{"id":90100,"date":"2019-11-05T09:00:55","date_gmt":"2019-11-05T17:00:55","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\/?p=90100"},"modified":"2023-05-15T23:28:55","modified_gmt":"2023-05-16T06:28:55","slug":"balance-compliance-security-vodafone","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/11\/05\/balance-compliance-security-vodafone\/","title":{"rendered":"Thinking about the balance between compliance and security"},"content":{"rendered":"

Today, many organizations still struggle to adhere to General Data Protection Regulation (GDPR) mandates even though this landmark regulation took effect nearly two years ago. A key learning for some: being compliant does not always mean you are secure. Shifting privacy regulations, combined with limited resources like budgets and talent shortages, add to today\u2019s business complexities. I hear this concern time and again as I travel around the world meeting with our customers to share how Microsoft can empower organizations successfully through these challenges.<\/p>\n

Most recently, I sat down with Emma Smith, Global Security Director at Vodafone Group to talk about their own best practices when navigating the regulatory environment. Vodafone Group is a global company with mobile operations in 24 countries and partnerships that extend to 42 more. The company also operates fixed broadband operations in 19 markets, with about 700 million customers. This global reach means they must protect a significant amount of data while adhering to multiple requirements.<\/p>\n

Emma and her team have put a lot of time and effort into the strategies and tactics that keep Vodafone and its customers compliant no matter where they are in the world. They\u2019ve learned a lot in this process, and she shared these learnings with me as we discussed the need for organizations to be both secure and compliant, in order to best serve our customers and maintain their trust. You can watch our conversation and hear more in our CISO Spotlight episode<\/a>.<\/p>\n

Cybersecurity enables privacy compliance<\/h3>\n

As you work to balance compliance with security keep in mind that, as Emma said, \u201cThere is no privacy without security.\u201d If you have separate teams for privacy and security, it\u2019s important that they\u2019re strategically aligned. People only use technology and services they trust, which is why privacy and security go hand in hand.<\/p>\n

Vodafone did a security and privacy assessment across all their big data stores to understand where the high-risk data lives and how to protect it. They were then able to implement the same controls for privacy and security. It\u2019s also important to recognize that you will never be immune from an attack, but you can reduce the damage.<\/p>\n

Emma offered three recommendations for balancing security with privacy compliance:<\/p>\n