Categories
Europe In the News Legal & Compliance Strategy and Management UK

Small creative firms risk reputation by underestimating cyber attack impact

So say the findings of the Small Business Reputation and the Cyber Risk report, just launched by the UK Government’s Cyber Streetwise campaign and KPMG.

Despite the majority (92%) of the creative small businesses surveyed thinking about their company’s reputation frequently or all the time, they aren’t considering how a breach could affect it. In fact, just 26% of those surveyed that haven’t experienced a breach say the potential damage a cyber breach could cause is an important consideration.Privacy

However, 83% of consumers surveyed are now concerned about which businesses have access to their data and whether it’s safe, and over half (58%) say that a cyber breach would discourage them from using a business in the future.

This concern is even greater in the supply chain and recently published KPMG Supply Chain research supports this. 86% of procurement departments would consider removing a supplier from their roster due to a breach, highlighting that an attack can have serious short and long term implications. 94% of procurement managers say that cyber security standards are important when awarding a project to an SME supplier, it is essential that every company has at least one expert with Security+ training experience.

Cyber attack causing brand damage

This is reflected by the fact that the majority (80%) of small creative businesses surveyed who have experienced a breach felt the cyber attack impacted their reputation in some way, with 28% of those having been breached reporting brand damage, 29% reporting a loss of clients and 24% receiving negative reviews on social media.

And the impact has been long lasting. Almost a quarter (23%) of those surveyed have been unable to grow in line with previous expectations and 23% said it took over six months for the business to get back on track. Quality of service is also at risk; those who experienced a cyber breach found it impacted the business’ ability to operate (87%) and caused customer delays (22%).

The lack of concern around potential reputation damage may be explained by the fact that many small creative businesses don’t realise the value of their data. The majority (92%) hold data in their IT systems, yet up to 27% of those surveyed don’t consider this data to be commercially sensitive. And despite the fact that customer, financial and IP data can be shared with competitors if a company is attacked, just 17% of small creative businesses said they would be immediately concerned about competitors gaining advantage if they were breached.

The report also reveals that more than half of businesses in the sector (59%) don’t think they will be a target for an attack, despite the majority of consumers worrying about the security of their data, especially in the hands of small businesses.

Cyber attack risks articleDanny Lawrence (pictured left), National Police Chiefs’ Council PROTECT co-ordinator for Cyber Crime, said: “A cyber attack may prove so serious that it impairs an organisation’s ability to operate and even function longer term. Doing nothing can no longer be an option – SMEs place their reputation and existence on the line if they fail to take action. I would encourage all SMEs to consider their cyber security, seek out support from resources available and consider making this piece of work a critical part of their business strategies in 2016.”

George Quigley (pictured right), a partner in KPMG’s cyber security practice, added: “Small businesses know that their reputation is critical to their success, but it seems that many haven’t considered quite how many factors can affect it. Every piece of data in a business can be of interest to a cyber criminal – even if the business itself may not realise it – and with SMEs a key target for this very reason; it’s vital to take steps to protect your data, and with it the trust of your customers and, ultimately, your reputation.”George Quigley, a partner in KPMG’s cyber security practice, cyber attack risks article

Sandra Dexter, vice-chairman for the Federation of Small BusinessesSandra Dexter (left), vice-chairman for the Federation of Small Businesses, said: “Small businesses need simple, straightforward cyber security advice like that provided by Cyber Streetwise. All small firms should now be aware of the risks and take steps to protect themselves against the escalating level of cyber crime. Cyber breaches can happen to any business, any size and the repercussions should not be underestimated, leading to damaged reputations, hindered growth and in the worst cases, entrepreneurs being put out of business. Building the resilience of small businesses to cyber crime is important and should be high on all business owners’ list of priorities.”

Cyber Streetwise is encouraging small businesses and consumers across the UK to do three simple things to improve their online security and protect themselves from cyber crime:

  • Make your passwords stronger with three random words
  • Install security software on all devices
  • Always download the latest software updates

The UK Government also offers a free cyber security guide and a free online training course for small businesses. Visit: www.cyberstreetwise.com to learn more about the simple steps to stay cyber secure.

Categories
Best practice In the News Legal & Compliance Strategy and Management UK

Compliance: consent should be given not taken, says watchdog

“It’s simply not good enough for people to buy and sell data if they have no means of satisfying themselves that the people involved have given consent for the information to be shared in the way proposed.”

