When there is a suspected data breach, the course of action a chief information
security officer (CISO) should be analysing the situation and making sure the correct
tools and solutions are being implemented. Its also very important to build the correct
team and have ongoing reports sent out. Management of data should be accessed
again. Other data systems should be restricted from being used and patches should be
resolved as well and real time analysis of the breach should be completed as well.
Depending on the data breach bases what type of action to take. If the data is/was
stolen, the contacting person associated with the data should be contacted immediately.
If its based on passwords this could mean a key logger is being used so the
keystrokes of the keyboard should be checked. One data breach and steps to avoid it
would be phishing. Phishing is when someone sends a malicious link in an email or
installs malicious software. Steps to take would to be to install an antivirus, or web
filters can be used to block malicious pages on the web. A lot of people aren't even
sure of what a CISO is being that it has only been around for the last decade or so.
A CISO is simply the senior level executive that handles the execution and the
overseeing of the company's cybersecurity strategy. In case of a suspected data breach,
the course of action of the chief information security officer should take is first of all
planning for disaster recovery. Ensuring the privacy and security of customer data is
another strategy that will help in case of a data breach. Managing responses to
cybersecurity incidents and monitoring the IT environment for vulnerabilities and
abnormal events are also some great strategies that a chief information security officer
(CISO) can take in the case of a suspected data breach. Developing secure business
policies and practices, hiring IT security staff, conducting employee security awareness
training, verifying the company’s compliance with laws and regulations should also be
some of the first things a CISO should look into when possibly facing a suspected
data breach.The type of data breach affects the actions because it affects what needs
to be done, it affects your strategy. You wouldn't use the same strategy you used
towards identity theft when facing malware. In a scenario in which a data breach
occurs, the CISO would have to take action in order to in best case scenario stop the
information from getting into the hands of the intended party. They would do this by
increasing their responsibilities and expanding their ow role within the company. Their
first step would be to stop the leak, by locating the source and containing it. They
would make sure that no more information is released as well as take preventative
measures against potential malware being installed on the company’s data base. The
organization targeted would be contacted by the CISO to inform them of the breach
and to also refresh them on the correct procedures and protocols to handle the
situation. Locking down access to the network database will be crucial to access the
level of damage dealt. The security incident response team would be next on the list
to contact, they will be crucial to determine how the attack was implemented, the
amount of data leaked, what was damaged, and which data was targeted. They will
also investigate suspicious behaviors of employees to help determine the parties
involved in the attack. After this the team and the CISO will put together new
software to prevent the attack from happening again. If a suspected data breach were
to take place, the CISO will be required to take on additional roles and
responsibilities in order to prevent the threat from reaching its intended target or the
loss of important data due to damage or leaks. The CISO would first locate and
contain the threat, preventing it from accessing anymore files or data then it may
already have or releasing malware into the database. During this time, the CISO
should contact the organization to inform them of the possible threat and refresh them
on the approved protocol/steps that will take place. The CISO should then temporarily
lockdown any access to the network database to determine how serious the threat may
be and what damage has been done already. The next step is to inform and update
the Security Incident Response Team about the situation. Together, the team will
gather data and information about how the breach was able to slip through security,
what data was targeted, damaged, leaked or lost, employees data will be scanned for
suspicious activity. The CISO and their team will pick the threat apart to create a new
software that will be prepared for a similar attack and alert security before the threat
is able to access the database. In case of a suspected data breach, the CISO should
first secure the operation. By stabilizing the whole operation, you are protecting any
further data from being stolen. The CISO should lock down all physical access points
and change all all access codes. The CISO Should also shutdown all network
connection temporarily, in case the source of the attack is coming from the network.
Once all of the area's of the operation has been secured, The CISO should deploy
Computer Security Incident Response Team to help identify where the source of the
breach occurred. This team should be able monitor all networking traffic, all source of
communication, and other areas of vulnerability. Once, the threat has been identified
and neutralized, the CISO should look to strengthen that area of weakness. Whether
it's transferring all the sensitive data to a more secure source, monitor network traffic
stricter , granting less access to important information, or installing IDS.The type of
branch effects this action because each threat needs to be handled in different manner.
