The Ramifications of a Data Breach
The ramifications of a Data Breach are huge for businesses. They often face financial loss and reputational damage, particularly in highly regulated industries like healthcare and finance. Attackers also gain access to high-value corporate data and personally identifiable information (PII), which they can sell or use for harm.
The risk of a breach can be due to human error, malware or ransomware. Attackers may also exploit vulnerabilities in third-party software and cloud services. A common culprit is compromised credentials, which attackers gain through phishing or password reuse, or by using misconfigured storage or permissions, especially on endpoint devices such as Internet of Things (IoT) products.
For instance, in a 2017 cyberattack against Equifax, 153 million records of personal information were exposed—including names, addresses, birth dates and Social Security numbers—in a breach that took place over several months. Attackers were able to exploit a vulnerability in an older version of a third-party software application that was not updated on Equifax’s servers.
When a breach occurs, companies need to respond quickly to limit the damage. Work with your forensics experts to understand what data was compromised and who had access at the time of the breach, as well as any steps you can take to prevent future attacks. Be sure to share that information with the appropriate people in your organization and consider the impact on consumers, including their privacy, rights and expectations. Write comprehensive communications plans, including letters, websites and toll-free numbers. Include FAQs that address frequently asked questions. Be mindful of how you communicate with the media so that you do not interfere with any ongoing law enforcement investigation.