A data breach happens when data is accessed, modified, or deleted without authorization. Security weaknesses can lead to incidents ranging from an accidental data leak to a malicious database breach – and the effects can be devastating. Learn how data breaches happen and the steps you can take to protect yourself and your business.
Cybercriminals flood a target website or network with requests until its resources become unavailable to legitimate users, resulting in a denial of service. Although it is not a data breach in itself, a DDoS attack can be used to divert the attention of IT or security staff while malware is installed.
A form of malicious software (malware), ransomware allows cybercriminals to encrypt data on the target network and demand a ransom payment to restore it. In the event of a data breach, this may be combined with the attacker viewing, copying, or exporting data from the network before encrypting it and threatening a data leak if the ransom is not paid. However, it’s important to note that payment does not guarantee the safe return of data.
Many web applications use SQL databases to store important data and sensitive information, such as customers’ usernames, passwords, and credit card details. In an SQL injection attack, cybercriminals exploit security flaws to manipulate the queries an application makes to its database, allowing them to access, modify, or delete data.
A cybercriminal may contact a victim by email, phone, or text message pretending to be a trusted contact. The attacker then convinces the victim to download malware or a virus – often by opening an attachment or clicking a link – or they may fool them into handing over data directly.
A criminal insider is someone – often an employee or contractor who may or may not have legitimate authority to access sensitive information – who abuses their position in order to leak data. Their motivation is usually personal profit or to cause harm to the organization.
Conversely, an accidental insider is someone who unintentionally causes a cybersecurity breach, such as falling victim to a phishing attack, using an unauthorized personal device, or through poor password management. Employees who have not had basic cybersecurity training are a vulnerability to their employer.
Any physical device, such as an unsecured laptop, hard drive, mobile phone, or USB containing sensitive information that is lost or stolen could put your business at risk.
It may seem like large companies are the main targets of data breaches, possibly because they make headlines when it happens, but small businesses and individuals are equally at risk. The following data breach examples highlight just how much damage they can cause.
In early 2020, Cam4, a small business that provides an adult streaming service, became the victim of one of the largest data breaches ever recorded. A misconfigured database allowed the release of 10.88 billion user records. The data stolen included customers’ personally identifiable information (PII) such as names, email addresses, and chat transcripts.
The popular email service, Yahoo, disclosed two data breaches in 2016, which affected all three billion of its user accounts.
The first attack was initiated by a phishing email. Attackers were able to access the names, email addresses, passwords, dates of birth, and telephone numbers of users. The breaches wiped an estimated $350 million off the company’s market value, and several shareholders filed lawsuits following the disclosures.
The Equifax breach was entirely preventable. In 2017, hackers exploited an unpatched – but known – vulnerability in a system used to build the credit reporting agency’s web application.
The data of more than 143 million individuals was compromised, including names, addresses, dates of birth, and even driving license information. The company reported that the breach cost $1.4 billion. Surprisingly, no fraud or identity theft cases have been connected with the incident.
Data privacy is covered by various laws and regulations around the world, and depending on where you or your customers are located, they may be different. If your business is a victim of a data breach, there are certain steps you must follow, so it’s important to know what is required of you. This will be affected by:
Where you do business
Where you store personally identifiable information (PII)
What type of PII your company maintains
Where the individual data subjects of the PII reside
Widely considered the world’s strongest set of rules governing data protection, GDPR was put into force by the European Parliament in May 2018. Here is a brief overview of the requirements relating to data breaches:
Personal data must be protected against "unauthorized or unlawful processing”.
You must report to a country’s data protection regulator the "destruction, loss, alteration, unauthorized disclosure of, or access to" people’s data where it could have a detrimental impact on the data subjects.
In the UK, a breach must be reported to the ICO within 72 hours of discovery.
If a breach puts individuals at risk, you must inform them, too. This should be done as soon as possible.
Even if a data breach does not require notification, you must still keep a record of it.
While the US doesn’t have a federal law governing notification following a data breach, certain states have their own data privacy laws, and you will need to be aware of the provisions for each. Well-known US regulations include the California Consumer Privacy Act (CCPA) and the Health Insurance Portability and Accountability Act (HIPAA).
