{"id":8155,"date":"2020-09-01T14:09:29","date_gmt":"2020-09-01T14:09:29","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-2443\/"},"modified":"2026-05-10T19:06:51","modified_gmt":"2026-05-10T19:06:51","slug":"top-5-data-protection-risks-for-enterprises","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2020\/09\/01\/top-5-data-protection-risks-for-enterprises\/","title":{"rendered":"Top 5 Data Protection Risks for Enterprises"},"content":{"rendered":"<p><strong>The World Economic Forum has intensified its focus on corporate data protection, driven in part by remote-work policies. The collapse of the EU-US Privacy Shield further underscored the need for closer scrutiny.<\/strong><\/p>\n<p>Here are the five most dangerous data risks, according to OTRS AG:<\/p>\n<h2><strong>1. Partnering with Grey-Market Providers<\/strong><\/h2>\n<p>Grey-market providers offer software solutions outside official distribution channels. Some enterprises opt for these offerings &#8211; often due to their low price &#8211; despite the legal and security risks involved. The core problem is that grey-market vendors do not own the source code.<\/p>\n<p>This creates two major risks for enterprises. First, limited product expertise may lead to insecure configurations that leave data exposed. Second, because the software is distributed outside official channels, it often receives no updates or security patches &#8211; leaving known vulnerabilities unaddressed.<span class=\"apple-converted-space\">\u00a0<\/span><\/p>\n<h2><strong>2. Using Outdated, Unpatched Solutions<\/strong><\/h2>\n<p>Product updates and security patches are essential for closing known vulnerabilities. Without them, attackers can exploit backdoors &#8211; unauthorized entry points that bypass standard access controls &#8211; to gain access to sensitive data. According to a<span class=\"apple-converted-space\">\u00a0<\/span><a href=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUcuBs-2Fmjkk0lZ-2FArCawvc6zgi1yyre3OERt2de8eHyAtXyjX5WVacw71sC9et-2BpramsutGtrhrXAwgOCueYsPX2lpZyUC6kLeNVYCeFYUv5sROF4-2FGmZVWPymaN5AR-2FHQx96IJmwBFqLBQjd8rYRPe4YVU9dT0jmnF5duXZMnUpd0Ac831q8WcKqCqT0uuF6oslRGLX2E7MmQsfilHtILKg-3D\" target=\"_blank\" rel=\"noopener\">Tripwire study<\/a><span class=\"apple-converted-space\">\u00a0<\/span>, 27 percent of security breaches stem from delayed or missing patches.<\/p>\n<h2><strong>3.<\/strong>\u00a0<strong>Working with Suppliers That Neglect Data Protection<\/strong><\/h2>\n<p>Whether engaging external consultants or service providers, enterprises must fully understand how those third parties protect data. Before signing any contract, clients should<span class=\"apple-converted-space\">\u00a0<\/span><a href=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUTIdUVkW1CpdVAZvgFez52nytaDEF-2FcGOdSMd6ERZC04Hr5R4tANX6NTh9PCDQsbE75F2QMWH4UjPIDdNFjiHO5BfYXvttNUurML7drQeUwWLo5MJVRKF7a-2B-2BI-2FYaJPXQFobZogPoac1q-2BJojbLnelL93IHOmUU-2FfW4UUnB1KkxYOtvqAPsDTgWXCthkxdxBsJb7YnC-2FBjcwC9aeok7kZ1K5rbOjK6jdiA-2Bm22uEEP2hwk-A_8hLPQzGtYz122j-2FetqzZ4xP9ye24JxORoUvE-2FX77yOps0n-2FmF-2FD5TIEnWy3RmFe-2FJNBTwKy6NW6bGVvq74vIfFDZ-2Fhgq2ZUQ-2B0brlDiKLZdoN3WSj5JwE8z-2B2YD-2F3Q8yBc9w3emNvhcNzgIwy7vgrux5zqsnWNcgwfoYjiFt9BShNatmwP6osOX4ccwbX8X-2FulvIZdnOqaOGTjS54OF72fxP4qwEgUWaKYCZJXdlMhdJnlMrkqesx6bU3uze7eO2m-2Fcl5ih3UyGNyKy3jorUmX89mc8AyjPy2X1KqMIOV6TFWLPOuJLhZFlRGjWE-2F95RGmLw-2BW4T5B2A5UDSoqOZd9YD2GOcaaqiS0YSLcoVcaw-3D\" target=\"_blank\" rel=\"noopener\">ask targeted questions<\/a>, to gain a thorough understanding of the vendor\u2019s security practices &#8211; and explicitly incorporate security commitments into contractual agreements.<\/p>\n<h2><strong>4. Inadequate Employee Training<\/strong><\/h2>\n<div id=\"attachment_2447\" style=\"width: 392px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2447\" class=\"wp-image-2447\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2020\/08\/social-distancing-at-board-room-picture-id1248189960-700x466.jpg\" alt=\"\" width=\"382\" height=\"254\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2020\/08\/social-distancing-at-board-room-picture-id1248189960-700x466.jpg 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2020\/08\/social-distancing-at-board-room-picture-id1248189960-250x167.jpg 