When there is a suspected data breach, the course of action a chief
information security officer (CISO) should be analysing the situation and
making sure the correct tools and solutions are being implemented. Its also
very important to build the correct team and have ongoing reports sent out.
Management of data should be accessed again. Other data systems should be
restricted from being used and patches should be resolved as well and real
time analysis of the breach should be completed as well. Depending on the
data breach bases what type of action to take. If the data is/was stolen, the
contacting person associated with the data should be contacted immediately. If
its based on passwords this could mean a key logger is being used so the
keystrokes of the keyboard should be checked. One data breach and steps to
avoid it would be phishing. Phishing is when someone sends a malicious
link in an email or installs malicious software. Steps to take would to be
to install an antivirus, or web filters can be used to block malicious pages
on the web. A lot of people aren't even sure of what a CISO is being
that it has only been around for the last decade or so. A CISO is simply
the senior level executive that handles the execution and the overseeing of
the company's cybersecurity strategy. In case of a suspected data breach, the
course of action of the chief information security officer should take is first
of all planning for disaster recovery. Ensuring the privacy and security of
customer data is another strategy that will help in case of a data breach.
Managing responses to cybersecurity incidents and monitoring the IT
environment for vulnerabilities and abnormal events are also some great
strategies that a chief information security officer (CISO) can take in the
case of a suspected data breach. Developing secure business policies and
practices, hiring IT security staff, conducting employee security awareness
training, verifying the company’s compliance with laws and regulations should
also be some of the first things a CISO should look into when possibly
facing a suspected data breach.The type of data breach affects the actions
because it affects what needs to be done, it affects your strategy. You
wouldn't use the same strategy you used towards identity theft when facing
malware. In a scenario in which a data breach occurs, the CISO would have
to take action in order to in best case scenario stop the information from
getting into the hands of the intended party. They would do this by
increasing their responsibilities and expanding their ow role within the
company. Their first step would be to stop the leak, by locating the source
and containing it. They would make sure that no more information is
released as well as take preventative measures against potential malware being
installed on the company’s data base. The organization targeted would be
contacted by the CISO to inform them of the breach and to also refresh
them on the correct procedures and protocols to handle the situation. Locking
down access to the network database will be crucial to access the level of
damage dealt. The security incident response team would be next on the list
to contact, they will be crucial to determine how the attack was
implemented, the amount of data leaked, what was damaged, and which data
was targeted. They will also investigate suspicious behaviors of employees to
help determine the parties involved in the attack. After this the team and the
CISO will put together new software to prevent the attack from happening
again. If a suspected data breach were to take place, the CISO will be
required to take on additional roles and responsibilities in order to prevent
the threat from reaching its intended target or the loss of important data due
to damage or leaks. The CISO would first locate and contain the threat,
preventing it from accessing anymore files or data then it may already have
or releasing malware into the database. During this time, the CISO should
contact the organization to inform them of the possible threat and refresh
them on the approved protocol/steps that will take place. The CISO should
then temporarily lockdown any access to the network database to determine
how serious the threat may be and what damage has been done already. The
next step is to inform and update the Security Incident Response Team about
the situation. Together, the team will gather data and information about how
the breach was able to slip through security, what data was targeted,
damaged, leaked or lost, employees data will be scanned for suspicious
activity. The CISO and their team will pick the threat apart to create a new
software that will be prepared for a similar attack and alert security before
the threat is able to access the database. In case of a suspected data breach,
the CISO should first secure the operation. By stabilizing the whole operation,
you are protecting any further data from being stolen. The CISO should lock
down all physical access points and change all all access codes. The CISO
Should also shutdown all network connection temporarily, in case the source
of the attack is coming from the network. Once all of the area's of the
operation has been secured, The CISO should deploy Computer Security
Incident Response Team to help identify where the source of the breach
occurred. This team should be able monitor all networking traffic, all source
of communication, and other areas of vulnerability. Once, the threat has been
identified and neutralized, the CISO should look to strengthen that area of
weakness. Whether it's transferring all the sensitive data to a more secure
source, monitor network traffic stricter , granting less access to important
information, or installing IDS.The type of branch effects this action because
each threat needs to be handled in different manner. If the threat is coming
from an phishing email, then company would have to start monitoring the
companies email traffic and address it company wide to prevent others from
sending out information to a malicious source.One type of data breach would
be account hacking. A few remedies for an account being hacked is to
change the passwords on the account, backup all sensitive data, or deactivate
account/ start a new account. In a case of a suspected data breach, the
CISO would first need to contain the threat without panic and with a quick
response time. After containing the threat they would need to see how much
they can retain that was not loss as they can, and shut down the system
and all servers. The next step would be to figure out if the breach was
internal or external and why the breach occurred. However with different data
breach's steps may change because if a consumer information was hacked
they would then need to get there team to contact consumers. However some
data breach's will be much more serious with more extensive steps for
example government top secret information. A cloud data breach is far more
damaging than a regular computer, because multiple users information will be
in the hands of an attacker in single breach. Furthermore the same steps
should be taken, shut down system until the source of breach is found and
resolved. Most cloud data breach is due to the customers negligence . If
there was a data breach the CISO would first need to contain the threat.