If you’re unlucky enough to be on the receiving end of a data breach disclosure, there are several things you can do to improve your security:
Change your passwords on all accounts. Whether an account was affected by the breach or not, it’s wise to change all of your passwords. Choose long, complex passwords and activate two-factor authentication (2FA) where possible.
すべてのアカウントのパスワードを変更します。 アカウントが違反の影響を受けたかどうかに関係なく、すべてのパスワードを変更することをお勧めします。長くて複雑なパスワードを選択し、可能な場合は2要素認証(2FA)をアクティブにします。
Contact your bank or other financial institutions. Let them know that you’ve been the subject of a data breach, and ask them to check for any fraudulent activity. Request fraud alerts and consider changing your account details or replacing cards.
銀行または他の金融機関に連絡してください。 あなたがデータ漏洩の対象になっていることを彼らに知らせ、不正行為がないか確認するように依頼します。詐欺の警告をリクエストし、アカウントの詳細を変更するか、カードを交換することを検討してください。
Update your software. Install any pending updates to shore up potential vulnerabilities.
ソフトウェアを更新します。 潜在的な脆弱性を強化するために、保留中の更新をインストールします。
Be proactive. Learn about potential threats and make sure you know how to spot signs of suspicious activity. Stay alert for any future data issues.
積極的に。 潜在的な脅威について学び、疑わしい活動の兆候を見つける方法を知っていることを確認してください。今後のデータの問題に注意してください。
In 2020, the average cost per lost or stolen record in a data breach was $146, so the impact of a significant breach could be devastating, particularly for a small business. Fortunately, there is plenty you can do to make it harder for cybercriminals to infiltrate your systems and get their hands on your data.
Follow the steps below to ensure that you have a solid security foundation in place:
Install firewalls. The first line of defense in protecting your network, a firewall will prevent any unauthorized traffic or malicious software from entering your network.
ファイアウォールをインストールします。 ネットワークを保護するための最前線であるファイアウォールは、不正なトラフィックや悪意のあるソフトウェアがネットワークに侵入するのを防ぎます。
Install antivirus. A comprehensive business antivirus solution will proactively block, detect and remove threats like malware, and should also provide anti-phishing protection.
アンチウイルスをインストールします。 包括的なビジネスウイルス対策ソリューションは、マルウェアなどの脅威をプロアクティブにブロック、検出、削除し、フィッシング対策も提供する必要があります。
Install encryption software. Protect sensitive information by making it unreadable to unauthorized users.
暗号化ソフトウェアをインストールします。 機密情報を許可されていないユーザーが読み取れないようにすることで、機密情報を保護します。
Use a VPN or Zero Trust Network. Only send data via secured channels to avoid being intercepted by an unauthorized person.
VPNまたはゼロトラストネットワークを使用します。 権限のない人に傍受されないように、セキュリティで保護されたチャネルを介してのみデータを送信してください。
Use strong passwords. Require the use of complex and unique passwords for every user account and enforce regular password changes.
強力なパスワードを使用してください。 すべてのユーザーアカウントに複雑で一意のパスワードの使用を要求し、定期的なパスワード変更を実施します。
Educate employees. Highlight the importance of cybersecurity and train employees to recognize cybersecurity threats and take appropriate action.
従業員を教育します。 サイバーセキュリティの重要性を強調し、サイバーセキュリティの脅威を認識して適切な行動を取るように従業員を訓練します。
Communicate. Regularly remind employees of the dangers of clicking on links or attachments in emails from unfamiliar senders.
コミュニケーションする。 見知らぬ送信者からの電子メール内のリンクまたは添付ファイルをクリックすることの危険性を従業員に定期的に思い出させます。
Encourage accountability. Make sure every staff member is aware of their personal roles and responsibilities in protecting the company’s data.
説明責任を奨励する。 すべてのスタッフが、会社のデータを保護する上での個人的な役割と責任を認識していることを確認してください。
Set up new starters. Identify the specific data, devices, and access privileges new starters need.