If the threat is coming from an phishing email, then company would have to start
monitoring the companies email traffic and address it company wide to prevent others
from sending out information to a malicious source.One type of data breach would be
account hacking. A few remedies for an account being hacked is to change the
passwords on the account, backup all sensitive data, or deactivate account/ start a new
account. In a case of a suspected data breach, the CISO would first need to contain
the threat without panic and with a quick response time. After containing the threat
they would need to see how much they can retain that was not loss as they can, and
shut down the system and all servers. The next step would be to figure out if the
breach was internal or external and why the breach occurred. However with different
data breach's steps may change because if a consumer information was hacked they
would then need to get there team to contact consumers. However some data breach's
will be much more serious with more extensive steps for example government top
secret information. A cloud data breach is far more damaging than a regular computer,
because multiple users information will be in the hands of an attacker in single
breach. Furthermore the same steps should be taken, shut down system until the
source of breach is found and resolved. Most cloud data breach is due to the
customers negligence . If there was a data breach the CISO would first need to
contain the threat. Having an intrusion detection system would be beneficial to
minimize the amount of damage a breach could cause. Next, they should shut down
access to any compromised data/servers. The CISO should know exactly what data or
information was compromised and what information was taken. They should deploy
the disaster recovery plan and team. The CISO should be aware if individual’s private
information was compromised and make appropriate notifications if so. Depending on
the type of breach the actions may not be as extensive and time consuming. Some
may be internal mistakes and the CISO would have to adapt or make new policies
and procedures for employees. One example of a data breach could be caused by
phishing. You would need to identify where the email came from and who opened it.
Obtain a copy of said email as well. Ensure all employees are aware of the phishing
email, where it came from, and not to open it. After it is contained and you have
made sure there are no longer any threats, you should have said employees change
their passwords. Provide further security training for employees. If I was CISO and
there was a security data breach first I must remember not to panic. Second, I would
identify that breach, contain the breach before any more damages occurs. Then, I
would create a team of data analysts to identify the severity of the breach then create
another team to create a plan of action in case this were ever happen again. There are
many different types of data breaches that can affect the action plan of the analysts.
For example, when it comes to data breaches there are some are intentional and
unintentional once they identify the right course of action for the breach. One of the
most common types of breaches is phishing. Phishing is when hackers create a
website that replicates a legit website and asking the user to login into their account
when in reality you have just given someone your account information. The course of
the action I would take is to identify where the phishing raised from, second identify
what was affected; contain it and then create a plan of action on what to do if the
issue wherever to a raise. The role of the CISO is to Establishing the right security
and governance practices. Enabling a framework for risk-free and scalable business
operations. In case of a data breach the chief information security officer should
contain the breach. If you react to a breach by panicking and reacting too quickly,
you could make some costly mistakes. Once you have determined where the breach
originated, it is crucial that you contain it. If the breach spreads to other areas of
your organization, it will become a lot more difficult to handle. To reducing the risk
of a data breach, you need to understand where the risk is coming from. There are
two major risk factors, people and devices. A type of data breach could be Malware.
Malware is a common form of cybersecurity attacks. They are a type of software that
infects your entire system. They are caused by tricking a user into clicking on
something such as a pop-up ad that leads to the download of the software onto the
system. This can lead to systems being severely slowed down, or completely crashed.
To prevent future attacks is remedy whatever caused the initial breach to happen.
Consult and understand what kind of protection you need. The first thing a Chief
information security officer should take after a suspected data breach is to isolate the
issue and make sure it is contained. The next step is to shut down the network and
internal servers to make sure there are no other issues. After that there should be
some investigation done to determine what type of data breach it was and how this
affected the company assets.
For example, if there was a data breach that was the result of a phishing scam it
would be a high priority to educate employees and make them more aware of security
issues like malware/phishing scams. Knowing about cyber attacks and preventative
actions is meaningless unless the information is shared with the rest of the company.
