Increased levels of digitalization in society expose companies to new security threats, requiring them to establish adequate security and privacy measures. Additionally, the presence of exogenous forces like new regulations, e.g., GDPR and the global COVID-19 pandemic, pose new challenges for companies that should preserve an adequate level of security while having to adapt to change. In this paper, we investigate such challenges through a two-phase study in companies located in Denmark -- a country characterized by a high level of digitalization and trust -- focusing on software development and tech-related companies. Our results show a number of issues, most notably i) a misalignment between software developers and management when it comes to the implementation of security and privacy measures, ii) difficulties in adapting company practices in light of implementing GDPR compliance, and iii) different views on the need to adapt security measures to cope with the COVID-19 pandemic.
翻译:社会数字化程度的提高使公司面临新的安全威胁,要求公司制定适当的安全和隐私措施。此外,外部力量的存在,如新的监管条例,如GDPR和全球COVID-19大流行,给公司带来了新的挑战,这些公司应当保持适当的安全水平,同时必须适应变化。在本文件中,我们通过对位于丹麦的公司 -- -- 以高度数字化和信任为特点的国家 -- -- 进行两阶段研究来调查这种挑战,重点是软件开发和与技术有关的公司。我们的结果显示,一些问题,特别是软件开发者与管理层在执行安全和隐私措施时的不协调,二)在执行GDPR合规措施时难以调整公司做法,三)关于需要调整安全措施以应对COVID-19大流行的不同看法。