A Quick Guide to Data Breach
Data breach is actually either unintentional or intentional release of private/confidential or secure information to untrustworthy environment. Some other terms for this phenom include data leak, data spill and also, unintentional information disclosure. Such incidents might range from organized attack by black hats associated with organized crime, national governments or political activities to careless disposal of used data storage media or computer equipment and systems.
The most basic definition when it comes to data breach is being a security incident wherein sensitive, confidential or protected data is transmitted, viewed, copied, stolen or even used by individual unauthorized to do so. Data breaches might also involve financial information like bank details or credit card, PHI or Personal Health Information, PII or Personal Identifiable Information, intellectual property or trade secrets of corporations. Most of the data breaches are involving vulnerable and overexposed unstructured files, data, documents as well as sensitive information.
This can also include incidents like theft or even loss of digital media similar to hard drives, computer tapes or even laptops or computers that contain media upon which the information is stored unencrypted, posting the information on the internet or on computer. Otherwise accessible from the web without proper information security precautions, transfer of this information to a system which isn’t open completely but isn’t formally or appropriately accredited for security at approved level like transfer of such info to information systems of a possible hostile agency like a foreign nation or competing corporation where the data can be exposed to a more intensive techniques in decryption.
The concept of trusted environment is somewhat fluid actually. The departure of trusted staff members with accessibility to sensitive info might be a data breach if the staff member has retained access to data subsequent to the termination of trust relationship. In relation to distributed systems, it might take place with breakdown in web of trust.
As a matter of fact, most of these incidents are publicized in media involving private info on individuals like social security numbers and the likes. Losing corporation similar to sensitive corporate info, details of contracts, trade secrets and so on or of government information is unreported all too often. This is mainly because of the reason that there is no compelling reason to do such in the absence of potential damage to the private citizens and even publicity around such event may be more damaging than losing the data itself.
When it comes to this situation, data breach lawyer is often called upon to be able to settle things and at the same time, to apply the right legal action.