Just recently our company sent out a test phishing email to see if employees would
click on it. I would guess at least 25% of our team clicked on it. Even with all of
our continued education and trainings around this and still this many employees fell
for it. In case of a suspected data breach, the course of action a chief information
security officer should take would be to have previously implemented backup servers,
or copies of important data for the organization to continue operating if needed, but
most importantly, immediately turn off the power source to the computer, disconnect
the computer from the network, and/or reinstalling the systems application. These steps
to reacting to the security breach will minimize any damage. The reaction time is
crucial considering any breach so some type intrusion detection system would be
beneficial to detect abnormal behavior within the network. This can help manage and
automate security reactions to intruders. Once the incident is under control, forensic
security team would investigate the incident. Documenting and identifying all parties
involved and how the security breach occurred, and the course of action to resolved
the issue. Depending on the type of breach, if the organization’s security was
compromised and couldn’t prevent further damage to the data breach, some type of
procedure or escalation for this new type of breach would have to take place to find
the appropriate solution/course of action and be implemented for security moving
forward. If a data breach is suspected, the CISO’s response time is critical due to
longer the response time the higher possibility of extensive damage occurring.
Reacting to the incident involves the anticipation of attacks as well as planning
measures to be taken to help restore the services. The incident is to be isolated by
terminating the power supply to the computer in question. The computer is to be
taken off the network to help reduce the chances of higher damage, then the system
applications are reinstalled as an attempt to have the computer back to its proper
operating condition. All data breaches can not be reacted to in the same manner due
to some may be intentional while others may be accidental. Either way the use of an
antivirus and or an IDS can help monitor the network to help reduce the chances of
intentional attacks through the cyber domain. When it comes to physical security using
security password requirements to access the data along with encryption are the best
possibility. A type of data breach would be a worm, these are the most used type of
malware that enters an operating system to spread malicious code. It is self-replicating
and consumes excessive bandwidth, deletes files, or sends files through email which
are infected. To reduce the risk of a worm attack, the user account should be running
as “limited” to prevent installation, modification, or removal of software. Second
firewalls should limit unauthorized network activity with the operating system set to
automatically install system updates. Lastly, an anti-virus software should be installed
and set to scan and update automatically, a paid for antivirus program will have more
benefits and features in comparison to a free program. In the case of a suspected
breach, the CISO should detect a breach fast and discover the details. Whenever there
is a breach, the CISO should be able to detect it at the earliest, before it causes big
damages to the organization. Next, the CISO should assemble the team quickly, and
prepare a plan to recover from the breach. Whenever there is a cybersecurity breach,
the CISO should be able to assemble the Computer Security Incident Response Team
(CSIRT), and get a plan ready to tackle the cyber crisis, gathering information for
detailed analysis, ensuring involvement at all levels. The next step would be to
contain the breach effectively and promptly. Once a breach is detected and the team is
ready to tackle it, the CISO should first seek to plan ways to contain it as effectively
as possible without losing any time. The CISO's role also includes informing the
public and customers. The CISO should also plan to address the security issue with
the public, especially since this is an important step as regards mitigating damages
caused by the incident. Last, the CISO is responsible for taking steps to prevent
further attacks. Once a cybersecurity issue is detected and resolved, plans have to be
made and steps have to be taken to ensure that the same attack wouldn't happen again
and also ensure that other attacks are also prevented.
In the event of a network-based breach, the CISO must make sure that the incident
response plan is in place, and limit the ability of the attacker to access your network.
This step includes blocking IP addresses utilized by known threats or denying servers
and critical infrastructure the ability to directly communicate with the internet. The
next course of action would be to eliminate the files that caused the infection,
including removing the service/application that created the vulnerability, and deleting
or disabling the process/protocol used to launch the cyber attack. The last course of
action would be to remove affected devices from the environment. This includes
restoring affected devices to a known-good state via backups or snapshots, and
powering off the device and disconnecting it from the network. In the case of a
suspected data breach the first thing the CISO should do is to isolate the incident.
After they have isolated the incident they should try to prevent as much loss as
possible. Then they need to investigate what was taken in the breach. They then need
to notify if any personal information was taken from consumers. If found that the
breach was internal instead of external, they need to have the workers change their
passwords in order to protect from future attacks.