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2020\/08\/social-distancing-at-board-room-picture-id1248189960-768x512.jpg 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2020\/08\/social-distancing-at-board-room-picture-id1248189960-120x80.jpg 120w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2020\/08\/social-distancing-at-board-room-picture-id1248189960.jpg 1024w\" sizes=\"auto, (max-width: 382px) 100vw, 382px\" \/><p id=\"caption-attachment-2447\" class=\"wp-caption-text\">Employee training can be the key to solving the problem. Source: iStock \/ skynesher<\/p><\/div>\n<p>People remain the weakest link: employees still create weak passwords and frequently connect via unsecured networks. Professional training helps build awareness of real-world threats &#8211; including social engineering and phishing attacks.<\/p>\n<p>With so many employees now working remotely, mobile workers must ensure their home networks are secured &#8211; and use a Virtual Private Network (VPN), wherever possible.<\/p>\n<h2><strong>5. Absence of Clearly Defined Incident-Response Processes<\/strong><\/h2>\n<p>What happens when a breach occurs? The longer an incident remains undetected or unresolved, the greater the volume of compromised data. In a global<span class=\"apple-converted-space\">\u00a0<\/span><a title=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUeyQLEz1-2FOo4L1eJ-2F5B4PnNPjpmh3RA8wn40q4dzA562PLHHyIb22wTtwKqUWADkyNhSJeJylkippXgrBbcO3A8jgLFUlqGVOlicszD-2BJaZfQyGXpeFMgc3i42vEFtU8VMz6DYEG5oMvs-2FlrZRQe6b3TXnVnY7xwiKGtjB3hOazQcHolBkx\" href=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUeyQLEz1-2FOo4L1eJ-2F5B4PnNPjpmh3RA8wn40q4dzA562PLHHyIb22wTtwKqUWADkyNhSJeJylkippXgrBbcO3A8jgLFUlqGVOlicszD-2BJaZfQyGXpeFMgc3i42vEFtU8VMz6DYEG5oMvs-2FlrZRQe6b3TXnVnY7xwiKGtjB3hOazQcHolBkxxxwkwI6mUae8u9oyISwypU6ccvV1e534GaxAXtqiv2FhPUCCXHLfj48Sm1R-2FagaiXleZq15s3OxC0pw-3D-3DS0Gr_8hLPQzGtYz122j-2FetqzZ4xP9ye24JxORoUvE-2FX77yOps0n-2FmF-2FD5TIEnWy3RmFe-2FJNBTwKy6NW6bGVvq74vIfFDZ-2Fhgq2ZUQ-2B0brlDiKLZdoN3WSj5JwE8z-2B2YD-2F3Q8yBc9w3emNvhcNzgIwy7vgrux5zqsnWNcgwfoYjiFt9BShNatmwP6osOX4ccwbX8X-2FZ6mR8gZDuW-2FOqQukp5BhFJGOEoZcKPdXKdaIpIjlwKCJE-2FCoeDkkOUj7BfpV7t5o2WnlZs6J3-2FGcXaeYE4s2Atfz2kCr65ndoPrLPLsYofkOl2M1rzdWxpZkMA72P4QyNt2gWaGQc4cDG9Gvl1vZv5pA5Db8riFzkvGw-2FZ-2FSw4I-3D\" target=\"_blank\" rel=\"noopener\">survey by the OTRS Group<\/a><span class=\"apple-converted-space\">\u00a0<\/span>of IT managers, 40 percent cited the urgent need for clearly defined incident-management processes to respond more effectively to security breaches.<\/p>\n<p>\u201cThere is no such thing as 100% data security &#8211; but there are numerous protective measures,\u201d says Jens Bothe, Director Global Consulting at OTRS AG and cybersecurity expert. \u201cRemote work increases our exposure to security risks, but following these five recommendations significantly reduces that risk.\u201d<\/p>\n<p>For more information on how<span class=\"apple-converted-space\">\u00a0<\/span><strong>OTRS<\/strong><span class=\"apple-converted-space\">\u00a0<\/span>can help structure enterprise security, see<span class=\"apple-converted-space\">\u00a0<\/span><a href=\"https:\/\/u7061146.ct.sendgrid.net\/ls\/click?upn=4tNED-2FM8iDZJQyQ53jATUTIdUVkW1CpdVAZvgFez52nA9LlBqlIxn-2BP3dLIr3dzX2ltiSDzu-2BPJ7mzAcPhJhhR3dZi2ioSQFEWhh5N6SmqViNZCyaG2hjDPqlmzWxiYQHe-2F2-2FimeVoO7s08-2BoKWX5B73l7xN1YbKBVYGfE6CDKF4XDgtME0RaFJfteQx5RKhvX-2BqpcK5tIVBMj1D9DhVUQ-3D-3DqXTD_8hLPQzGtYz122j-2FetqzZ4xP9ye24JxORoUvE-2FX77yOps0n-2FmF-2FD5TIEnWy3RmFe-2FJNBTwKy6NW6bGVvq74vIfFDZ-2Fhgq2ZUQ-2B0brlDiKLZdoN3WSj5JwE8z-2B2YD-2F3Q8yBc9w3emNvhcNzgIwy7vgrux5zqsnWNcgwfoYjiFt9BShNatmwP6osOX4ccwbX8X-2FIR9Ys9PtiDPtddJwQz9YQdI9nV1GvFboJBoWkXJ2aDaBULhkTKbii9wZk946pQDGuINKAByQ5DZ1uRbb375XbQl9sShT8JcUHHJE7nznM5x30GIoRiYgJRjPAn41greY09cYmD34JWuusfeDWkSn7JrJo5dwDxvjPJpB2stLEG4-3D\" target=\"_blank\" rel=\"noopener\">here.<\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>GDPR fines:<\/strong> European data protection authorities have imposed over \u20ac4.5 billion in penalties to date.<\/p>\n<p><strong>Data breaches:<\/strong> 83 percent of enterprises experience more than one data protection incident per year.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is the difference between data protection and data security?