Having an intrusion detection system would be beneficial to minimize the
amount of damage a breach could cause. Next, they should shut down access
to any compromised data/servers. The CISO should know exactly what data
or information was compromised and what information was taken. They should
deploy the disaster recovery plan and team. The CISO should be aware if
individual’s private information was compromised and make appropriate
notifications if so. Depending on the type of breach the actions may not be
as extensive and time consuming. Some may be internal mistakes and the
CISO would have to adapt or make new policies and procedures for
employees. One example of a data breach could be caused by phishing. You
would need to identify where the email came from and who opened it.
Obtain a copy of said email as well. Ensure all employees are aware of the
phishing email, where it came from, and not to open it. After it is
contained and you have made sure there are no longer any threats, you
should have said employees change their passwords. Provide further security
training for employees. If I was CISO and there was a security data breach
first I must remember not to panic. Second, I would identify that breach,
contain the breach before any more damages occurs. Then, I would create a
team of data analysts to identify the severity of the breach then create
another team to create a plan of action in case this were ever happen
again. There are many different types of data breaches that can affect the
action plan of the analysts. For example, when it comes to data breaches
there are some are intentional and unintentional once they identify the right
course of action for the breach. One of the most common types of breaches
is phishing. Phishing is when hackers create a website that replicates a legit
website and asking the user to login into their account when in reality you
have just given someone your account information. The course of the action
I would take is to identify where the phishing raised from, second identify
what was affected; contain it and then create a plan of action on what to
do if the issue wherever to a raise. The role of the CISO is to
Establishing the right security and governance practices. Enabling a framework
for risk-free and scalable business operations. In case of a data breach the
chief information security officer should contain the breach. If you react to a
breach by panicking and reacting too quickly, you could make some costly
mistakes. Once you have determined where the breach originated, it is crucial
that you contain it. If the breach spreads to other areas of your organization,
it will become a lot more difficult to handle. To reducing the risk of a
data breach, you need to understand where the risk is coming from. There
are two major risk factors, people and devices. A type of data breach could
be Malware. Malware is a common form of cybersecurity attacks. They are
a type of software that infects your entire system. They are caused by
tricking a user into clicking on something such as a pop-up ad that leads
to the download of the software onto the system. This can lead to systems
being severely slowed down, or completely crashed. To prevent future attacks
is remedy whatever caused the initial breach to happen. Consult and
understand what kind of protection you need. The first thing a Chief
information security officer should take after a suspected data breach is to
isolate the issue and make sure it is contained. The next step is to shut
down the network and internal servers to make sure there are no other
issues. After that there should be some investigation done to determine what
type of data breach it was and how this affected the company assets.
For example, if there was a data breach that was the result of a phishing
scam it would be a high priority to educate employees and make them more
aware of security issues like malware/phishing scams. Knowing about cyber
attacks and preventative actions is meaningless unless the information is shared
with the rest of the company.
Just recently our company sent out a test phishing email to see if employees
would click on it. I would guess at least 25% of our team clicked on it.
