{"id":527,"date":"2013-02-09T23:54:33","date_gmt":"2013-02-09T23:54:33","guid":{"rendered":"http:\/\/www.halkynconsulting.co.uk\/a\/?p=527"},"modified":"2013-06-14T21:19:10","modified_gmt":"2013-06-14T20:19:10","slug":"mandatory-reporting-of-data-security-breaches","status":"publish","type":"post","link":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/","title":{"rendered":"Mandatory Reporting of Data Security Breaches"},"content":{"rendered":"<figure id=\"attachment_528\" aria-describedby=\"caption-attachment-528\" style=\"width: 200px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"528\" data-permalink=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/020919_1689_0020_ksms\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?fit=200%2C200&amp;ssl=1\" data-orig-size=\"200,200\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"Mandatory Security Breach Reporting\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Mandatory security breach reporting &#8211; good thing, or just more paperwork?&lt;\/p&gt;\n\" data-medium-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?fit=200%2C200&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?fit=200%2C200&amp;ssl=1\" class=\"size-full wp-image-528 \" title=\"Mandatory Security Breach Reporting\" alt=\"Mandatory reporting of security breaches - good thing, or just more paperwork?\" src=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?resize=200%2C200\" width=\"200\" height=\"200\" srcset=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?w=200&amp;ssl=1 200w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?resize=100%2C100&amp;ssl=1 100w\" sizes=\"auto, (max-width: 200px) 100vw, 200px\" data-recalc-dims=\"1\" \/><figcaption id=\"caption-attachment-528\" class=\"wp-caption-text\">Mandatory security breach reporting &#8211; good thing, or just more paperwork?<\/figcaption><\/figure>\n<p>It has been announced that the European Commission, together with the High Representative of the Union for Foreign Affairs and Security Policy, is looking to bring in mandatory reporting of information security breaches, at least within some industry sectors.<\/p>\n<p>In an interesting press release titled &#8220;<a title=\"EU Cybersecurity plan to protect open internet and online freedom and opportunity\" href=\"http:\/\/europa.eu\/rapid\/press-release_IP-13-94_en.htm\" target=\"_blank\">EU Cybersecurity plan to protect open internet and online freedom and opportunity<\/a>&#8220;, makes the proposal as part of it is overarching strategy on the cumbersome-named &#8220;cybersecurity&#8221; and &#8220;network &amp; information security.&#8221;<\/p>\n<p>One of the more interesting part of the proposal is the bit that has been picked up by most news agencies this week, and it runs as follows: (the emphasis is ours)<\/p>\n<blockquote><p>Operators of critical infrastructures in some sectors (financial services, transport, energy, health), enablers of information society services (notably: app stores e-commerce platforms, Internet payment, cloud computing, search engines, social networks) and public administrations <strong>must adopt risk management practices and report major security incidents on their core services<\/strong>.<\/p><\/blockquote>\n<p>In most (admittedly not all) state run organisations (for example, City Councils &amp; the NHS in the UK) there are already mandatory reporting requirements but it is has frequently been claimed across Europe that private companies are able to hush up data security breaches. This has cast doubt on security studies (such as the Ponemon data breach report) as it is never been clear if everything is being captured.<\/p>\n<p>Creating a mandatory reporting requirement for such a broad spread of service providers seems to be an effective way to level the playing field, as long as it is properly enforced. Any public company has to weigh up competing interests before reporting a data breach and it seems likely that this is going to be just another factor to be considered. (<em>For example, if the fine for not reporting is \u00a310,000 but the likely loss in profit from the public reaction is \u00a3100,000, lots of companies will opt to not report<\/em>).<\/p>\n<p>There is another hurdle that will need to be ironed out by the EU &#8211; and that is what constitutes a &#8220;major&#8221; security incident. There is no clearly agreed definition of this and I suspect entire books could be written on the subject.<\/p>\n<p>However, if the EU can get over these obstacles, then this could actually be a very good move &#8211; even if companies try to resist it initially:<\/p>\n<ul>\n<li>The pain of reporting a data breach creates an incentive to provide better security driven by sound risk\u00a0management\u00a0strategies.<\/li>\n<li>As companies report security breaches, we will get better quality intelligence on what drives the breaches and how much impact they have.<\/li>\n<li>The more security breaches that are reported, the greater pressure there is for police forces (national or international) to become involved and punish offenders &#8211; at the moment, hackers are only prosecuted in exceptional circumstances and often private companies are forced to utilise their own resources post-breach.<\/li>\n<\/ul>\n<p>Time will tell if the EU actually implements this reporting requirement, but in the meantime, good practice would be to make sure that you have the following mechanisms in place (if you do, the EU requirements are likely to be painless):<\/p>\n<ul>\n<li><span style=\"line-height: 16px;\">A well run, well documented risk management process across your organisation.<\/span><\/li>\n<li>A well documented and properly implemented security management system.<\/li>\n<li>Robust network monitoring and incident detection systems.