Learn from the mistakes of others

The month of April closed in Spain with 527 notifications of personal data leaks to the Spanish Data Protection Agency (AEPD). In just 30 days! The volume of incidents, most of which are intentional, that is, crimes against privacy and data protection, seems to alert us that the question is not if it will ever happen to us, but when. And we must be prepared to minimize risks.

In this sense, data protection prevention in Spain has taken a very important qualitative leap thanks to an initiative by the AEPD that changes the way we analyze information security. The agency has launched a new interactive public consultation tool that allows access in a completely visual and agile way to all security breach notifications received from companies. Until now, this information was published statically in closed monthly documents, which made it very difficult to draw useful conclusions for the day-to-day work of professionals. With this commitment to open government, the AEPD uses a dynamic dashboard based on Power BI technology that allows any privacy officer to filter, segment and explore the historical data collected. This resource radically improves market transparency and becomes an essential ally because it allows us to reverse engineer cybersecurity, learning from other people's mistakes and real attack trends to design better defense barriers.

If we delve into a didactic reading of the data offered by this new viewer, we see that the panorama of breaches in the Spanish State leaves us with very clear lessons about where organizations really fail. The heart of these statistics shows that security incidents do not discriminate by sector, although there are some that historically accumulate a much higher volume of notifications due to the massive nature of the data they manage, such as financial services, telecommunications, the healthcare sector and education. When we analyze the typology of breaches, it is observed that the loss of confidentiality is the undisputed queen of digital scares, generally caused by unauthorized access or document leaks.

The tool also allows us to demystify the idea that all failures come from super-intelligent external hackers. Although intentional attacks such as ransomware (rescue software) or phishing (credential theft) remain a critical weight, the graphs overwhelmingly demonstrate the enormous impact of human error and accidental factors. Sending mass emails with visible addresses, the loss of unencrypted corporate devices or the poor configuration of cloud servers are the order of the day. Therefore, the lesson for any company or professional is that technological investment is of little use if it is not accompanied by a real culture of internal training of the workforce. Current events tell us that monitoring the digital environment through these new interactive utilities is the best preventive audit that we can apply to our own businesses.

Related articles

Meet Windat

Scroll to Top

Closed for holidays

The week of August 11th to 15th, we will be closed.

If you need us, send us an email at hola@windat.eu and we will respond to you as soon as we can.

Happy Holidays from
Vilafranca del Penedès!

Enjoy the culture, tradition and festival with responsibility and joy. Long live Sant Fèlix and long live the Festa Major!