Even with all of our continued education and trainings around this and still
this many employees fell for it. In case of a suspected data breach, the
course of action a chief information security officer should take would be to
have previously implemented backup servers, or copies of important data for
the organization to continue operating if needed, but most importantly,
immediately turn off the power source to the computer, disconnect the
computer from the network, and/or reinstalling the systems application. These
steps to reacting to the security breach will minimize any damage. The
reaction time is crucial considering any breach so some type intrusion
detection system would be beneficial to detect abnormal behavior within the
network. This can help manage and automate security reactions to intruders.
Once the incident is under control, forensic security team would investigate
the incident. Documenting and identifying all parties involved and how the
security breach occurred, and the course of action to resolved the issue.
Depending on the type of breach, if the organization’s security was
compromised and couldn’t prevent further damage to the data breach, some
type of procedure or escalation for this new type of breach would have to
take place to find the appropriate solution/course of action and be
implemented for security moving forward. If a data breach is suspected, the
CISO’s response time is critical due to longer the response time the higher
possibility of extensive damage occurring. Reacting to the incident involves the
anticipation of attacks as well as planning measures to be taken to help
restore the services. The incident is to be isolated by terminating the power
supply to the computer in question. The computer is to be taken off the
network to help reduce the chances of higher damage, then the system
applications are reinstalled as an attempt to have the computer back to its
proper operating condition. All data breaches can not be reacted to in the
same manner due to some may be intentional while others may be
accidental. Either way the use of an antivirus and or an IDS can help
monitor the network to help reduce the chances of intentional attacks through
the cyber domain. When it comes to physical security using security password
requirements to access the data along with encryption are the best possibility.
A type of data breach would be a worm, these are the most used type of
malware that enters an operating system to spread malicious code. It is self-
replicating and consumes excessive bandwidth, deletes files, or sends files
through email which are infected. To reduce the risk of a worm attack, the
user account should be running as “limited” to prevent installation,
modification, or removal of software. Second firewalls should limit
unauthorized network activity with the operating system set to automatically
install system updates. Lastly, an anti-virus software should be installed and
set to scan and update automatically, a paid for antivirus program will have
more benefits and features in comparison to a free program. In the case of
a suspected breach, the CISO should detect a breach fast and discover the
details. Whenever there is a breach, the CISO should be able to detect it
at the earliest, before it causes big damages to the organization. Next, the
CISO should assemble the team quickly, and prepare a plan to recover from
the breach. Whenever there is a cybersecurity breach, the CISO should be
able to assemble the Computer Security Incident Response Team (CSIRT), and
get a plan ready to tackle the cyber crisis, gathering information for detailed
analysis, ensuring involvement at all levels. The next step would be to
contain the breach effectively and promptly. Once a breach is detected and
the team is ready to tackle it, the CISO should first seek to plan ways to
contain it as effectively as possible without losing any time. The CISO's role
also includes informing the public and customers. The CISO should also plan
to address the security issue with the public, especially since this is an
important step as regards mitigating damages caused by the incident. Last, the
CISO is responsible for taking steps to prevent further attacks. Once a
cybersecurity issue is detected and resolved, plans have to be made and steps
have to be taken to ensure that the same attack wouldn't happen again and
also ensure that other attacks are also prevented.
In the event of a network-based breach, the CISO must make sure that the
incident response plan is in place, and limit the ability of the attacker to
access your network. This step includes blocking IP addresses utilized by
known threats or denying servers and critical infrastructure the ability to
directly communicate with the internet. The next course of action would be
to eliminate the files that caused the infection, including removing the
service/application that created the vulnerability, and deleting or disabling the
process/protocol used to launch the cyber attack. The last course of action
would be to remove affected devices from the environment. This includes
restoring affected devices to a known-good state via backups or snapshots,
and powering off the device and disconnecting it from the network. In the
case of a suspected data breach the first thing the CISO should do is to
isolate the incident. After they have isolated the incident they should try to
prevent as much loss as possible. Then they need to investigate what was
taken in the breach. They then need to notify if any personal information
was taken from consumers. If found that the breach was internal instead of
external, they need to have the workers change their passwords in order to
protect from future attacks.
The CISO after knowing what type of breach has occurred if preventable in
the future should change policy in order to prevent future breaches. If it
were an external device that was the root cause having a policy in place
about personal drives in work computers would help prevent future breaches.
