1 / 19100%
When there is a suspected data breach, the course of action a chief information
security officer (CISO) should be analysing the situation and making sure the correct
tools and solutions are being implemented. Its also very important to build the
correct team and have ongoing reports sent out. Management of data should be
accessed again. Other data systems should be restricted from being used and patches
should be resolved as well and real time analysis of the breach should be completed
as well. Depending on the data breach bases what type of action to take. If the data
is/was stolen, the contacting person associated with the data should be contacted
immediately. If its based on passwords this could mean a key logger is being used
so the keystrokes of the keyboard should be checked. One data breach and steps to
avoid it would be phishing. Phishing is when someone sends a malicious link in an
email or installs malicious software. Steps to take would to be to install an antivirus,
or web filters can be used to block malicious pages on the web. A lot of people
aren't even sure of what a CISO is being that it has only been around for the last
decade or so. A CISO is simply the senior level executive that handles the execution
and the overseeing of the company's cybersecurity strategy. In case of a suspected
data breach, the course of action of the chief information security officer should take
is first of all planning for disaster recovery. Ensuring the privacy and security of
customer data is another strategy that will help in case of a data breach. Managing
responses to cybersecurity incidents and monitoring the IT environment for
vulnerabilities and abnormal events are also some great strategies that a chief
information security officer (CISO) can take in the case of a suspected data breach.
Developing secure business policies and practices, hiring IT security staff, conducting
employee security awareness training, verifying the company’s compliance with laws
and regulations should also be some of the first things a CISO should look into
when possibly facing a suspected data breach.The type of data breach affects the
actions because it affects what needs to be done, it affects your strategy. You
wouldn't use the same strategy you used towards identity theft when facing malware.
In a scenario in which a data breach occurs, the CISO would have to take action in
order to in best case scenario stop the information from getting into the hands of
the intended party. They would do this by increasing their responsibilities and
expanding their ow role within the company. Their first step would be to stop the
leak, by locating the source and containing it. They would make sure that no more
information is released as well as take preventative measures against potential
malware being installed on the company’s data base. The organization targeted would
be contacted by the CISO to inform them of the breach and to also refresh them on
the correct procedures and protocols to handle the situation. Locking down access to
the network database will be crucial to access the level of damage dealt. The
security incident response team would be next on the list to contact, they will be
crucial to determine how the attack was implemented, the amount of data leaked,
what was damaged, and which data was targeted. They will also investigate
suspicious behaviors of employees to help determine the parties involved in the
attack. After this the team and the CISO will put together new software to prevent
the attack from happening again. If a suspected data breach were to take place, the
CISO will be required to take on additional roles and responsibilities in order to
prevent the threat from reaching its intended target or the loss of important data due
to damage or leaks. The CISO would first locate and contain the threat, preventing
it from accessing anymore files or data then it may already have or releasing
malware into the database. During this time, the CISO should contact the
organization to inform them of the possible threat and refresh them on the approved
protocol/steps that will take place. The CISO should then temporarily lockdown any
access to the network database to determine how serious the threat may be and what
damage has been done already. The next step is to inform and update the Security
Incident Response Team about the situation. Together, the team will gather data and
information about how the breach was able to slip through security, what data was
targeted, damaged, leaked or lost, employees data will be scanned for suspicious
activity. The CISO and their team will pick the threat apart to create a new
software that will be prepared for a similar attack and alert security before the threat
is able to access the database. In case of a suspected data breach, the CISO should
first secure the operation. By stabilizing the whole operation, you are protecting any
further data from being stolen. The CISO should lock down all physical access
points and change all all access codes. The CISO Should also shutdown all network
connection temporarily, in case the source of the attack is coming from the network.
Once all of the area's of the operation has been secured, The CISO should deploy
Computer Security Incident Response Team to help identify where the source of the
breach occurred. This team should be able monitor all networking traffic, all source
of communication, and other areas of vulnerability. Once, the threat has been
identified and neutralized, the CISO should look to strengthen that area of weakness.