<\/li>\n<li>Sound incident management processes.<\/li>\n<li>Good, timely, reporting chains.<\/li>\n<\/ul>\n<p>This is good practice with or without regulations, so you really should be doing it now!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It has been announced that the European Commission, together with the High Representative of the Union for Foreign Affairs and Security Policy, is looking to bring in mandatory reporting of information security breaches, at least within some industry sectors. In an interesting press release titled &#8220;EU Cybersecurity plan to protect open internet and online freedom [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":528,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[5,3,21],"tags":[76,75,73,38,74,6,61,80,79,140,77,78,19],"class_list":["post-527","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-securitynews","category-security-risk-management","tag-breach","tag-data-breach-reporting","tag-eu","tag-european-union-data-protection","tag-incident-management","tag-infosec","tag-nhs","tag-regulation","tag-reporting","tag-security","tag-security-breach","tag-security-incident","tag-srm","entry","has-media"],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mandatory Reporting of Data Security Breaches - Halkyn Security Blog<\/title>\n<meta name=\"description\" content=\"Mandatory reporting (of security breaches) is being proposed by the European Commission - is it a good thing, or just more paperwork?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mandatory Reporting of Data Security Breaches - Halkyn Security Blog\" \/>\n<meta property=\"og:description\" content=\"Mandatory reporting (of security breaches) is being proposed by the European Commission - is it a good thing, or just more paperwork?\" \/>\n<meta property=\"og:url\" content=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\" \/>\n<meta property=\"og:site_name\" content=\"Halkyn Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-02-09T23:54:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2013-06-14T20:19:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?fit=200%2C200&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"200\" \/>\n\t<meta property=\"og:image:height\" content=\"200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Taz Wake - Halkyn Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/tazwake\" \/>\n<meta name=\"twitter:site\" content=\"@HalkynSecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Taz Wake - Halkyn Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#article\",\"isPartOf\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\"},\"author\":{\"name\":\"Taz Wake - Halkyn Security\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc\"},\"headline\":\"Mandatory Reporting of Data Security Breaches\",\"datePublished\":\"2013-02-09T23:54:33+00:00\",\"dateModified\":\"2013-06-14T20:19:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\"},\"wordCount\":588,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\"},\"keywords\":[\"Breach\",\"Data Breach Reporting\",\"EU\",\"European Union Data Protection\",\"Incident Management\",\"Information Security\",\"NHS\",\"Regulation\",\"Reporting\",\"Security\",\"Security Breach\",\"Security Incident\",\"Security Risk Management\"],\"articleSection\":[\"Security\",\"Security News\",\"Security Risk Management\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\",\"name\":\"Mandatory Reporting of Data Security Breaches - Halkyn Security Blog\",\"isPartOf\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#website\"},\"datePublished\":\"2013-02-09T23:54:33+00:00\",\"dateModified\":\"2013-06-14T20:19:10+00:00\",\"description\":\"Mandatory reporting (of security breaches) is being proposed by the European Commission - is it a good thing, or just more paperwork?\",\"breadcrumb\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Halkyn Security\",\"item\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"http:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Mandatory Reporting of Data Security Breaches\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#website\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\",\"name\":\"Halkyn Security Blog\",\"description\":\"Specialist Security &amp; Risk Management Consultants\",\"publisher\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\",\"name\":\"Halkyn Consulting\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1\",\"contentUrl\":\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1\",\"width\":\"990\",\"height\":\"170\",\"caption\":\"Halkyn Consulting\"},\"image\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/2329571\",\"https:\/\/twitter.com\/HalkynSecurity\"]},{\"@type\":\"Person\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc\",\"name\":\"Taz Wake - Halkyn Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g\",\"caption\":\"Taz Wake - Halkyn Security\"},\"description\":\"Certified Information Systems Security Professional with over 19 years experience providing in-depth security risk management advice to government and private sector organisations. Experienced in assessing risks, and producing mitigation plans, worldwide in both peaceful areas and war zones. Additionally, direct experience carrying out investigations into security lapses, producing evidential standard reports and conducting detailed interviews to ascertain the details of the incident. Has a detailed understanding of the Security Policy Framework (SPF) and JSP440, as well as in depth expertise in producing cost-effective solutions in accordance with legislative and regulatory guidelines. Experienced in accrediting establishments and networks as well as project managing the development of secure, compliant, workable business processes.