The CISO after knowing what type of breach has occurred if preventable in the future
should change policy in order to prevent future breaches. If it were an external device
that was the root cause having a policy in place about personal drives in work
computers would help prevent future breaches. If it was a physical theft of
information making sure that updates are made to the security around that device to
prevent further thefts. If found to be an employee breach limiting access to
information that is not crucial to the job that they perform. A CISO would and should
isolate the breach and mitigate the damage where possible. A CISO will also analyze
the data breach after the attack has been contained in order to assess why it occurred
and resolve any vulnerabilities found.
The type of data breach will determine what actions are taken. A breach in
Confidentiality can result in exposure to personal data. This could be due to a lack
of encryption use for storing and transmitted data. The law requires for the
organization to notify parties who were exposed and mitigation of the risk in the
future requires different policies and technology. A breach in Integrity can result in
data being altered. The cause of this integrity breach can be the result of a lack of
anti-virus on computers or the lack of application/hardware controls. The CISO would
potentially have to find a means to restore data that is damaged by the breach and
mitigate any future risks by installing controls mentioned earlier. A breach in
Availability can result in a loss of access to information resources. The CISO would
have to identify where and why the loss of access occurred and determine if there is
a redundant means to get users back online.
One specific course of action to mitigate a breach of Availability is to create
redundancies in your organizations infrastructure. This can be done via the network or
server level. For instance, an organization can decide to have a primary and back up
circuit connection to the internet so that if one connection is lost then the back up
kicks in. For the perspective of the server, redundancy would translate into having a
RAID for your storage device. In the case of a suspected data breach, a chief
information security office has a few priorities: safety, security, and awareness. Safety
comes in the form of ensuring all systems and people are safe from harm. Harm
could be destruction of property, acquired information endangering someone's physical
safety, or potential financial losses due to compromised information. Security requires
a CISO getting to the root of the breach, determining to what extent the problem is,
resolving up the problem, and placing in safeguards to prevent such breaches from
happening again. Awareness is alerting all persons whose information could have been
compromised. In some cases, that's as simple as resetting all users' passwords. In other
cases, the remediation process is more complicated and requires more of a payout.
Different types of breaches (cyber, stolen paper receipts and banks statements,
recovered pin numbers and passcodes) require different reactionary responses and carry
different levels of responsibility. In the case of a cyber data breach, a CISO would
need to locate the entry point into the system of the breach, sure up the system
defenses and install programs to prevent similar breaches, and send out virtual alerts
to all users on the platform to be aware and change passcodes. The role of CISO is
the overall management of security for the information technology and report to the
CEO of potential risk associated with their information technology. The CISO will
give out responsibilities to handle the breach. In data breaches, the first thing is assess
the severity of the breach. Depending on the type of attack, they will launch a
counterattack plan. After they have taken action against the attack, they will launch
recovery actions to retrieve the loss of information or analyze for any data corruption.
At the end, they will evaluate the cause of the breach and the monetary value of the
attack to the business. The CISO will have to implement the new findings if any into
the policies to prevent future similar breaches. They will train the employees to the
new procedures.
One type of breach is the Phising attacks. They are attacks that imitate a legitimate
site and trusted source created by hackers to trick users into voluntarily inputting their
sensitive information. They could ask for usernames, passwords, or other information.
The links could lead to unknown sites that give hackers control of the information.
They should notify the information security teams so they are aware of the situation.
Another time sensitive step would be to run a full security scan on the device used to
catch lingering malware or intrusion of viruses that could corrupt the data. Then the
users must immediately change passwords or information that was given out. If credit
cards are compromised the course of action is to cancel or change the cards. For SSN
theft notify the credit bureau to lock the SSN to avoid identity theft. The next step is
to evaluate the attack and the cost associated and conduct proper training for future
attacks. we have to understand that the reason why we would expect the CISO to
handle the suspected security breach, is because he/she is the second at hand after the
CEO. With that being said normally the CISO would have various measures in place
to make sure this doesn't happen. In the case that it does happen the CISO will have
to gather is team together to pull the data where the breach was formed. Advise all
parties that were effected by the breach and the measures that are to be taken to get
it under control.The type of breach varies widely based on the company that it has
effected. For example, credit card breach which holds a lot of personal data can hit
consumers the hardest causing them not to have access to there funds when needed
due to cards being locked hoping to avoid fraud and identity theft. SOP's(Standard
Operational Procedures) if not already should be put into place so that everyone will
know how to handle these case as the come to surface. There are many different
types of data breaches. These range from stolen information to DDoS. The most
common types of data breaches and one of the most important to protect against is
stolen information. This could include anything from stolen email addresses to
passwords to credit card information. Stolen information is one of the most devastating
types of data breaches that can happen to a company. This can have a lasting impact
on a company and could even send them out of business and into bankruptcy.