Whether it's transferring all the sensitive data to a more secure source, monitor
network traffic stricter , granting less access to important information, or installing
IDS.The type of branch effects this action because each threat needs to be handled
in different manner. If the threat is coming from an phishing email, then company
would have to start monitoring the companies email traffic and address it company
wide to prevent others from sending out information to a malicious source.One type
of data breach would be account hacking. A few remedies for an account being
hacked is to change the passwords on the account, backup all sensitive data, or
deactivate account/ start a new account. In a case of a suspected data breach, the
CISO would first need to contain the threat without panic and with a quick response
time. After containing the threat they would need to see how much they can retain
that was not loss as they can, and shut down the system and all servers. The next
step would be to figure out if the breach was internal or external and why the
breach occurred. However with different data breach's steps may change because if a
consumer information was hacked they would then need to get there team to contact
consumers. However some data breach's will be much more serious with more
extensive steps for example government top secret information. A cloud data breach
is far more damaging than a regular computer, because multiple users information
will be in the hands of an attacker in single breach. Furthermore the same steps
should be taken, shut down system until the source of breach is found and resolved.
Most cloud data breach is due to the customers negligence . If there was a data
breach the CISO would first need to contain the threat. Having an intrusion detection
system would be beneficial to minimize the amount of damage a breach could cause.
Next, they should shut down access to any compromised data/servers. The CISO
should know exactly what data or information was compromised and what
information was taken. They should deploy the disaster recovery plan and team. The
CISO should be aware if individual’s private information was compromised and
make appropriate notifications if so. Depending on the type of breach the actions
may not be as extensive and time consuming. Some may be internal mistakes and
the CISO would have to adapt or make new policies and procedures for employees.
One example of a data breach could be caused by phishing. You would need to
identify where the email came from and who opened it. Obtain a copy of said email
as well. Ensure all employees are aware of the phishing email, where it came from,
and not to open it. After it is contained and you have made sure there are no
longer any threats, you should have said employees change their passwords. Provide
further security training for employees. If I was CISO and there was a security data
breach first I must remember not to panic. Second, I would identify that breach,
contain the breach before any more damages occurs. Then, I would create a team of
data analysts to identify the severity of the breach then create another team to create
a plan of action in case this were ever happen again. There are many different types
of data breaches that can affect the action plan of the analysts. For example, when
it comes to data breaches there are some are intentional and unintentional once they
identify the right course of action for the breach. One of the most common types of
breaches is phishing. Phishing is when hackers create a website that replicates a legit
website and asking the user to login into their account when in reality you have just
given someone your account information. The course of the action I would take is
to identify where the phishing raised from, second identify what was affected;
contain it and then create a plan of action on what to do if the issue wherever to a
raise. The role of the CISO is to Establishing the right security and governance
practices. Enabling a framework for risk-free and scalable business operations. In
case of a data breach the chief information security officer should contain the
breach. If you react to a breach by panicking and reacting too quickly, you could
make some costly mistakes. Once you have determined where the breach originated,
it is crucial that you contain it. If the breach spreads to other areas of your
organization, it will become a lot more difficult to handle. To reducing the risk of a
data breach, you need to understand where the risk is coming from. There are two
major risk factors, people and devices. A type of data breach could be Malware.
Malware is a common form of cybersecurity attacks. They are a type of software
that infects your entire system. They are caused by tricking a user into clicking on
something such as a pop-up ad that leads to the download of the software onto the
system. This can lead to systems being severely slowed down, or completely crashed.
To prevent future attacks is remedy whatever caused the initial breach to happen.
Consult and understand what kind of protection you need. The first thing a Chief
information security officer should take after a suspected data breach is to isolate the
issue and make sure it is contained. The next step is to shut down the network and
internal servers to make sure there are no other issues. After that there should be
some investigation done to determine what type of data breach it was and how this
affected the company assets.
For example, if there was a data breach that was the result of a phishing scam it
would be a high priority to educate employees and make them more aware of
security issues like malware/phishing scams. Knowing about cyber attacks and
preventative actions is meaningless unless the information is shared with the rest of
the company.
