Approximately 37% reduction in Cost of Risk on 10TB reference data
Benefits & Results
Background
Haleon, formed from the demerger of the consumer divisions of GSK and Pfizer, is a prominent player in the consumer healthcare market. With a robust portfolio of well-known brands, Haleon is committed to improving everyday health with humanity. Post-demerger, Haleon inherited a vast amount of data presenting both opportunities and challenges in managing and securing this information.
Challenges
Issue Identification: Following the demerger, Haleon inherited approximately 270TB of data from its parent companies, posing a high risk of data breaches. They struggled with assessing PII risk on large datasets, prioritizing remediation actions, and lacking proper data classification. Furthermore, the absence of a standardized policy for remediation treatments on aged and high-risk data exacerbated these challenges.
Issue Impact: The inability to effectively manage and secure this vast amount of data led to very high cost of risk and potential reputational threats, brand damage, and competitive disadvantages. The lack of data classification and agreed-upon remediation policies increased the risk of exfiltration, data breaches, and compliance issues, impacting Haleon's operational efficiency and strategic goals.
Solution
NowVertical implemented a Risk & Privacy (PII) Data Discovery solution to address Haleon's challenges regarding high cost of risk. This involved conducting a thorough risk assessment and reporting using advanced data discovery capabilities, implementing custom PII discovery and legal preservation. Additionally, NowVertical identified corporate sensitive information at unauthorized locations and established a remediation policy for Haleon's aged and high-risk files.
Implementation
- Conducted a comprehensive risk assessment and risk reporting using NowPrivacy's Data Discovery and visualization capabilities.
- Utilized advanced customer data discovery techniques to uncover PII/PI and corporate sensitive vulnerabilities in structured & unstructured data.
- Implemented custom data classification tagging and labelling based on legal hold requirements.
- Formulated a remediation policy for aged and high-risk files post-workshops and agreement with business stakeholders.