Privacy laws and regulations like GDPR, HIPAA, and COPPA require organizations to protect customer and employee data, and non-compliance can result in significant fines and reputational damage. A well-structured security program treats regulatory compliance as a core component of risk management and business continuity.
Laws & Regulations Compliance
One of the important parts of a security program is that we're going to be implementing things that help us comply with laws and regulations. Then we can avoid fees, we can avoid fines, we can avoid different issues in the future by complying with these laws and regulations.
A lot of laws and regulations have to do with privacy. Do all of them? No. But a lot of them do. So what is privacy? That's being free from being observed and/or disturbed. Essentially you have rights. You are a consumer. You buy products out there, you buy services out there. There are things that get shipped to your door. There are things that you subscribe to online. There are software as a service companies. There are people collecting data about you all the time.
Now, do you want them to abuse that data? Do you want them to lose that credit card information? Do you want them to have a confidentiality breach and other people see your medical records or your financial records, or be able to get into your bank account? No. The simple answer is that we are trusting other people to do the right thing to protect our data.
Well, for the organizations that we work for, we are holding other people's data. Maybe it's employees' data. Maybe it is data from users who are using our systems. Maybe it's partnerships' employees. In any case, we have some sort of data that will most likely fall under this privacy umbrella, and we need to protect that data. We are stewards of that data. We need to be able to control that data properly and make sure that we're handling it correctly. One of the ways we do this is we have policies and procedures, and we do the training, and we do compliance, and make sure that everybody is following through with what we want them to do.
Ultimately all of this does cost money. And because of that, a lot of times it gets deprioritized by maybe accounting or finance, maybe it's the CEOs, maybe it's the exec teams, maybe it's the board of directors. Often they're looking at the bottom line: are we making a profit? And as you come to them with projects of, hey, we want to create these policies and procedures, they ask, well, is that really what we should be doing? Is that really what we should be investing our money into?
The thing is that businesses are looking at revenue and expenses, and really they want to generate a profit. A business is there for generating profit. Now there are different entities out there, like organizations that are not-for-profit, where this isn't their bottom line. But for a big part of the businesses that are out there, for the most part what they're designed to do is create profit. And the only way that they can create profit is by reducing expenses or increasing revenue.
So really the goal of our security program should do exactly that. If you render it down, that's really what it gets to. But us as technical people, us as security professionals, we're not always thinking of that. We're thinking of the end customer. So we're speaking two different languages from the business, from the people who are in control of the business. Often — I'm not saying always, but often — we're speaking two different languages: the IT people are thinking what is the right thing and the best thing to do, and many times the business is thinking, well, we need to be profitable. And they should be thinking we need to be profitable. So we just need to keep that in mind when we're talking about this.
But this is all to say that a lot of businesses don't put the proper security measures in place to protect their employees' data, to protect their employees' privacy, to protect the customer data and privacy. So what needs to happen there? We need laws and regulations that say no, you as a business are going to protect the privacy of your customers and of your employees, and you have to put this stuff in place. So laws and regulations are necessary, because a lot of businesses won't take the proper steps to protect their customer data, to protect privacy, unless they're forced to by the law and have some stiff penalties.
Here are some of the laws that are out there — these are different laws and regulations from different parts of the country. The US has the US Privacy Act of 1974, and GDPR is another one that's out there that protects the citizens of Europe. And there are some crazy fines with GDPR if you're not doing the right thing.
So us as a business, that's where we start talking to the business and say, well, yes, our goal as a company, as a security program, is that we will either increase revenue or decrease expenses, and this comes in the form of risk. I'm not going to get into all of how this mathematically plays out, but that's essentially what a security program is doing. One of the things is that we need to limit our risk by complying with laws and regulations.
Now we've got this strong argument that we can come and say, no, a security program is necessary, security awareness training is necessary, we need to have these things put into place to make sure that we're complying with the laws and regulations, and that we're going to stay in business here 5 years from now because we are doing the right things and we're not damaging our reputation and we're not racking up fines and that type of thing. So it's important that we comply with these laws and regulations. It's important that these laws and regulations are out there. There are a lot of different types of laws and regulations, but it's important that we have these to make sure that we're following the right thing and that we're doing the right thing.
This is an example of some of those laws and regulations that happen at a global scale, depending on the country or the area that you live in, or the area that your clients are in. These are some of the ones that we might have to apply to.
These are some of the United States laws and regulations. You can see that there are quite a few here that we may need to be concerned with and may need to comply with.
Here are some state specific laws. The point here is that you have the federal laws, but you also have state specific laws, and so there might be many of these that we have to fall under.
There's also sector specific. If we have data from children under 13 in the United States, we've got to comply with COPPA. If there are health records, then we've got to comply with HIPAA. If there's educational records, we've got to comply with FERPA. And there are different — the financial institute has ones where we're processing data. Those aren't necessarily laws and regulations, but they are compliance that we have to do with the credit card companies in order to have the ability to process credit cards. So there are a lot of different sector specific regulations that we might have to fall under to make sure that we comply with what's expected of us as a company.
There's a whole management behind this as well, because there is so much federal, state, province, and sector specific regulation and law that we have to comply with that it becomes kind of something we have to manage in itself. This compliance that we have to manage is a component of our security program, and making sure that we have the right things in place as we move forward.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →