Challenges in Digital Transformation Flashcards
Why do we need to prioritize digital transformation - even in a downturn
- Companies across industries are speeding up their adoption of digital solns
- Digital transformation is central to creating resilient economies
- Digital transformation is an impt enabler for sustainabaility & innovation:
-> allows for creation of new biz models
-> encourages op excellence
-> streamlines & automate processes
-> improves customer exp.
Name the challenges to digital transformation (brief - 6)
- Technology (Cyber security, data privacy, tech glitch)
- Org & govt
- Env
- Sustainability
- Scalability
- Social (inclusivity)
How is cyber security (tech) a challenge to digital transformation? & aim to overcome?
- Cyber breaches -> loss of trust thruout all sectors of society
- Aim: Cyber resilience - take measures to prevent & protect against the criminal / unauthorized use of electronic data
Desc data privacy
- It rests on a definition called Personally Identifiable Information (PII) - NRIC, credit card etc
- Special categories - generic code, biometric data etc
State the EU framework GDPR (Global Data Protection Regulations) as part of data privacy (3)
- Privacy as a human right
- Citizens’ data rights - access, rectification, erasure, restriction, portability, objection, notification & automated decision-making
- Fines of up to 2% of global sales -> accountability & up to 4% -> fail in citizens’ data rights
State the PDPA in SG
- Unless required by law, it is illegal for org to physically hold on to an indv’s NRIC & collect its full number
- Applies to birth cert no., foreign identification no. & work permit no.
Eg of Data Breach Incidents
Yahoo Data Breach (2013)
- Records affected: 3b
-Compromised: real names, email addm DOB, telephone no. & security qns
- Damage: $350m
First American Financial Corporation Data Breach (2019)
- Records affected: 885m
- Compromised: Bank acc no., bank statements, mortgage, tax records, ssn, wire transaction receipts, driver license images
- Damage: charges from NY State Department Financial Services (NYDFS)
SolarWinds Supply Chain Data Breach (2020)
- Compromised: > 18000 org & govt entities at risk; activated against ~50 org including US govt agencies
Eg of how tech glitch affects biz continuity
AWS (2021)
- AWS second outage took out Twitch, DoorDash, Xbox Live, PSN, Ring, Disney+ & T-Mobile - cased by issues at Amazon’s Oregon & Northern California AWS facilities
- AWS third outage took out Fortnite, Hulu, Quora, Slack & Imgur - caused by a power outage at a AWS facility
Will outage problem diminish or grow?
- Cloud-dependent system is fragile
-> conc on a few apps & services
-> services by a few major cloud infrastructure providers - What needs to be done:
-> Investment in cloud infrastrucutre - Data center -> backups to kick until problematic node is fixed
-> Processes, governance of service providers (most outages in 2021 came from company errors)
-> Biz continuity planning
Why is cyber resilience impt to org?
- Pri source of vulnerability - human error
-> train employees on digital habits
-> use internal data classification - secret, confidential, public etc to ↑ awareness - Central inventory of all networked devices & app to monitor devices
- Incident response team & procedures
- Third-party risk - vendors need min cybersecurity standards
How are govt involved in cyber resilience?
- Govt must develop national cybersecurity strat & transnationaal treaties
- Ensure public databases & infrastrucure have necessary safeguards
- Law enforcement needs to be standardizezd & deterrents to cybercrime shared b/w nations
- Educational curriculum on best online prac & managing personal data
- Indv can be more aggressive in reporting phishing attacks
Role of data governance in org
- Managing data as biz assets
- Compliant w regulation; Establish procedures - regular audits
- Maintain correct desc (metadata) of & permissions to data
- Set clear procedures on how data can be used
- Define owner of various data:
-> Who is responsible for data accuracy?
-> Who can access the data?
-> Who maintain the access control?
-> Who is responsible to update the data?
Should org own data?
- If the key biz process depends on some data, it is impt to own the data & NOT depend on third-party
- Implication if third-party ↑ price -> serious distruption to biz
- Data minimization as good prac:
-> X keep every piece of data
-> May cause legal trouble - recall GDPR “adequate, relevant & limited to min necessary for the purposes for which the data are processed”
-> Walmart - only prev 4 weeks of data
-> Storing data “jic” is dangerous, not a good prac
Limitations of regulations
- Inability of regulatory frameworks to cope w the rate of change
- Risk of digital transformation -> digital fraud within banking institutions ; cyber terrorists that paralyze public institutions
Describe how IoT can be a threat to org & govt
- With ↑ connected device -> ↑ possible attack points
- Leverage on network vulnerabilities to get to PCs / phones that hold sensitive & valuable info
- Attacks can be prompts to download patches - malware to access other devices / ransomware - locking user out of the device unless a ransom is paid