Breach intro video

Quick video on breaches!  Stay alert to what can happen!


Contact us by filling out this form - Contact Us



Purchase our DLP Solution and help prevent breaches


Breaches

"It's not a matter of if....but when".   If you have never heard of that phrase, you should get familiar with it, as it is hand in hand with the word "breach".

A breach, also known as a "data breach", can come in a variety of formats and doesn't necessarily have to mean a failure in the network, computer systems, databases, or anything else digital or electronic.

For example, in the State of Arizona, boxes full of papers were discovered in an alley, containing hundreds of records.  This wasn't a data breach from a digital or electronic standpoint, but it still was, as data that was supposed to be protected and confidential was left for anyone to find in an alley.

You can also experience a data breach through a simple user permissions error.  There have been cases where a person emailed a link to sensitive data to the wrong recipient.  If the wrong individual accessed the data, then we have another data breach.  

Another perfect, and common, example is when someone clicks a phishing link and either encounters ransomware or a backdoor into a protected environment.  This could lead to a data breach and some serious issues for the company and the individual.  However, if ransomware encrypts and ransoms the data, that doesn't necessarily mean there is a data breach.  For a data breach to happen, data must be accessed by persons who should not have access to it.  This means that a data breach could occur internally or externally to a company, involving persons who don't work for the company as well as those who do.

A prime example of this would be the situation involving Britney Spears, where hospital workers were curious about her medical records and felt the need to satisfy their curiosity.  This was a data breach (a very small one) and also a crime.

Should you feel like you have a breach situation, you should also understand a few things to protect yourself and your company.
1. What type of data was breached?  Some data breaches are required by federal law, depending on the type of data.
2. What are the state laws for data breaches?  Some states require breach notification for as few as 100 records, while other states require a higher number.  As a company employee, you will need to understand this, as you may "legally" not be required to notify anyone of a breach, or you may be violating the law if you don't.
3. If there is a breach, and you must report it, how will you report the breach?  Again, some laws require a specific method of reporting or notifying affected individuals (Data Subject Owners if we are referencing GDPR).
4. Do you have cyberinsurance?  You should, if you don't, as the average cost of a data breach is around $200 per record stolen.

To visualize the impact of data breaches, check out this link, which details breaches worldwide.

Need to validate the security of your suppliers?  Our Prosikon platform can help reduce your risk.

Arrakis can help you avoid a data breach and also act as a trusted agent or advisory during your difficult time of dealing with data breaches. If you are in trouble, give us a call.

We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us