<\/h3>\n<p>Data protection governs the lawful handling of personal data &#8211; covering legal basis, purpose limitation, and data subject rights. Data security refers to the technical and organisational measures used to safeguard <em>all<\/em> data against loss, tampering, or unauthorised access.<\/p>\n<h3>Does every company need a Data Protection Officer (DPO)?<\/h3>\n<p>In Germany, appointing a DPO is mandatory if at least 20 people regularly process personal data using automated systems &#8211; or if special categories of personal data (e.g., health data) are processed.<\/p>\n<h3>What rights do data subjects have under the GDPR?<\/h3>\n<p>The right of access, rectification, erasure (\u201cright to be forgotten\u201d), restriction of processing, data portability, and objection. Companies must respond to such requests within one month.<\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2023\/04\/28\/post_id-3229\/\">How to prevent cyberattacks on critical infrastructure<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2023\/04\/28\/post_id-3221\/\">Multi-carrier connectivity as a safeguard against system failure<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2022\/02\/16\/post_id-2273\/\">Essential guidelines for video conferencing systems and data protection<\/a><\/li>\n<\/ul>\n<h3>More from the MBF Media Network<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.mybusinessfuture.com\" target=\"_blank\" rel=\"noopener\">Explore more cybersecurity trends at mybusinessfuture.com<\/a><\/li>\n<li><a href=\"https:\/\/www.digital-chiefs.de\" target=\"_blank\" rel=\"noopener\">Discover IT strategies for decision-makers at digital-chiefs.de<\/a><\/li>\n<\/ul>\n<p style=\"text-align: right;\"><em>Header Image Source: iStock \/ <a href=\"https:\/\/www.istockphoto.com\/de\/portfolio\/crocothery?assettype=image&amp;mediatype=photography&amp;sort=best\" target=\"_blank\" rel=\"noopener\">CROCOTHERY<\/a><\/em><\/p>\n<p><strong>Fact:<\/strong> According to Bitkom, German enterprises invest an average of 14 percent of their IT budgets in cybersecurity.<\/p>\n<p><strong>Fact:<\/strong> IBM reports that 95 percent of all cybersecurity incidents result from human error.<\/p>\n<\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>According to a Tripwire study, 27 percent of security breaches stem from delayed or missing patches.<\/li>\n<li>In a global OTRS Group survey of IT managers, 40 percent said they urgently require clearly defined incident-management processes to respond more effectively to security breaches\u2026<\/li>\n<li>Inadequate employee training  Employee training can be the key to solving the problem.<\/li>\n<li>The World Economic Forum has intensified its focus on corporate data protection, driven by remote-work policies.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"The World Economic Forum has intensified its focus on corporate data protection, driven in part by remote-work policies. The collapse of the EU-US Privacy Shield further underscored the need for closer scrutiny. Here are the five most dangerous data risks, according to OTRS AG: 1. Partnering with Grey-Market Providers Grey-market providers offer software solutions outside [&hellip;]","protected":false},"author":55,"featured_media":2444,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"data protection","_yoast_wpseo_title":"Top 5 Data Protection Risks for Enterprises","_yoast_wpseo_metadesc":"Data protection risks: Avoid breaches & compliance fines. Learn the top 5 threats and how to safeguard your enterprise now. Read more.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-2443"],"footnotes":""},"categories":[251],"tags":[],"class_list":["post-8155","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":2443,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8155","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8155"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8155\/revisions"}],"predecessor-version":[{"id":10390,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8155\/revisions\/10390"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/2444"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8155"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8155"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8155"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}