Cyber security compliance – getting started

Cyber security compliance

Cyber security compliance can seem pretty complicated to outsiders. Our industry is littered with jargon, heavy technical detail and salesmen with supposed silver bullet solutions.  

So where do you start? There are so many options, and depending on who you talk to, you’ll hear arguments for splashing eye-watering amounts of cash in all sorts of directions. 

But there is some happy news. If you haven’t done much to improve your cyber security yet, there are some logical places to begin that are unlikely to break your bank, starting with cyber security compliance.

Are you on top of your cyber security compliance?

It’s likely that there are some things you really need to be doing to improve your cyber security. Otherwise, you could face some negative consequences, like regulatory fines, legal action and losing customer contracts. 

Here are some of the most common areas of cyber security compliance that likely need your attention:

PCI DSS

Whether you store, process or transmit card details, PCI compliance is mandatory. It doesn’t matter whether you take payments in person, over the phone or online – you need to prove that you’re looking after cardholder data (even if you use a third-party payment provider like SagePay or Stripe). 

The requirements change depending on your payment card environment, scope and the number of transactions your business carries out. And it’s worth noting that if you suffer a data breach and you aren’t PCI compliant, you may be subject to fines and liable for the fraud losses incurred against the card data lost.

Find out more about PCI DSS

Cyber Essentials and Cyber Essentials Plus

Cyber Essentials is a requirement if you’re a supplier to the government or larger organisations, but it’s requested more and more now as part of supply chain due diligence. It’s an inexpensive certification that proves you are protected against 80% of cyber attacks. 

The National Cyber Security Centre and the ICO recommend the certifications, and they are a great place to start for any business that wants to up its cyber security game. 

Find out more about Cyber Essentials 

GDPR and ISO 27001 

Everyone took the GDPR pretty seriously when it was first introduced, and leapt into action to ensure they were compliant. But data protection is ongoing. So it’s no far stretch to imagine that processes may have slipped or changed since then, and teams could have fallen back into bad practice. 

One way of ensuring you’ve got 75%-80% of the GDPR covered, is to look at achieving ISO 27001. It’s the leading international standard for information security. It helps you prove that you take it seriously to customers and prospects, while giving you peace of mind that you’re automatically meeting most of your legal requirements for GDPR at the same time. 

Traditionally, ISO 27001 was expensive to implement. However, that changed with the launch of our online ISO 27001 Academy, which delivers a more effective (and cost-effective) implementation.

Find out more about our ISO 27001 Academy 

Ready to get cyber security compliance off your to-do list?

If you want to make a start on cyber security, it probably makes sense to start on areas where you are currently non-compliant. It won’t address everything, but it will be a really good way of improving your situation.

Read more in our guide to compliance and cyber security accreditations

If you like the sound of sorting your cyber security compliance, get in touch using the contact form below.

See our updated Ultimate guide on how to get Cyber Essentials