If it was a physical theft of information making sure that updates are made
to the security around that device to prevent further thefts. If found to be
an employee breach limiting access to information that is not crucial to the
job that they perform. A CISO would and should isolate the breach and
mitigate the damage where possible. A CISO will also analyze the data
breach after the attack has been contained in order to assess why it occurred
and resolve any vulnerabilities found.
The type of data breach will determine what actions are taken. A breach in
Confidentiality can result in exposure to personal data. This could be due to
a lack of encryption use for storing and transmitted data. The law requires
for the organization to notify parties who were exposed and mitigation of the
risk in the future requires different policies and technology. A breach in
Integrity can result in data being altered. The cause of this integrity breach
can be the result of a lack of anti-virus on computers or the lack of
application/hardware controls. The CISO would potentially have to find a
means to restore data that is damaged by the breach and mitigate any future
risks by installing controls mentioned earlier. A breach in Availability can
result in a loss of access to information resources. The CISO would have to
identify where and why the loss of access occurred and determine if there
is a redundant means to get users back online.
One specific course of action to mitigate a breach of Availability is to
create redundancies in your organizations infrastructure. This can be done via
the network or server level. For instance, an organization can decide to have
a primary and back up circuit connection to the internet so that if one
connection is lost then the back up kicks in. For the perspective of the
server, redundancy would translate into having a RAID for your storage
device. In the case of a suspected data breach, a chief information security
office has a few priorities: safety, security, and awareness. Safety comes in
the form of ensuring all systems and people are safe from harm. Harm
could be destruction of property, acquired information endangering someone's
physical safety, or potential financial losses due to compromised information.
Security requires a CISO getting to the root of the breach, determining to
what extent the problem is, resolving up the problem, and placing in
safeguards to prevent such breaches from happening again. Awareness is
alerting all persons whose information could have been compromised. In some
cases, that's as simple as resetting all users' passwords. In other cases, the
remediation process is more complicated and requires more of a payout.
Different types of breaches (cyber, stolen paper receipts and banks statements,
recovered pin numbers and passcodes) require different reactionary responses
and carry different levels of responsibility. In the case of a cyber data
breach, a CISO would need to locate the entry point into the system of the
breach, sure up the system defenses and install programs to prevent similar
breaches, and send out virtual alerts to all users on the platform to be
aware and change passcodes. The role of CISO is the overall management of
security for the information technology and report to the CEO of potential
risk associated with their information technology. The CISO will give out
responsibilities to handle the breach. In data breaches, the first thing is assess
the severity of the breach. Depending on the type of attack, they will launch
a counterattack plan. After they have taken action against the attack, they
will launch recovery actions to retrieve the loss of information or analyze for
any data corruption. At the end, they will evaluate the cause of the breach
and the monetary value of the attack to the business. The CISO will have
to implement the new findings if any into the policies to prevent future
similar breaches. They will train the employees to the new procedures.
One type of breach is the Phising attacks. They are attacks that imitate a
legitimate site and trusted source created by hackers to trick users into
voluntarily inputting their sensitive information. They could ask for usernames,
passwords, or other information. The links could lead to unknown sites that
give hackers control of the information. They should notify the information
security teams so they are aware of the situation. Another time sensitive step
would be to run a full security scan on the device used to catch lingering
malware or intrusion of viruses that could corrupt the data. Then the users
must immediately change passwords or information that was given out. If
credit cards are compromised the course of action is to cancel or change the
cards. For SSN theft notify the credit bureau to lock the SSN to avoid
identity theft. The next step is to evaluate the attack and the cost associated
and conduct proper training for future attacks. we have to understand that the
reason why we would expect the CISO to handle the suspected security
breach, is because he/she is the second at hand after the CEO. With that
being said normally the CISO would have various measures in place to make
sure this doesn't happen. In the case that it does happen the CISO will
have to gather is team together to pull the data where the breach was
formed. Advise all parties that were effected by the breach and the measures
that are to be taken to get it under control.The type of breach varies
widely based on the company that it has effected. For example, credit card
breach which holds a lot of personal data can hit consumers the hardest
causing them not to have access to there funds when needed due to cards
being locked hoping to avoid fraud and identity theft. SOP's(Standard
Operational Procedures) if not already should be put into place so that
everyone will know how to handle these case as the come to surface. There
are many different types of data breaches. These range from stolen
information to DDoS. The most common types of data breaches and one of
the most important to protect against is stolen information. This could include
anything from stolen email addresses to passwords to credit card information.