\",\"sameAs\":[\"http:\/\/www.halkynconsulting.co.uk\",\"https:\/\/twitter.com\/https:\/\/twitter.com\/tazwake\"],\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/author\/tazwake\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mandatory Reporting of Data Security Breaches - Halkyn Security Blog","description":"Mandatory reporting (of security breaches) is being proposed by the European Commission - is it a good thing, or just more paperwork?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/","og_locale":"en_GB","og_type":"article","og_title":"Mandatory Reporting of Data Security Breaches - Halkyn Security Blog","og_description":"Mandatory reporting (of security breaches) is being proposed by the European Commission - is it a good thing, or just more paperwork?","og_url":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/","og_site_name":"Halkyn Security Blog","article_published_time":"2013-02-09T23:54:33+00:00","article_modified_time":"2013-06-14T20:19:10+00:00","og_image":[{"width":200,"height":200,"url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?fit=200%2C200&ssl=1","type":"image\/jpeg"}],"author":"Taz Wake - Halkyn Security","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/tazwake","twitter_site":"@HalkynSecurity","twitter_misc":{"Written by":"Taz Wake - Halkyn Security","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#article","isPartOf":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/"},"author":{"name":"Taz Wake - Halkyn Security","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc"},"headline":"Mandatory Reporting of Data Security Breaches","datePublished":"2013-02-09T23:54:33+00:00","dateModified":"2013-06-14T20:19:10+00:00","mainEntityOfPage":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/"},"wordCount":588,"commentCount":0,"publisher":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"keywords":["Breach","Data Breach Reporting","EU","European Union Data Protection","Incident Management","Information Security","NHS","Regulation","Reporting","Security","Security Breach","Security Incident","Security Risk Management"],"articleSection":["Security","Security News","Security Risk Management"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#respond"]}]},{"@type":"WebPage","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/","url":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/","name":"Mandatory Reporting of Data Security Breaches - Halkyn Security Blog","isPartOf":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#website"},"datePublished":"2013-02-09T23:54:33+00:00","dateModified":"2013-06-14T20:19:10+00:00","description":"Mandatory reporting (of security breaches) is being proposed by the European Commission - is it a good thing, or just more paperwork?","breadcrumb":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/02\/mandatory-reporting-of-data-security-breaches\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Halkyn Security","item":"http:\/\/www.halkynconsulting.co.uk\/a\/"},{"@type":"ListItem","position":2,"name":"Security","item":"http:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Mandatory Reporting of Data Security Breaches"}]},{"@type":"WebSite","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#website","url":"http:\/\/www.halkynconsulting.co.uk\/a\/","name":"Halkyn Security Blog","description":"Specialist Security &amp; Risk Management Consultants","publisher":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization","name":"Halkyn Consulting","url":"http:\/\/www.halkynconsulting.co.uk\/a\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","width":"990","height":"170","caption":"Halkyn Consulting"},"image":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/2329571","https:\/\/twitter.com\/HalkynSecurity"]},{"@type":"Person","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc","name":"Taz Wake - Halkyn Security","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g","caption":"Taz Wake - Halkyn Security"},"description":"Certified Information Systems Security Professional with over 19 years experience providing in-depth security risk management advice to government and private sector organisations. Experienced in assessing risks, and producing mitigation plans, worldwide in both peaceful areas and war zones. Additionally, direct experience carrying out investigations into security lapses, producing evidential standard reports and conducting detailed interviews to ascertain the details of the incident. Has a detailed understanding of the Security Policy Framework (SPF) and JSP440, as well as in depth expertise in producing cost-effective solutions in accordance with legislative and regulatory guidelines. Experienced in accrediting establishments and networks as well as project managing the development of secure, compliant, workable business processes.","sameAs":["http:\/\/www.halkynconsulting.co.uk","https:\/\/twitter.com\/https:\/\/twitter.com\/tazwake"],"url":"http:\/\/www.halkynconsulting.co.uk\/a\/author\/tazwake\/"}]}},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/02\/020919_1689_0020_ksms.jpg?fit=200%2C200&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9yHvD-8v","jetpack_likes_enabled":true,"_links":{"self":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/comments?post=527"}],"version-history":[{"count":17,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/527\/revisions"}],"predecessor-version":[{"id":734,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/527\/revisions\/734"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media\/528"}],"wp:attachment":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media?parent=527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/categories?post=527"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/tags?post=527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}