ransomware is another type of data breaches that could happen to a company. This is
when a company is breached and their information on computers and servers is locked
and the only way to get it back is to pay the ransom fee. One large data breach was
back in 2014 when eBay was breached by someone having access to 3 different
coorperate employees credentials. This allowed the breachers to have access to all of
it's customers personal information including emails, passwords, and other personally
identifiable information. eBay attempted to hide this but it was evenually revealed that
the hackers had access to the accounts for more than 229 days. This could have been
avoided or at least noticed sooner if eBay would have had better password renewal
process. If an organization has a data breach, a chief information security officer
(CISO) could take a few approaches, such as; engaging the incident management
team, as well as gaining an understanding of how the breach took place. A large
number of security breaches stem from unintentional mistakes made by employee
carelessness. If an employee is not aware of the damage he or she can cause simply
by opening an email, and clicking on a link, there is not too much the company can
do about it. However, if the employee took the security training and education where
the harm of clicking on links and downloading a worm, virus, or spyware was
explained in detail, and the employee electronically signed stating they agree with the
information and the repercussions involved, the organization can use that information
in court if the employee sued them. I work in a company that will not only explain
what the employee did wrong, it may include terminating the employee for the action.
The employee would typically retain a lawyer and attempt to sue the organization for
wrongful termination stating, "they just did not know". The CISO and Human
Resources (HR) could bring that electronically signed paper to court, and most likely
would dismiss the accusation. A CISO should begin by first analyzing the alert and
determine if it’s a true attack. There are times when someone could forget a password
and used someone else’s login to finish work or something to that effect. The CISO
needs to notify his response team and have them look to see if the attack is real once
that is determined then the following actions should be take place.
1. Shut off whatever they are using to access information
2. That means either unplugging hardware or executing a shut off command
3. See what was taken and or damaged
4. Looking for where the leak is how it happen as well while taking notes
5. Make a report of the incident and catalog all areas of vulnerability
6. Fix where the leak occurred and fortify security
7. Determine if it was an outside attack or fromwith in
8. Deal with the leak if its from within the company
9. Reset all users’ passwords and apply any needed restrictions
10. Notify public of information leak to save face and begin earning back trust
11. Begin recovery and gaining back trust of those data that was lost
There are several forms of data breach, like there are different ways to rob a bank.
1. Employee error
2. The employee opened a phishing email or easy password
3. Cyber attack
4. Coming through internet links or searches using malware
5. Social engineering
6. Employees or other taking information from servers or other data storage and
then trading it to attackers or selling it on the black-market, and or allowing
someone inside that will attack the organization
7. Unauthorized access
8. Someone allowed to wait at a desk or something akin to that, they then look
for things like personal Data and other HR related items or attempt to steal
company secrets
9. Ransomware
10. It is new but it attacks a company and stea lsdata or locks out users and
demands money to be removed, or information regarding the decryption key
11. Malicious Insider
12. Someone actively plotting to either steal andor sabotage an organization
13. Physical theft
14. They steal something
Each one requires a different response and different program to protect. The bulk is
done with physical security and monitoring as well as cyber to prevent these attacks.
If an employee user information ever become vulnerable and taken the following
actgions need to occur. Immediate access denial and user deleted then information
gathered on what was stolen and taken and determine if the employee did it on
accident or purpose. Then notify the CISO and being recovery protocols
In case of a suspected data breach, what course of action should a chief
information security officer (CISO) take?
When there is a security breach, it think that the CISO course of action should be a
few things. Building a team that can provide security analysis who can provide
analysis and assess vulnerabilities in the infrastructure. A system engineering, who can
perform security monitoring. traffic analysis, intrusion detection. Also, installing
antivirus software should be installed, also, contacting the people who the data breach
affected.
