Cyber ​​incident management of personal data breaches

Site: Loomen za stručna usavršavanja
Course: Security and Privacy in the Digital Environment
Book: Cyber ​​incident management of personal data breaches
Printed by: Gost (anonimni korisnik)
Date: Tuesday, 28 July 2026, 8:15 AM

1. Introduction

Cyber incident – an event that compromises the availability, authenticity, integrity, or confidentiality of stored, transmitted, or processed data, or of the services that network and information systems provide or enable access to. (National Taxonomy of Computer Security Incidents)

A data breach is a cyber incident that results in the exposure of confidential, sensitive, or otherwise protected information to unauthorised individuals.

Attackers often target organisations to gain access to employee and client personal data or to corporate information (intellectual property, financial data).

Data breaches can result from various cybersecurity‑related events, such as malicious insider activity, social engineering attacks, and the exploitation of software vulnerabilities. At the same time, the impact of a data breach can involve severe and far‑reaching consequences.

Organisations of all sizes, especially educational institutions, face risks such as data breaches, ransomware attacks, identity theft (phishing), and other forms of cyber incidents. Without clearly defined and well‑practiced procedures (policies) for managing such incidents, even minor security failures can lead to serious consequences — from financial losses and operational disruptions to damage to reputation and user trust.

This is why establishing procedures for managing cyber incidents is essential for timely detection, effective response, and limiting the damage. A well‑designed cyber incident management plan enables an organisation to respond more quickly, reduce negative impacts, and meet legal and regulatory requirements related to data security and protection.

Personal data breach security incident management

Figure 6: Personal data breach security incident management

2. Cyber incident

Defining a Cyber Incident

An event is any observable occurrence within a system or network. Events include a user connecting to shared files, a server receiving a website request, a user sending an email, a firewall blocking a connection attempt, and similar activities.

Undesirable events are those with negative consequences, such as system crashes, packet flooding, unauthorised use of system privileges, unauthorised access to sensitive data, execution of malware that destroys data, and similar incidents.

An occurrence that actually or potentially threatens the confidentiality, integrity, or availability of an information system or the information it processes, stores, or transmits represents a violation or an imminent threat of violating security policies, security procedures, or acceptable‑use policies. Source: National Institute of Standards and Technology – Computer Security Incident / Security Incident from FIPS 200 and NIST SP 800‑12, SP 800‑128, SP 800‑137

According to NIST, the definition of a cyber incident refers to the compromise of one of the three key goals of information security, known as the CIA triad. The same definition is provided by the Croatian Cybersecurity Act:

An incident is an event that compromises the availability, authenticity, integrity, or confidentiality of stored, transmitted, or processed data, or of the services that network and information systems provide or enable access to.

The life cycle of a cyber incident

Figure 7: The life cycle of a cyber incident

3. Data breach

A data breach is a cyber incident that results in the exposure of confidential, sensitive, or otherwise protected information to unauthorised individuals.

Attackers often target organisations to gain access to employees’ and clients’ personal data or to corporate information (intellectual property, financial data).

Data breaches can result from various cybersecurity‑related events, such as malicious insider activity, social engineering attacks, and the exploitation of software vulnerabilities. At the same time, the impact of a data breach can involve severe and far‑reaching consequences.

4. Impact of a data breach

Financial loss – the average loss due to a data breach was US$4.45 million in 2023, according to IBM's Cost of a Data Breach Report 2023 (experiences of 604 organisations).

Prikaz troška curenja podataka

Ova slika je ilustrativna

Figure 8: Overview of the costs of data breaches and the logo of the website "information is beautiful". 

Review and analyse some of the largest data losses using the provided link. 

Effects of a Data Breach

Data unavailability as a result of a cyberattack refers to a situation in which authorised users are temporarily or permanently unable to access data due to malicious actions such as encryption, deletion, or system disruption.

Legal consequences – parties affected by a data breach, as well as regulatory authorities, may initiate legal actions that result in financial penalties.

Operational downtime – when a data breach occurs, data may be stolen, damaged, or encrypted until a ransom is paid. If some of this data is critical to your business operations, it can lead to disruptions in productivity, communication, and service delivery.

Reputational damage – current and potential clients may lose trust in the security of your organisation and its ability to protect data, which can result in lost business opportunities, especially when the breach involves sensitive personal information.

5. Steps in managing a computer security data breach incident

1.     Preparation for a Data Breach Incident

  • conduct a risk analysis,
  • form an incident response team,
  • prepare appropriate software support (data breach response, cybersecurity software)

threat detection and monitoring toolsdata loss prevention systemsaccess management solutionsuser and entity behavior analytics, etc.,

  • create a data breach incident response plan and policy,
  • conduct cybersecurity awareness training.

In preventing data breaches, it is essential to treat employees as the first line of defense. This is primarily achieved through regular education.

2. Detecting Whether a Data Breach Has Occurred

Indicators suggesting that a data breach may occur:

  • log files on the web server contain artifacts indicating vulnerability scanning of the system,
  • discovery of a vulnerability within the system that could be exploited,
  • posts on certain channels indicating an intention to attack the organisation.

Indicators showing that a data breach is occurring or has already occurred:

  • a buffer overflow targeting the database server,
  • multiple failed login attempts from an unknown remote system,
  • receiving an email with suspicious content.

