Back to all lessons
Awareness Lessons
3 days ago

Romanian Cosmetics Retailer Fined €5,000 for Inadequate Security Controls After Cyberattack

GEROCOSSEN S.R.L. failed to implement the baseline technical and organizational security measures required by GDPR Article 32, leaving customer personal data — including identification and contact details — exposed during a cyberattack. The absence of adequate access monitoring, logging systems, and backup procedures meant the company could neither detect the intrusion early nor recover effectively. This case underscores that GDPR compliance is not just about data collection policies but demands active, operational security controls. Regulators increasingly expect organizations of all sizes to demonstrate measurable security maturity, and failure to do so carries both financial and reputational consequences.

Tactical Insight

Immediate actions

  • Deploy centralized logging across all IT systems and configure a minimum 30-day log retention policy to support incident investigation.
  • Conduct an urgent audit of access controls to ensure only authorized personnel can reach systems storing personal data.
  • Implement and test an automated backup procedure for all systems handling personal data.

Long-term improvements

  • Establish a formal information security policy aligned with GDPR Article 32 requirements, including periodic review cycles.
  • Perform regular risk assessments to identify and remediate gaps in technical and organizational security measures before regulators or attackers do.
  • Engage a qualified Data Protection Officer (DPO) or external security advisor to maintain ongoing GDPR compliance oversight.

Detection measures

  • Deploy an intrusion detection or SIEM solution to generate real-time alerts on suspicious access patterns or unauthorized data transfers.
  • Schedule periodic penetration testing and vulnerability scans of all internet-facing infrastructure.
  • Establish an incident response plan with clear roles, escalation paths, and mandatory breach notification timelines.