Just recently our company sent out a test phishing email to see if employees would
click on it. I would guess at least 25% of our team clicked on it. Even with all of
our continued education and trainings around this and still this many employees fell
for it. In case of a suspected data breach, the course of action a chief information
security officer should take would be to have previously implemented backup servers,
or copies of important data for the organization to continue operating if needed, but
most importantly, immediately turn off the power source to the computer, disconnect
the computer from the network, and/or reinstalling the systems application. These
steps to reacting to the security breach will minimize any damage. The reaction time
is crucial considering any breach so some type intrusion detection system would be
beneficial to detect abnormal behavior within the network. This can help manage and
automate security reactions to intruders. Once the incident is under control, forensic
security team would investigate the incident. Documenting and identifying all parties
involved and how the security breach occurred, and the course of action to resolved
the issue. Depending on the type of breach, if the organization’s security was
compromised and couldn’t prevent further damage to the data breach, some type of
procedure or escalation for this new type of breach would have to take place to find
the appropriate solution/course of action and be implemented for security moving
forward. If a data breach is suspected, the CISO’s response time is critical due to
longer the response time the higher possibility of extensive damage occurring.
Reacting to the incident involves the anticipation of attacks as well as planning
measures to be taken to help restore the services. The incident is to be isolated by
terminating the power supply to the computer in question. The computer is to be
taken off the network to help reduce the chances of higher damage, then the system
applications are reinstalled as an attempt to have the computer back to its proper
operating condition. All data breaches can not be reacted to in the same manner due
to some may be intentional while others may be accidental. Either way the use of
an antivirus and or an IDS can help monitor the network to help reduce the chances
of intentional attacks through the cyber domain. When it comes to physical security
using security password requirements to access the data along with encryption are
the best possibility. A type of data breach would be a worm, these are the most
used type of malware that enters an operating system to spread malicious code. It is
self-replicating and consumes excessive bandwidth, deletes files, or sends files
through email which are infected. To reduce the risk of a worm attack, the user
account should be running as “limited” to prevent installation, modification, or
removal of software. Second firewalls should limit unauthorized network activity with
the operating system set to automatically install system updates. Lastly, an anti-virus
software should be installed and set to scan and update automatically, a paid for
antivirus program will have more benefits and features in comparison to a free
program. In the case of a suspected breach, the CISO should detect a breach fast
and discover the details. Whenever there is a breach, the CISO should be able to
detect it at the earliest, before it causes big damages to the organization. Next, the
CISO should assemble the team quickly, and prepare a plan to recover from the
breach. Whenever there is a cybersecurity breach, the CISO should be able to
assemble the Computer Security Incident Response Team (CSIRT), and get a plan
ready to tackle the cyber crisis, gathering information for detailed analysis, ensuring
involvement at all levels. The next step would be to contain the breach effectively
and promptly. Once a breach is detected and the team is ready to tackle it, the
CISO should first seek to plan ways to contain it as effectively as possible without
losing any time. The CISO's role also includes informing the public and customers.
The CISO should also plan to address the security issue with the public, especially
since this is an important step as regards mitigating damages caused by the incident.
Last, the CISO is responsible for taking steps to prevent further attacks. Once a
cybersecurity issue is detected and resolved, plans have to be made and steps have
to be taken to ensure that the same attack wouldn't happen again and also ensure
that other attacks are also prevented.
In the event of a network-based breach, the CISO must make sure that the incident
response plan is in place, and limit the ability of the attacker to access your
network. This step includes blocking IP addresses utilized by known threats or
denying servers and critical infrastructure the ability to directly communicate with the
internet. The next course of action would be to eliminate the files that caused the
infection, including removing the service/application that created the vulnerability, and
deleting or disabling the process/protocol used to launch the cyber attack. The last
course of action would be to remove affected devices from the environment. This
includes restoring affected devices to a known-good state via backups or snapshots,
and powering off the device and disconnecting it from the network. In the case of a
suspected data breach the first thing the CISO should do is to isolate the incident.
After they have isolated the incident they should try to prevent as much loss as
possible. Then they need to investigate what was taken in the breach. They then
need to notify if any personal information was taken from consumers. If found that
the breach was internal instead of external, they need to have the workers change
their passwords in order to protect from future attacks.