Stolen information is one of the most devastating types of data breaches that
can happen to a company. This can have a lasting impact on a company
and could even send them out of business and into bankruptcy. ransomware
is another type of data breaches that could happen to a company. This is
when a company is breached and their information on computers and servers
is locked and the only way to get it back is to pay the ransom fee. One
large data breach was back in 2014 when eBay was breached by someone
having access to 3 different coorperate employees credentials. This allowed the
breachers to have access to all of it's customers personal information
including emails, passwords, and other personally identifiable information. eBay
attempted to hide this but it was evenually revealed that the hackers had
access to the accounts for more than 229 days. This could have been
avoided or at least noticed sooner if eBay would have had better password
renewal process. If an organization has a data breach, a chief information
security officer (CISO) could take a few approaches, such as; engaging the
incident management team, as well as gaining an understanding of how the
breach took place. A large number of security breaches stem from
unintentional mistakes made by employee carelessness. If an employee is not
aware of the damage he or she can cause simply by opening an email, and
clicking on a link, there is not too much the company can do about it.
However, if the employee took the security training and education where the
harm of clicking on links and downloading a worm, virus, or spyware was
explained in detail, and the employee electronically signed stating they agree
with the information and the repercussions involved, the organization can use
that information in court if the employee sued them. I work in a company
that will not only explain what the employee did wrong, it may include
terminating the employee for the action. The employee would typically retain
a lawyer and attempt to sue the organization for wrongful termination stating,
"they just did not know". The CISO and Human Resources (HR) could bring
that electronically signed paper to court, and most likely would dismiss the
accusation. A CISO should begin by first analyzing the alert and determine
if it’s a true attack. There are times when someone could forget a password
and used someone else’s login to finish work or something to that effect.
The CISO needs to notify his response team and have them look to see if
the attack is real once that is determined then the following actions should
be take place.
1. Shut off whatever they are using to access information
2. That means either unplugging hardware or executing a shut off command
3. See what was taken and or damaged
4. Looking for where the leak is how it happen as well while taking
notes
5. Make a report of the incident and catalog all areas of vulnerability
6. Fix where the leak occurred and fortify security
7. Determine if it was an outside attack or fromwith in
8. Deal with the leak if its from within the company
9. Reset all users’ passwords and apply any needed restrictions
10. Notify public of information leak to save face and begin earning back
trust
11. Begin recovery and gaining back trust of those data that was lost
There are several forms of data breach, like there are different ways to rob
a bank.
1. Employee error
2. The employee opened a phishing email or easy password
3. Cyber attack
4. Coming through internet links or searches using malware
5. Social engineering
6. Employees or other taking information from servers or other data
storage and then trading it to attackers or selling it on the black-
market, and or allowing someone inside that will attack the organization
7. Unauthorized access
8. Someone allowed to wait at a desk or something akin to that, they
then look for things like personal Data and other HR related items or
attempt to steal company secrets
9. Ransomware
10. It is new but it attacks a company and stea lsdata or locks out users
and demands money to be removed, or information regarding the
decryption key
11. Malicious Insider
12. Someone actively plotting to either steal andor sabotage an organization
13. Physical theft
14. They steal something
Each one requires a different response and different program to protect. The
bulk is done with physical security and monitoring as well as cyber to
prevent these attacks.
If an employee user information ever become vulnerable and taken the
following actgions need to occur. Immediate access denial and user deleted
then information gathered on what was stolen and taken and determine if the
employee did it on accident or purpose. Then notify the CISO and being
recovery protocols
In case of a suspected data breach, what course of action should a chief
information security officer (CISO) take?
When there is a security breach, it think that the CISO course of action
should be a few things. Building a team that can provide security analysis
who can provide analysis and assess vulnerabilities in the infrastructure. A
system engineering, who can perform security monitoring. traffic analysis,
intrusion detection. Also, installing antivirus software should be installed, also,
contacting the people who the data breach affected.
