---
title: "Cybercrime Doesn't Follow Regulations - Part III: What's Next?"
description: In the past two posts we discussed how many companies have been breached despite being compliant and how dynamic and adaptable cybercrime has become, making it neigh impossible to eliminate the risk of being breached. In this post we explore how to protect sensitive data in this environment.
image: https://insights.comforte.com/hubfs/Cybercrime_3.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![Cybercrime_3](https://insights.comforte.com/hubfs/Cybercrime_3.png)](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-)

[Felix Rosbach](https://insights.comforte.com/author/felix-rosbach) l Sep 28, 2018 l [GDPR](https://insights.comforte.com/tag/gdpr), [PCI DSS](https://insights.comforte.com/tag/pci-dss), [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance), [Data Breaches](https://insights.comforte.com/tag/data-breaches)

# Cybercrime Doesn't Follow Regulations - Part III: What's Next?

In the past two blog posts we looked at regulations, the history of hacking, and cybercrime today.

[Part I: Lessons from the Past](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-i-lessons-from-the-past?hsLang=en)   
[Part II: The Evolution of Hacking](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking?hsLang=en)

We found out that a) compliance is always a process and that many companies have been breached despite being compliant  and b)  the cybercrime environment is becoming more and more diverse, sophisticated, and complex, making it neigh impossible to completely eliminate the risk of being breached.

So what can we learn from all of this?

## Compliance does NOT equal security

The rapid evolution and sophistication of hacking has led to the creation of complex regulations. These regulations try to set industry security standards as best as they can and while a lot of people are afraid of GDPR and PCI DSS, they are actually a good thing! They’re a step in the right direction.

On the other hand, these standards have also created a false sense of security.

Compliance follows Cybercrime – especially when it comes to targeted attacks. Hackers are quick to adapt their tactics and tools to always be one step ahead. They operate much faster than regulations can be written and implemented.

A lot of enterprises try to secure their systems – they try to secure devices, servers, and networks. However, security teams have a limited budget. Even if they had every method and measure at their disposal, an enterprise with thousands of endpoints and a complex infrastructure will never be 100% compliant and will never be 100% secure. And there is one main reason:

> *While most hackers aren’t wizards, neither is the average employee.*

We are human – sometimes we make mistakes. Sometimes we get complacent. As a result, when you Google usernames and passwords - you can find tons of real credentials on the internet. In times of GDPR, that could cost real money. Unfortunately, these shortcomings can easily be exploited. And once they are – someone benefits – usually it’s the bad guys. We need to remember that people are not infallible.

So what does this mean for security and compliance teams?

## Compliance and security are ongoing projects

Nothing new here. Looking back at the breaches over the last few years, we all know that both security and compliance require constant vigilance and careful architecture.

PCI DSS and GDPR are a great place to start but they must be considered as simply a baseline level of security. While both regulations cover the basic rules of data protection, an enterprise security architecture should be further enhanced to meet unique organizational culture and risk management objectives.

Knowing that it is not possible to be 100% compliant and 100% secure, there remains one big question:

## What should take priority?

Essentially, there are two main types of attacks: it’s either sabotage or data theft, gaining access to sensitive information that is valuable to the attackers. While sabotage usually isn’t that bad and companies often recover pretty quickly, theft is something far more dangerous. It’s all about getting access to data.

What if data is rendered unreadable anywhere it is stored? What if you could still work with the data while keeping it protected?

Developing a data-centric security strategy is the key to answering these questions. Data-centric security enables organizations to be more proactive about keeping data secure and privacy protected.

The EU’s GDPR supports solutions like this and states that if stolen data is adequately protected, then there is no obligation to disclose the breach, since no actual sensitive data has been compromised. This means that in the event of a breach, personal data is kept safe and the affected company doesn’t have to worry about legal battles, fines, or settlements.

comforte already makes this possible through its patented data-centric security solution, SecurDPS.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Looking where to get started with GDPR complaince?

If your organization is PCI compliant, then you've already got a solid foundation for achieving GDPR compliance. Check out the white paper below to find out how PCI DSS and GDPR overlap so you can avoid redundant work and get the most out of your data security investments.

[![Download White Paper](https://no-cache.hubspot.com/cta/default/4026697/aea1fd18-c4e0-4e49-8af5-2f3ba7b8a21c.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/aea1fd18-c4e0-4e49-8af5-2f3ba7b8a21c)

### Related posts

![OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png)

 Apr 6, 2023 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [AI](https://insights.comforte.com/tag/ai)

### [OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

After several weeks of incredible growth, OpenAI has come in for a bumpy ride of late. First it revealed details of a data breach exposing a significant number of ChatGPT subscribers. Then the Italian data protection regulator (GPDP) became the...

[Read more](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

![How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/hubfs/Analytics%20on%20Red%20Button%20Enter%20on%20Black%20Computer%20Keyboard..jpeg)

 Aug 4, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

Cloud-based analytics offer a truly transformative opportunity for global organizations. By extracting insights from data, they are already helping companies better serve their customers, improve operational efficiencies and make better business...

[Read more](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

![17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/hubfs/Int_Datenschutz_Strategie_1.png)

 Jan 13, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

GDPR wasn't the beginning and it certainly won't be the end. Strict data privacy legislation with extraterritorial applicability is appearing in more and more economies across the globe, meaning the list of “GDPR-free” havens is growing shorter by...

[Read more](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>