Marks & Spencer’s cyberattack isn’t an exception – it’s a warning



Marks & Spencer did the right thing by self-reporting its recent cybersecurity incident to the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC). That kind of transparency is essential, not just for managing reputational risk, but for limiting regulatory fallout.

Under UK GDPR, failing to protect personal data or report breaches promptly can lead to fines of up to £17.5 million, or 4% of global turnover. And if M&S handles EU customer data, it may also come under the scope of the EU’s NIS2 Directive, which can carry penalties of up to €10 million.

https://cdn.mos.cms.futurecdn.net/YbizeHRMkF5QLe6eeYypqc.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img