The CISO after knowing what type of breach has occurred if preventable in the
future should change policy in order to prevent future breaches. If it were an
external device that was the root cause having a policy in place about personal
drives in work computers would help prevent future breaches. If it was a physical
theft of information making sure that updates are made to the security around that
device to prevent further thefts. If found to be an employee breach limiting access
to information that is not crucial to the job that they perform. A CISO would and
should isolate the breach and mitigate the damage where possible. A CISO will also
analyze the data breach after the attack has been contained in order to assess why it
occurred and resolve any vulnerabilities found.
The type of data breach will determine what actions are taken. A breach in
Confidentiality can result in exposure to personal data. This could be due to a lack
of encryption use for storing and transmitted data. The law requires for the
organization to notify parties who were exposed and mitigation of the risk in the
future requires different policies and technology. A breach in Integrity can result in
data being altered. The cause of this integrity breach can be the result of a lack of
anti-virus on computers or the lack of application/hardware controls. The CISO
would potentially have to find a means to restore data that is damaged by the
breach and mitigate any future risks by installing controls mentioned earlier. A
breach in Availability can result in a loss of access to information resources. The
CISO would have to identify where and why the loss of access occurred and
determine if there is a redundant means to get users back online.
One specific course of action to mitigate a breach of Availability is to create
redundancies in your organizations infrastructure. This can be done via the network
or server level. For instance, an organization can decide to have a primary and back
up circuit connection to the internet so that if one connection is lost then the back
up kicks in. For the perspective of the server, redundancy would translate into
having a RAID for your storage device. In the case of a suspected data breach, a
chief information security office has a few priorities: safety, security, and awareness.
Safety comes in the form of ensuring all systems and people are safe from harm.
Harm could be destruction of property, acquired information endangering someone's
physical safety, or potential financial losses due to compromised information. Security
requires a CISO getting to the root of the breach, determining to what extent the
problem is, resolving up the problem, and placing in safeguards to prevent such
breaches from happening again. Awareness is alerting all persons whose information
could have been compromised. In some cases, that's as simple as resetting all users'
passwords. In other cases, the remediation process is more complicated and requires
more of a payout.
Different types of breaches (cyber, stolen paper receipts and banks statements,
recovered pin numbers and passcodes) require different reactionary responses and
carry different levels of responsibility. In the case of a cyber data breach, a CISO
would need to locate the entry point into the system of the breach, sure up the
system defenses and install programs to prevent similar breaches, and send out
virtual alerts to all users on the platform to be aware and change passcodes. The
role of CISO is the overall management of security for the information technology
and report to the CEO of potential risk associated with their information technology.
The CISO will give out responsibilities to handle the breach. In data breaches, the
first thing is assess the severity of the breach. Depending on the type of attack, they
will launch a counterattack plan. After they have taken action against the attack,
they will launch recovery actions to retrieve the loss of information or analyze for
any data corruption. At the end, they will evaluate the cause of the breach and the
monetary value of the attack to the business. The CISO will have to implement the
new findings if any into the policies to prevent future similar breaches. They will
train the employees to the new procedures.
One type of breach is the Phising attacks. They are attacks that imitate a legitimate
site and trusted source created by hackers to trick users into voluntarily inputting
their sensitive information. They could ask for usernames, passwords, or other
information. The links could lead to unknown sites that give hackers control of the
information. They should notify the information security teams so they are aware of
the situation. Another time sensitive step would be to run a full security scan on the
device used to catch lingering malware or intrusion of viruses that could corrupt the
data. Then the users must immediately change passwords or information that was
given out. If credit cards are compromised the course of action is to cancel or
change the cards. For SSN theft notify the credit bureau to lock the SSN to avoid
identity theft. The next step is to evaluate the attack and the cost associated and
conduct proper training for future attacks. we have to understand that the reason why
we would expect the CISO to handle the suspected security breach, is because
he/she is the second at hand after the CEO. With that being said normally the CISO
would have various measures in place to make sure this doesn't happen. In the case
that it does happen the CISO will have to gather is team together to pull the data
where the breach was formed. Advise all parties that were effected by the breach
and the measures that are to be taken to get it under control.The type of breach
varies widely based on the company that it has effected. For example, credit card
breach which holds a lot of personal data can hit consumers the hardest causing
them not to have access to there funds when needed due to cards being locked
hoping to avoid fraud and identity theft. SOP's(Standard Operational Procedures) if
not already should be put into place so that everyone will know how to handle
these case as the come to surface. There are many different types of data breaches.