How does the type of data breach affect the actions? zz
There are many causes for a data breach, it can affect a business, whereas, if in the
wrong hands,, it can cause the business to loose financially. Also, if it is customer
related, hackers can obtain personal information from the customer. Personal
information that is in the wrong hands can cause identify theft.
Select 1 type of data breach and the course of action that should be taken. zz
A data breach that comes to mind is human error. Sometimes humans who are very
busy can make common mistakes, like sending personal information to a wrong party.
Sometimes in human error, information can be entered incorrectly as well., Leaving a
computer unlocked can cause someone to obtain information. Talking about a
customer's information or writing specific personal data down and not destroying it
can lead to a data breach. As we know that data breach is an incident where
information is stolen from a system without the knowledge or authorization of the
system's owner. Stolen data may involve sensitive, proprietary, or confidential
information such as credit card numbers, customer data, trade secrets, pictures or
matters of national security.
In this event, The CISO should make sure that all employees of the organization
change their passwords, assemble the team after the disaster strikes to determine what
went wrong in a breach, dealing with those responsible if they're internal, and
planning to avoid repeats of the same crisis. Physical security is also a major concern.
The statistics discussed earlier reveal that the loss/theft of media such as laptops, data
cards, phones etc. account for major security breach incidents. Since physical security
breaches are the highest among personal devices, individual users must be careful
about securing their computing gadgets. Data breaches are not always intentional.
Users can accidentally send protected data to the wrong email address or upload it to
the wrong share. Social engineering is very common way for data breach its a
manipulation technique that exploits human error to gain private information, access,
or valuables. In cybercrime, these scams tend to lure unsuspecting users into exposing
data, spreading malware infections, or giving access to restricted systems. Attacks can
happen online, in-person, and via other interactions. Implementing security applies to
any database whether it was a personal computer or or a large corporation and by
applying the security steps ( precaution, maintenance, and reaction) if there is a
suspected data breach we would be in the reaction step and the CISO would have to
investigate what type of threat it is and where exactly did it come from to provide
the right course of action, for example if it was internal and a mistake by one of the
employees a new measures of security needs to be discussed and maybe more training
for said employee.Of course the type of threat would affect the action and the
outcome, let say an organization with a big number of personal data of costumers and
the breach was intended to steal personal info such as banking Info or credit cards
information, the organization would be responsible for any damage to the costumers
and would have to work on developing a new security plan maybe adding more
firewalls or changing anti viruses as well as using IDS (Intrusion Detection Systems).
In case of suspected data breach, the CISO would gather his team together and have
them analyze the situation and determine if there are any immediate threats. If a
breach has occurred, then the CISO would set a plan into action to seal off the
breach, investigate how it happened and communicate with the appropriate people
about the incident. Once the breach has been fixed and the investigation has been
completed. The CISO will develop a policy to prevent it from happening again.
Depending on the type of breach, that will determine the policy that will be put into
place. If it was an outside intrusion into the network, then measure will be put in
place to prevent that. That also goes for user error or a user purposely attacking the
company’s network from the inside. If the breach was caused from an employee
stealing data. A policy can be put in place that would eliminate the use of any type
of electronic storage devices or cameras to prevent data being taken out of the
building. When reading over the chapter I think as a chief information security officer
is to first see how the breach occurred. The breach could have happen by simply a
worker placing a flash drive in the computer and by them doing that the system
might have caught a virus. We offer see this when we are using our bank cards and
one minute is working and the next it has stop working. Knowing how the breach
happened helps to find where to start. One solution that should take place is making
sure that all firewall are updated and is also Norton is used. The reason I said Norton
is because it does do a cleaning on the computer and system. It is real important that
the chief let the customer(s) know what is going on and if their information has been
compromised and what action the company is taking to fix this issues. Giving the
customer(s) a firm solution and understand that this matter is important to the
company. I also think that the information should be back up on a backup storage
system. CISO is a management/leadership position in most companies. It would NOT
normally be the CISO that wades in and assesses the damage, does forensic analysis,
nor puts controls in place to prevent further attacks. The CISO would set policy,
advise, follow-up, and consult.