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Europe In the News Legal & Compliance Strategy and Management UK

Usage limits set on new charity database of 2.5million known UK donors

UK business and consumer marketing data specialists, DBS Data, has announced the availability of a newly enriched 2.5 million record charity database, of known charity donors in the UK and – in what the company says is a ground-breaking move for the data marketing industry – usage of the data will be limited to one charity delivering one communication per month to each donor.

Charities that will benefit from this new DBS Data service are those operating in the health and medical, animal, cancer and environmental sectors.

DBS Data news articleManaging director of DBS Data, Adam Williams (pictured), said: “This new service enables charities to better target people with the highest propensity to donate to their specific cause. The result will be a combination of lower yet more effective marketing spend and higher more profitable response rates.

“We have taken the bold decision to place usage limits on the data, to prevent households from being bombarded with donation requests which can lead to apathy. In doing so we hope and expect that this will help charities to stand out in their marketing communications and increase donations.”

The new database has been created by extracting key characteristics from DBS’s pre-existing 2.5 million charity donor file and overlaying it with its LifeBase pool of 46million consumer records. This means that using DBS propensity scoring models and flags, DBS can enable charities to target and engage with donors (by mail, email and Facebook) based on the types of charities the person donates to and the value and frequency of their donations.

Categories
Best practice Europe Legal & Compliance Strategy and Management UK

Concerns over brand security are escalating

Ben Harknett discusses data breaches and the effect of cyber crime.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Best practice Global Legal & Compliance Strategy and Management

How to scale The Three Pillars of Consent-to-Contact

David Cole explains how time spent researching hundreds of permission statements has uncovered The Three Pillars of Consent – the factors which most influence consent-to-contact.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Europe In the News Legal & Compliance Strategy and Management UK

Battling digital damage – families and young people looking for expert help managing reputations online

As the iRights initiative launched this summer – campaigning for the rights of children and young people to be able to easily edit or delete personal information online – new research revealed a growing demand for specialist support.

According to a report from British reputation experts, Igniyte, 40 per cent of their inquiries now come from individuals, rather than corporations. Of those, another 40 per cent wanted help removing incorrect, defamatory or libellous information.

A further 21 per cent were parents or family members of young people concerned about their online reputation or behaviour.

In addition, 16 per cent of all new clients were looking for support with ‘Right to be Forgotten’ applications.

Concern growing over reputations online needing protection

Despite being widely criticised for apparently allowing criminals to hide their past from the public, most requests were from people just wanting to protect their personal information and privacy, with more than a third (34 per cent) the victims, or family of the victims, of a crime.

data privacy articleCommenting on the findings and iRights campaign, Igniyte’s managing partner Simon Wadsworth (pictured left) said: “Concern regarding content online is growing and, with regard to young people, the iRights campaign is very much needed to protect them. Young people’s digital literacy often surpasses their parents’, teachers’ or guardians’, resulting in content online without advice on what should and should not be shared.

“For the iRights campaign to be a success, it needs to be backed by the main search engines and social platforms who tend to house the content that young people post online. Further legislation is required to protect them and practical steps taken to ensure children and adults are educated on how things are published, who can see them and what can be removed.”

Categories
Best practice Europe Insight Legal & Compliance Strategy and Management UK

Privacy and social media: incompatible or indispensable?

Do ‘digital natives’ care about privacy? Whether they do or not, Richard Beaumont says its a deep-seated cultural expectation that businesses should remain well aware of.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Global In the News Legal & Compliance Strategy and Management

That .sucks: avoid the fallout as questionable web domain names become available

Brands’ and celebrities’ worst nightmares could become a reality this June, when hundreds of questionable web domain Business Word Representing Trade Partnership and Commercenames go up for grabs.

Names such as .sucks, .porn and .adult are just some of the TDLs that will become available, and experts are now advising businesses to purchase uncomplimentary names, before it’s too late.

Web hosting company 34SP.com has predicted that some of the world’s biggest brands could be subject to torrents of abuse from online trolls purchasing unfavourable domain names with the sole aim of tormenting brands and celebrities.

Indeed, Taylor Swift has already registered taylorswift.porn and taylorswift.sucks, while Microsoft has reserved Office.porn and Office.adult.

More variations of domain names due

34SP predicts that thousands more registries will be made ahead of the June 1st deadline, when generic domain names are expanded to include more variations.

Domain names articleDaniel Foster (left), co-founder and technical director of 34SP.com, said: “Businesses should do everything in their power to avoid being associated with negative messages – it’s hard to imagine domain names like .sucks and .porn will foster positivity.

“Clearly some big brands are already taking this seriously by registering controversial names while we are still in a mandated period. However, after June 1st it becomes a free-for-all, so I’d advise all businesses with even a slight worry about how this could affect their business to swoop up the domains sooner rather than later.