These range from stolen information to DDoS. The most common types of data
breaches and one of the most important to protect against is stolen information. This
could include anything from stolen email addresses to passwords to credit card
information. Stolen information is one of the most devastating types of data breaches
that can happen to a company. This can have a lasting impact on a company and
could even send them out of business and into bankruptcy. ransomware is another
type of data breaches that could happen to a company. This is when a company is
breached and their information on computers and servers is locked and the only way
to get it back is to pay the ransom fee. One large data breach was back in 2014
when eBay was breached by someone having access to 3 different coorperate
employees credentials. This allowed the breachers to have access to all of it's
customers personal information including emails, passwords, and other personally
identifiable information. eBay attempted to hide this but it was evenually revealed
that the hackers had access to the accounts for more than 229 days. This could have
been avoided or at least noticed sooner if eBay would have had better password
renewal process. If an organization has a data breach, a chief information security
officer (CISO) could take a few approaches, such as; engaging the incident
management team, as well as gaining an understanding of how the breach took
place. A large number of security breaches stem from unintentional mistakes made
by employee carelessness. If an employee is not aware of the damage he or she can
cause simply by opening an email, and clicking on a link, there is not too much the
company can do about it. However, if the employee took the security training and
education where the harm of clicking on links and downloading a worm, virus, or
spyware was explained in detail, and the employee electronically signed stating they
agree with the information and the repercussions involved, the organization can use
that information in court if the employee sued them. I work in a company that will
not only explain what the employee did wrong, it may include terminating the
employee for the action. The employee would typically retain a lawyer and attempt
to sue the organization for wrongful termination stating, "they just did not know".
The CISO and Human Resources (HR) could bring that electronically signed paper
to court, and most likely would dismiss the accusation. A CISO should begin by
first analyzing the alert and determine if it’s a true attack. There are times when
someone could forget a password and used someone else’s login to finish work or
something to that effect. The CISO needs to notify his response team and have them
look to see if the attack is real once that is determined then the following actions
should be take place.
1. Shut off whatever they are using to access information
2. That means either unplugging hardware or executing a shut off command
3. See what was taken and or damaged
4. Looking for where the leak is how it happen as well while taking notes
5. Make a report of the incident and catalog all areas of vulnerability
6. Fix where the leak occurred and fortify security
7. Determine if it was an outside attack or fromwith in
8. Deal with the leak if its from within the company
9. Reset all users’ passwords and apply any needed restrictions
10. Notify public of information leak to save face and begin earning back trust
11. Begin recovery and gaining back trust of those data that was lost
There are several forms of data breach, like there are different ways to rob a bank.
1. Employee error
2. The employee opened a phishing email or easy password
3. Cyber attack
4. Coming through internet links or searches using malware
5. Social engineering
6. Employees or other taking information from servers or other data storage and
then trading it to attackers or selling it on the black-market, and or allowing
someone inside that will attack the organization
7. Unauthorized access
8. Someone allowed to wait at a desk or something akin to that, they then look
for things like personal Data and other HR related items or attempt to steal
company secrets
9. Ransomware
10. It is new but it attacks a company and stea lsdata or locks out users and
demands money to be removed, or information regarding the decryption key
11. Malicious Insider
12. Someone actively plotting to either steal andor sabotage an organization
13. Physical theft
14. They steal something
Each one requires a different response and different program to protect. The bulk is
done with physical security and monitoring as well as cyber to prevent these attacks.
If an employee user information ever become vulnerable and taken the following
actgions need to occur. Immediate access denial and user deleted then information
gathered on what was stolen and taken and determine if the employee did it on
accident or purpose. Then notify the CISO and being recovery protocols
In case of a suspected data breach, what course of action should a chief
information security officer (CISO) take?
When there is a security breach, it think that the CISO course of action should be a
few things. Building a team that can provide security analysis who can provide
analysis and assess vulnerabilities in the infrastructure. A system engineering, who
can perform security monitoring. traffic analysis, intrusion detection. xx Also, installing
antivirus software should be installed, also, contacting the people who the data
breach affected.
