launch multi-billion pound investment opportunities Stephen Atkinson

Leaders launch multi-billion pound investment opportunities

18 May 2026

Background image for hub sign up block

LBV Hub

Leverage Lancashire Business View platforms

Post your news
Post your events
Post your offers
Build your network
Improve your SEO
Gain coverage in the magazine
Sign-up
Events
LBV128 May/June Magazine Networking Event
Canva - Mag Launch
Networking
19 May 2026

LBV128 May/June Magazine Networking Event

Colne Market Hall, Lancashire, BB8 0HS

08:30 - 10:30

Funding Summit
Funding Logo Canva Mid
Summit
17 Jun 2026

Funding Summit

Village Hotel Blackpool

08:30 - 11:00

LBV129 July/August Magazine Networking Event
Nov/Dec Networking Event
Networking
16 Jul 2026

LBV129 July/August Magazine Networking Event

Brysdales, Britannia Buildings Drumhead Road, Chorley, PR6 7BX

16:00 - 18:00

LBV130 September/October Magazine Networking Event
Jan/Feb Networking Event - Entrance
Networking
17 Sep 2026

LBV130 September/October Magazine Networking Event

The Beehive Blackburn, Shadsworth Business Park, BB1 2Q

08:30 - 10:30

LBV131 November/December Magazine Networking Event
Jan/ Feb Networking Event - Talking
Networking
19 Nov 2026

LBV131 November/December Magazine Networking Event

Lancashire

08:30 - 10:30

Research and Knowledge Exchange Festival 2026
Spark 2026 newsletter v3-5 (1).png.png
LBV Hub Seminars
18 May 2026 - 22 May 2026

Research and Knowledge Exchange Festival 2026

University of Lancashire, Preston, PR1 2HE

10:00 - 20:00

U35 Networking Event
Logo.jpg.jpg
LBV Hub Networking
20 May 2026

U35 Networking Event

The Royal Hotel & Bar, Lancaster, LA1 1YD

17:30 - 19:00

How to handle an underperforming employee
Logo.jpg.jpg
LBV Hub Seminars
20 May 2026

How to handle an underperforming employee

The Longlands Hotel, Carnforth, LA6 1JH

08:00 - 10:00

Culture, Community & Commerce in the City # 1 - Northern Dough Co x WASH Studio
8.png.png
LBV Hub Networking
20 May 2026

Culture, Community & Commerce in the City # 1 - Northern Dough Co x WASH Studio

Society1, Coworking Space, Preston, PR1 3LT

18:00 - 20:30

Getting ahead of risk: Managing cash flow, costs, funding and supply chains in uncertain times
Webinar invite (3).png.png
LBV Hub Webinar
20 May 2026

Getting ahead of risk: Managing cash flow, costs, funding and supply chains in uncertain times

Online - teams, N/A, N/A

09:30 - 11:00

Preston Freelancer Meet-Up: May
LBV Hub Networking
21 May 2026

Preston Freelancer Meet-Up: May

Society1, Coworking Space, Preston, PR13LT

10:00 - 12:00

Why digital accessibility is crucial for your business
EXP-Webinar-LBV-Hub.png.png
LBV Hub Webinar
21 May 2026

Why digital accessibility is crucial for your business

Online, Microsoft Teams, Webinar

12:30 - 13:00

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more LBV124 Online Graphic
Subscribe now

Weekly news bulletin