How does the type of data breach affect the actions? ww
There are many causes for a data breach, it can affect a business, whereas,
if in the wrong hands,, it can cause the business to loose financially. Also,
if it is customer related, hackers can obtain personal information from the
customer. Personal information that is in the wrong hands can cause identify
theft.
Select 1 type of data breach and the course of action that should be
taken. ww
A data breach that comes to mind is human error. Sometimes humans who
are very busy can make common mistakes, like sending personal information
to a wrong party. Sometimes in human error, information can be entered
incorrectly as well., Leaving a computer unlocked can cause someone to
obtain information. Talking about a customer's information or writing specific
personal data down and not destroying it can lead to a data breach. As we
know that data breach is an incident where information is stolen from a
system without the knowledge or authorization of the system's owner. Stolen
data may involve sensitive, proprietary, or confidential information such as
credit card numbers, customer data, trade secrets, pictures or matters of
national security.
In this event, The CISO should make sure that all employees of the
organization change their passwords, assemble the team after the disaster
strikes to determine what went wrong in a breach, dealing with those
responsible if they're internal, and planning to avoid repeats of the same
crisis. Physical security is also a major concern. The statistics discussed
earlier reveal that the loss/theft of media such as laptops, data cards, phones
etc. account for major security breach incidents. Since physical security
breaches are the highest among personal devices, individual users must be
careful about securing their computing gadgets. Data breaches are not always
intentional. Users can accidentally send protected data to the wrong email
address or upload it to the wrong share. Social engineering is very common
way for data breach its a manipulation technique that exploits human error to
gain private information, access, or valuables. In cybercrime, these scams tend
to lure unsuspecting users into exposing data, spreading malware infections, or
giving access to restricted systems. Attacks can happen online, in-person, and
via other interactions. Implementing security applies to any database whether it
was a personal computer or or a large corporation and by applying the
security steps ( precaution, maintenance, and reaction) if there is a suspected
data breach we would be in the reaction step and the CISO would have to
investigate what type of threat it is and where exactly did it come from to
provide the right course of action, for example if it was internal and a
mistake by one of the employees a new measures of security needs to be
discussed and maybe more training for said employee.Of course the type of
threat would affect the action and the outcome, let say an organization with
a big number of personal data of costumers and the breach was intended to
steal personal info such as banking Info or credit cards information, the
organization would be responsible for any damage to the costumers and
would have to work on developing a new security plan maybe adding more
firewalls or changing anti viruses as well as using IDS (Intrusion Detection
Systems). In case of suspected data breach, the CISO would gather his team
together and have them analyze the situation and determine if there are any
immediate threats. If a breach has occurred, then the CISO would set a plan
into action to seal off the breach, investigate how it happened and
communicate with the appropriate people about the incident. Once the breach
has been fixed and the investigation has been completed. The CISO will
develop a policy to prevent it from happening again.
Depending on the type of breach, that will determine the policy that will be
put into place. If it was an outside intrusion into the network, then measure
will be put in place to prevent that. That also goes for user error or a
user purposely attacking the company’s network from the inside. If the breach
was caused from an employee stealing data. A policy can be put in place
that would eliminate the use of any type of electronic storage devices or
cameras to prevent data being taken out of the building. When reading over
the chapter I think as a chief information security officer is to first see
how the breach occurred. The breach could have happen by simply a worker
placing a flash drive in the computer and by them doing that the system
might have caught a virus. We offer see this when we are using our bank
cards and one minute is working and the next it has stop working. Knowing
how the breach happened helps to find where to start. One solution that
should take place is making sure that all firewall are updated and is also
Norton is used. The reason I said Norton is because it does do a cleaning
on the computer and system. It is real important that the chief let the
customer(s) know what is going on and if their information has been
compromised and what action the company is taking to fix this issues.
Giving the customer(s) a firm solution and understand that this matter is
important to the company. I also think that the information should be back
up on a backup storage system. CISO is a management/leadership position in
most companies. It would NOT normally be the CISO that wades in and
assesses the damage, does forensic analysis, nor puts controls in place to
prevent further attacks. The CISO would set policy, advise, follow-up, and
consult.