新しいスターターを設定します。 新しい初心者が必要とする特定のデータ、デバイス、およびアクセス権限を特定します。
Process leavers. Adopt a controlled exit policy for leavers, including prompt group password resetting.
脱退者を処理します。 グループパスワードの迅速なリセットなど、脱退者には管理された終了ポリシーを採用します。
Review returned devices. Wipe or securely destroy data where necessary.
返品されたデバイスを確認します。 必要に応じて、データをワイプまたは安全に破棄します。
Stay up to date. Scan your network and devices frequently and check for necessary upgrades. Install any updates or patches from trusted software providers as soon as possible. Consider using software that can automate this process or alert you to anything that needs attention.
最新に保つ。 ネットワークとデバイスを頻繁にスキャンし、必要なアップグレードを確認します。信頼できるソフトウェアプロバイダーからの更新またはパッチをできるだけ早くインストールしてください。このプロセスを自動化できるソフトウェアの使用を検討するか、注意が必要なことを警告してください。
Prepare. Create an Emergency Response Plan that outlines how to handle a breach, theft, or loss of data.
準備します。 データの漏洩、盗難、または損失を処理する方法の概要を示す緊急対応計画を作成します。
Make copies. Regularly back up your data so you can easily restore it if the worst happens.
コピーを作成します。 最悪の事態が発生した場合に簡単に復元できるように、定期的にデータをバックアップしてください。
While cybercriminals are continuously devising new ways to detect and exploit business vulnerabilities, some security weaknesses can be easily prevented by implementing best practices. Here are some of the most common vulnerabilities and what to do about them.
Weak credentials are an easy win for cybercriminals. Create a requirement for employees to use unique, complex passwords for every account, and use two-factor authentication (2FA) on sensitive accounts.
If your employees use their personal devices for work – which they often do – you have far less control over security standards, such as passwords, who else has access to the device, and use of public Wi-Fi. Implement a bring your own device (BYOD) policy that sets out clear expectations for each employee, and spend some time on training to highlight the potential threats.
従業員が自分の個人用デバイスを仕事に使用する場合(よくあることですが)、パスワード、デバイスにアクセスできる他のユーザー、パブリックWi-Fiの使用などのセキュリティ標準を制御することははるかに困難です。各従業員に明確な期待を設定するBYOD(Bring Your Own Device)ポリシーを実装し、潜在的な脅威を強調するためのトレーニングに時間を費やします。
If you are running software that has an update or patch available but not installed, you are exposing your business to risk. Ensure that all software is fully patched and updated.
The most effective way to safeguard your business is to follow best practices and use a wide range of security tools to build multiple layers of protection. Avast Business offers cybersecurity solutions that defend your business against data breaches using a combination of next-gen endpoint protection and cloud-based network security solutions. Keep your data in the right hands.
Intel®、インテル®、Intel® ロゴ、Atom™、Core™、Xeon®、Phi™、Pentinum®は、米国およびその他の国におけるIntel® Corporation の商標です。 NVIDIA®、NVIDIA®ロゴ、GeForce、Quadroは、米国NVIDIA® corporationの登録商標です。 AMD®, AMD® Arrowロゴ、ならびにその組み合わせは、Advanced Micro Devices, Inc.の商標です。 Microsoft®(その他商標・登録商標名)は、米国 Microsoft® Corporation の米国およびその他の国における登録商標または商標です。 Windows®の正式名称は、Microsoft® Windows® Operating Systemです。 Linux® は、Linus Torvalds 氏の米国およびその他の国における登録商標です。 RED HATとShadowman logoは米国およびそのほかの国において登録されたRed Hat, Inc. の商標です。 CentOSの名称およびそのロゴは、CentOS ltdの商標または登録商標です。 Ubuntu は Canonical Ltd. の登録商標です。 Linux Mint は Linux Mark Institute の商標です。 IMSL® は、米国およびその他の国における Rouge Wave Software, Inc. の商標です。 Avast™ は、Avast Software の商標です。 AVG® は AVG Technologies の登録商標です。 Python® はPSFの登録商標です。 その他、記載されている会社名、製品名は、各社の登録商標または商標です。 | ||