
Chris Cochran at Axonius describes how the ever-increasing attention of privacy regulators is driving forward more robust cyber security standards
Four years ago, the EU General Data Protection Regulation (GDPR) came into effect in the UK. A pioneering piece of legislation, it remains among the toughest privacy and security laws in the world. Though drafted and passed by the European Union, organisations everywhere have obligations under the legislation, so long as they target or collect data related to people in the EU.
With the advent of the UK leaving the European Union, the legislation was amended to reflect the UK’s status in 2021. Now the UK Government is working on a complete replacement to GDPR in a post-Brexit world with the Data Reform Bill. Regardless of the specific legislation, the theme will remain the same.
Regulators around the world are paying closer attention to how consumer data is collected, stored and managed, and are prepared to intervene as necessary.
With increased scrutiny from regulators come costly notification requirements in case of a breach, or fines in the case of non-compliance – not to mention the reputational fallout amongst customers or suppliers of getting this wrong.
These consequences, combined with the very real risk of the organisation being knocked completely out of action by cyber threats, means that any organisation that is serious about their future have some kind of formal cyber security program in place, to protect and defend against threats that puts this data at risk.
From testing incident response and software patching to network and data monitoring, and actively enforcing access restrictions to safeguard different types of data appropriately, there’s a lot to factor in here and keep track of.
For a typical IT department, which not only plays a major role for cyber security, but also the day-to-day administration of the broader IT infrastructure, this can be a heavy load to bear.
Simply keeping up with the array of software and tools an organisation might use can feel impossible. Lack of visibility creates gaps that threat actors can exploit, putting company and user data at risk and increasing the likelihood of data being breached and stolen.
Cyber security control failures were identified as the top emerging risk at the start of 2021 by senior executives globally, according to research from Gartner. 45% of the respondents to IBM’s most recent Cyber Resilient Organization study use more than 20 security tools and technologies to investigate and respond to cyber security incidents, and 37% said they feel they have too many solutions to achieve cyber resiliency.
What these stats show is that companies have invested significant time and resources in procuring and deploying a wide range of security tools, but the sheer number of them means that the teams responsible for them face an information overload.
The complexity and overlap mean organisations are simply unaware of where or what they should be doing. Incomplete and out-of-date device inventory information is a major barrier to making any real cyber security gains.
Not only is there information and alert overload, but there’s no consistency in what and how things are reported. Security teams need a single source of truth of what assets they have in play as well as their status.
Addressing this starts with implementing software that can scan and plug into the ecosystem of tools a business is already using, and from there map out their entire IT infrastructure and assets.
Any solution worth considering must be able to integrate the full spectrum of resources - from physical and virtual machines, mobile devices, and IoT right the way through to ephemeral devices that might frequently enter and leave networks, such as containers and virtual machines.
From detection comes enforcement, which is where organisations can take action to not only make sure they’re staying compliant with data privacy legislation, but also shielding themselves from the worst effects of a cyber attack or data breach, which could put the very future of the business at risk.
Depending on the sophistication of the tool used, this proactive response can be automated, helping free up security teams’ time to focus on bigger priorities.
As privacy and data protection regulations around the world tighten, organisations must get serious about their asset management. You can’t manage what you can’t see, and where there are blind spots, there are almost certainly vulnerabilities and breaches in the making.
Chris Cochran is Creative Director at Axonius
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543