“While some might use domains for good causes, by creating sites such as cancer.sucks for example, I’d predict that many will be swooping up the new names solely for defamatory purposes.”

Those who want to keep an eye on all the savoury and unsavoury new TLDs being released and applied for can do so on the Internet Corporation for Assigned Names and Numbers’ (ICANN) website.

Categories
Europe In the News Legal & Compliance Strategy and Management UK

Benchmark your permission statement to improve opt-in rates

The EU has committed to new legislation which will dramatically change the way European companies can collect, store and use data.

Its principal effect will be to stop firms contacting their customers unless they have been specifically given permission. The tacit agreement implied by people not ticking the opt-out box will no longer be enough.

In the not too distant future, companies throughout Europe will have to persuade customers to tick the opt-in box if they want to continue marketing to them.

And even before the EU law became an issue, consumers were becoming increasingly cautious about revealing information about themselves. They are concerned about who will have access to their data, how it will be used and how it will be stored and protected.

This has prompted them to look at permission statements more closely before deciding whether to allow further marketing contact.

UK DMA executive director Chris Combemale is quoted as saying: “Widespread concerns about rapidly shifting consumer attitudes to data privacy should be ringing alarm bells in the board room of every business involved with one-to-one communications.”

But there is a positive side to all this, according to Scott Logie, former UK DMA chairman and head of research, data and analysis for Bank of Scotland, who said: “Improving opt-in permission rates is fundamentally a commercial issue. At Bank of Scotland, we computed that the marginal value of increasing the consumer opt-in rate by just one per cent was worth a huge amount of incremental value. This created the basis for an ongoing scheme to improve opt-ins.”

What marketers can do

One way marketers can counteract the effects of the legislation (which some industry pundits predict could decimate some European databases) is to adopt a serious and urgent attitude to collecting permissions and make sure the permission statement is worded in a way which will maximise opt-ins.

Until now, brands have had no way of measuring whether the wording of their permission statements is generating the maximum response possible.

So, to take the guesswork out of the process, online research company fast.MAP and Opt-4 strategic consultant on data protection legislation compliance and permission maximisation, have joined forces to build a new industry standard The Data Permission Benchmarkdate permission benchmark logo

How it works

By comparing current or proposed permission-statement wording with actual results from thousands of consumers, the Data Permissions Benchmark allows marketers to quickly measure potential opt-in rates.

They will be able to understand what works and what doesn’t; compare the score against the benchmark; and gain insights into how and why consumers share their data.

The Benchmark allows brands to understand how their proposed wording performs against the 14 key attributes which affect sharing: Clear, Trustworthy, Honest, Flexible, Appealing, Inviting, Reassured, Gives confidence, Rewarding, control, Welcoming, Values me, Gives me choice, My data will be safe.

They may then compare the results with statements which perform highly in areas where their statement is underperforming and thus identify beneficial changes and refine and re-test statements.

The benchmarking process involves loading a current or proposed statement onto a fast.MAP questionnaire and sending it to a live panel of 1,000 consumers. This allows the statement to be live tested and improvements implemented within days.

Director of Opt-4, Rosemary Smith, said: “Live testing of multiple-data protection statements creates an untidy legacy of consumer promises that brands are obliged to honour, benchmarked research is the sensible alternative.”

Isn’t what constitutes an effective opt-in statement obvious?

Permission scripts which score well on clarity, control and trust are likely to achieve a high score.

To check your own success in judging the likely success of different statements, try this test.

What percentage of opt-ins do you think this statement achieved?

“By giving us your details and clicking the submit button, you are agreeing that we may use your personal data in accordance with our privacy policy including for marketing purposes”

Click here to find out if you came close.

And this one:

You know that we have some great deals in-store and online. To be the first to hear about these offers – as well as to receive vouchers which are only sent by email – please provide your email address below.

You’ll start receiving offers straight away and there will be something special in the first email that you won’t want
to miss!”

Email address…………………………………..

Click here for result.

And this:

“We’d like to keep you informed by email about our future offers and new product launches. Please tick this box to let us know that you are happy for us to do this   

(Don’t forget, you can change your contact preferences at any time by logging into your account or by using the unsubscribe links which you will find on all our emails)”

Click here for result.

The next Benchmark step is to analyse exactly what makes some statements more successful and correct the weaknesses in the one being tested. Visit the website for more information.

Contact: rosemary.smith@opt-4.co.uk  0796 147 2210 or david.cole@fastmap.com  0777 568 4293.