3. Executing Emergency Incident Response

Several urgent steps must be taken when a data breach incident occurs:

  • record the time when the first information about the breach was received, along with all known facts,
  • the person who discovered the incident must inform all relevant parties, including the IRT,
  • the responsible person must implement measures to restrict access to compromised data to prevent further leakage,
  • isolate the location where the incident occurred,
  • collect all possible data about the incident,
  • interview the individuals who discovered the incident,
  • conduct a risk analysis,
  • document all steps and analyses,
  • notify the relevant authorities,
  • begin in‑depth analysis and forensics to identify the main attack vector,
  • notify the regulator.

4. Evidence Collection

It is necessary to collect data from all cybersecurity tools, servers, and network devices, as well as gather information from employees.

Information that must be collected includes:

  • the date and time the data breach was discovered,
  • the date and time the response to the breach began,
  • who discovered the breach, who reported it, and who else is aware of it,
  • which information was compromised and how,
  • a description of all events related to the incident,
  • information about all parties involved in the breach,
  • which systems were affected,
  • information about the scope and type of damage caused.

5. Analysing the Data Breach

After collecting incident data, it must be analysed. The goal of this step is to examine all circumstances that led to the incident.

Questions that must be answered include:

  • Was suspicious traffic detected?
  • Did the attacker have privileged access to the system?
  • How long were the data compromised?
  • Did the attackers use specialised software? If so, which?
  • Was the data breach intentional, and were external attackers involved?

6. Implementing Containment, Eradication, and Recovery Measures

Containment – the goal is not only to isolate compromised computers and servers but also to prevent the destruction of evidence that might assist the investigation. If possible, attacker activity should be monitored to determine whether data leakage continues during the investigation.

Eradication – it is crucial to remove all sources of the data breach. For example, if the breach was caused by an insider threat, security experts should disable all accounts used for leaking information. If the threat was external, such as malware, the affected system must be cleaned and the vulnerabilities patched.

Recovery – after successful eradication, the organisation must resume normal operations. This includes restoring affected systems to full functionality, installing patches, changing passwords, etc.

7. Notifying Affected Parties

Regardless of legal obligations, all individuals affected by the data breach must be informed so they can take protective measures.

Whom must be notified depends on the type of compromised data.

Certain regulations require notifying the competent authorities within a specific timeframe.

The General Data Protection Regulation (GDPR) requires notifying the appropriate supervisory authorities no later than 72 hours after discovering a data breach. GDPR sets a maximum fine of EUR 20 million or four percent of annual global turnover (whichever is higher) for data breaches.

8. Implementing Post‑Incident Measures

These activities include analysing the incident and its consequences and taking steps to prevent similar issues in the future. Every data breach must be thoroughly reviewed afterward:

  • review the cybersecurity measures implemented by the organisation,
  • analyse the causes of the data breach,
  • create or revise a plan to prevent similar incidents in the future,
  • revise policies and procedures based on lessons learned,
  • improve cybersecurity awareness among employees.

6. How to manage a computer security data breach incident

To reduce the damage caused by a potential data breach, an organisation must define procedures and steps for incident response before a data breach or any cybersecurity incident occurs.

Developing an effective plan is the first step toward carrying out a successful response to data breach incidents.

A data breach response plan or data breach response policy provides a framework that defines the roles of employees involved in handling a data breach and the steps they should take if (or when) a breach occurs.

One advantage of having an established incident response capability is that it supports a systematic reaction to incidents by ensuring that appropriate, predefined actions are taken. Incident response helps organisations minimise data loss or theft and reduce service disruptions caused by the incident.

Another benefit of incident response is the ability to use information gathered during incident handling to better prepare for future incidents and ensure stronger protection of data and systems.

Incident response capability also helps address legal issues that may arise during an incident.

The steps that must be taken in the process of managing a cybersecurity data breach incident include:

  1. preparation for a data breach incident,
  2. detecting whether a data breach has actually occurred,
  3. executing emergency incident response actions,
  4. collecting evidence,
  5. analysing the data breach,
  6. implementing containment, eradication, and system recovery measures,
  7. notifying affected parties,
  8. carrying out post‑incident activities.

7. Statistics of computer security incidents and data breaches

Interesting statistical data related to data breach incidents:

  • 88 % of cybersecurity breaches are caused by human error (Stanford University/Tessian study "Psychology of Human Error")

  • The average time needed to detect a breach is 194 days (IBM: AI makes ‘real‑world impact’ on breach costs)

  • The average breach lifecycle — from detection to containment — lasts 258 days (IBM: AI makes ‘real‑world impact’ on breach costs)
  • 56 % of Americans do not know what steps to take in the event of a data leak (Varonis)

  • The average ransomware payout increased sharply — from $812,380 in 2022 to $1,542,333 in 2023 (SC Magazine Report: Ransomware payouts and recovery cost went way up in 2023)

  • 94 % of malware is delivered via email (Verizon)

  • The average cost of recovering from a ransomware attack in 2024 is $2.73 million (Sophos)

  • 75 % of organisations experienced at least one ransomware attack last year (Infosecurity Magazine)

  • Phishing was the leading infection method, recorded in 41 % of incidents, making it the most common initial attack vector (Security Magazine)

  • 19 % of security breaches include internal persons (Verizon)

Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight