Breach has become a common word in the IT world, however a recent article by Ashley Watters published on comptia.org reminds us that because the meaning of the word breach has been changing recently, you must be very careful about using it. For many years technologists used the word to refer to anytime some unauthorized person accessed the local network. It meant that someone who was not supposed to have access had gotten past the firewall.
In the past it did not necessarily mean that they took any data or even did any damage, just that something happened that was not supposed to happen.
Due to the new privacy rules, today the term breach has come to mean that there was a compromise of Personally identifiable information (PII). Knowledge of a compromise of PII will trigger various regulatory actions, depending on what industry you are in. As soon as you know about a breach, a clock starts ticking. So, you never want to use that word unless you mean it and are ready to act.
Speaking of actions, do you have an incident response plan in place so that you are ready to jump into action as soon as you know about a problem like a breach? I have written a few articles about all the layers of security that you can put in place to prevent a breach, but I have also pointed out that no protections are complete, there is always a chance that even with all the protections, someone could still get through.
What to do if you do have an INCIDENT
- Assemble your team and implement your response plan. You have one now, right?
- Get your cyber insurance company involved right away. You have that too, right?
- Document your actions. – You will need to document what you know, when you knew it and what and when you took various actions.
- Only communicate what is verified. Be careful about inadvertently giving false statements, only communicate what you really know.
- Follow the advice of experts – your incident response plan has got those all lined up right?
Resolving a cyber incident comes down to being prepared and taking well planned out, careful action in a timely manner. Get all the help you can and do it ahead of time. If you want to read the source article for the details, you can find it here on Comptia.org – Why You Should Never Use the Word Breach (comptia.org)
If you would like to talk about how you can prevent incidents AND prepare for them, I am happy to talk to you about that.