How does the type of data breach affect the actions? xx
There are many causes for a data breach, it can affect a business, whereas, if in the
wrong hands,, it can cause the business to loose financially. Also, if it is customer
related, hackers can obtain personal information from the customer. Personal
information that is in the wrong hands can cause identify theft.
Select 1 type of data breach and the course of action that should be taken. xx
A data breach that comes to mind is human error. Sometimes humans who are very
busy can make common mistakes, like sending personal information to a wrong
party. Sometimes in human error, information can be entered incorrectly as well.,
Leaving a computer unlocked can cause someone to obtain information. Talking
about a customer's information or writing specific personal data down and not
destroying it can lead to a data breach. As we know that data breach is an incident
where information is stolen from a system without the knowledge or authorization of
the system's owner. Stolen data may involve sensitive, proprietary, or confidential
information such as credit card numbers, customer data, trade secrets, pictures or
matters of national security.
In this event, The CISO should make sure that all employees of the organization
change their passwords, assemble the team after the disaster strikes to determine
what went wrong in a breach, dealing with those responsible if they're internal, and
planning to avoid repeats of the same crisis. Physical security is also a major
concern. The statistics discussed earlier reveal that the loss/theft of media such as
laptops, data cards, phones etc. account for major security breach incidents. Since
physical security breaches are the highest among personal devices, individual users
must be careful about securing their computing gadgets. Data breaches are not
always intentional. Users can accidentally send protected data to the wrong email
address or upload it to the wrong share. Social engineering is very common way for
data breach its a manipulation technique that exploits human error to gain private
information, access, or valuables. In cybercrime, these scams tend to lure
unsuspecting users into exposing data, spreading malware infections, or giving access
to restricted systems. Attacks can happen online, in-person, and via other interactions.
Implementing security applies to any database whether it was a personal computer or
or a large corporation and by applying the security steps ( precaution, maintenance,
and reaction) if there is a suspected data breach we would be in the reaction step
and the CISO would have to investigate what type of threat it is and where exactly
did it come from to provide the right course of action, for example if it was
internal and a mistake by one of the employees a new measures of security needs to
be discussed and maybe more training for said employee.Of course the type of threat
would affect the action and the outcome, let say an organization with a big number
of personal data of costumers and the breach was intended to steal personal info
such as banking Info or credit cards information, the organization would be
responsible for any damage to the costumers and would have to work on developing
a new security plan maybe adding more firewalls or changing anti viruses as well as
using IDS (Intrusion Detection Systems). In case of suspected data breach, the CISO
would gather his team together and have them analyze the situation and determine if
there are any immediate threats. If a breach has occurred, then the CISO would set
a plan into action to seal off the breach, investigate how it happened and
communicate with the appropriate people about the incident. Once the breach has
been fixed and the investigation has been completed. The CISO will develop a
policy to prevent it from happening again.
Depending on the type of breach, that will determine the policy that will be put into
place. If it was an outside intrusion into the network, then measure will be put in
place to prevent that. That also goes for user error or a user purposely attacking the
company’s network from the inside. If the breach was caused from an employee
stealing data. A policy can be put in place that would eliminate the use of any type
of electronic storage devices or cameras to prevent data being taken out of the
building. When reading over the chapter I think as a chief information security
officer is to first see how the breach occurred. The breach could have happen by
simply a worker placing a flash drive in the computer and by them doing that the
system might have caught a virus. We offer see this when we are using our bank
cards and one minute is working and the next it has stop working. Knowing how
the breach happened helps to find where to start. One solution that should take place
is making sure that all firewall are updated and is also Norton is used. The reason I
said Norton is because it does do a cleaning on the computer and system. It is real
important that the chief let the customer(s) know what is going on and if their
information has been compromised and what action the company is taking to fix this
issues. Giving the customer(s) a firm solution and understand that this matter is
important to the company. I also think that the information should be back up on a
backup storage system. CISO is a management/leadership position in most companies.
It would NOT normally be the CISO that wades in and assesses the damage, does
forensic analysis, nor puts controls in place to prevent further attacks. The CISO
would set policy, advise, follow-up, and consult.
Students also viewed