Breaches of information security are consistently one of the top reasons for regulator enforcement action, with fines for security breaches usually higher than for other types of data protection law breaches. The average global data breach cost now stands at over $4 million, and the threat landscape has evolved significantly, with criminal organisations forming complex networks of specialist groups operating under ransomware-as-a-service models.
Compliance professionals need to be suitably empowered with knowledge of the regulatory landscape to help their organisations mitigate data security risks and deal with data breaches effectively. It is also useful for compliance professionals to be aware of common threat types and vulnerabilities and have a basic knowledge of cybersecurity terminology, to facilitate effective communications with IT forensics experts.
This session is prepared specifically for information law professionals who are looking to understand the technical, regulatory and practical aspects of cybersecurity. The session addresses:
- common attack vectors, including ransomware and denial-of-service attacks
- authentication vulnerabilities and controls, including password security issues, hashing and salting techniques, and multi-factor authentication
- supply chain security risks and vulnerabilities
- the UK regulatory landscape, including the UK GDPR, PECR, NIS Regulations and the new Cybersecurity and Resilience Bill
- the EU regulatory landscape, including NIS 2, DORA and the Cyber Resilience Act
- Managing the personal impact of a serious data breach, including stress management and maintaining optimal performance under pressure
- A comprehensive programme for cyber preparedness, including board briefings, risk assessments, incident response plans, third-party controls, and cyber sims
- Breach response and recovery strategies, including incident discovery, vendor engagement, regulator engagement, communications planning, and privilege preservation
- AI and its role in both cyber threats and defence
- Practical case studies including a data breach scenario from initial alert through to regulatory fallout and compensation claims
No technical knowledge is required in order to attend this session. A basic working knowledge of data protection legal requirements would be useful. Delegates with limited data protection knowledge may find it helpful to attend Data Protection Essential Knowledge Level 1 before attending this training course.
“The cybersecurity course was well-structured and highly informative. It provided practical insights into key concepts and up-to-date knowledge on current threats and defences. The hands-on exercises were particularly useful in solidifying my understanding, making the content engaging and applicable to real-world scenarios. I highly recommend it to anyone looking to enhance their cybersecurity skills.”