Recent headlines paint a bleak picture of internet privacy and security. Between large-scale breaches, email compromises and questionable handling of users' data through third-party services, the need for organizations to embrace best practices when safeguarding private data is critical. In the recently released 10th edition of the Online Trust Audit & Honor Roll, the Internet Society's Online Trust Alliance evaluated over 1200 consumer-facing websites for their best practices in brand and consumer protection, security, and privacy across a broad range of industries, from healthcare to government to payment services. This has allowed for a comprehensive view of what top companies are doing today to protect consumers, and how it compares to previous practices. But how far do companies still have to go on privacy, and what implications do the EU's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) present? This speech will highlight the overarching results of the study, discussing areas where improvements have been made and how they were achieved, and instances where more work needs to be done to align current business practices with consumer expectations of trust. Key Take-Aways:Provide specific and tangible ways for businesses to enhance their online security and assess the effectiveness of existing privacy and security practices in place.Explain how companies can move back into alignment with consumer expectations, as well as comply with new and upcoming legislation, such as with their privacy policies.Gain key insights into next year's report criteria and areas of increased focus for privacy professionals, giving attendees a head start on addressing new and worsening threats.