5. Steps in managing a computer security data breach incident
1. Preparation for a Data Breach Incident
- conduct a risk analysis,
- form an incident response team,
- prepare appropriate software support (data breach response, cybersecurity software)
threat detection and monitoring tools, data loss prevention systems, access management solutions, user and entity behavior analytics, etc.,
- create a data breach incident response plan and policy,
- conduct cybersecurity awareness training.
In preventing data breaches, it is essential to treat employees as the first line of defense. This is primarily achieved through regular education.
2. Detecting Whether a Data Breach Has Occurred
Indicators suggesting that a data breach may occur:
- log files on the web server contain artifacts indicating vulnerability scanning of the system,
- discovery of a vulnerability within the system that could be exploited,
- posts on certain channels indicating an intention to attack the organisation.
Indicators showing that a data breach is occurring or has already occurred:
- a buffer overflow targeting the database server,
- multiple failed login attempts from an unknown remote system,
- receiving an email with suspicious content.
3. Executing Emergency Incident Response
Several urgent steps must be taken when a data breach incident occurs:
- record the time when the first information about the breach was received, along with all known facts,
- the person who discovered the incident must inform all relevant parties, including the IRT,
- the responsible person must implement measures to restrict access to compromised data to prevent further leakage,
- isolate the location where the incident occurred,
- collect all possible data about the incident,
- interview the individuals who discovered the incident,
- conduct a risk analysis,
- document all steps and analyses,
- notify the relevant authorities,
- begin in‑depth analysis and forensics to identify the main attack vector,
- notify the regulator.
4. Evidence Collection
It is necessary to collect data from all cybersecurity tools, servers, and network devices, as well as gather information from employees.
Information that must be collected includes:
- the date and time the data breach was discovered,
- the date and time the response to the breach began,
- who discovered the breach, who reported it, and who else is aware of it,
- which information was compromised and how,
- a description of all events related to the incident,
- information about all parties involved in the breach,
- which systems were affected,
- information about the scope and type of damage caused.
5. Analysing the Data Breach
After collecting incident data, it must be analysed. The goal of this step is to examine all circumstances that led to the incident.
Questions that must be answered include:
- Was suspicious traffic detected?
- Did the attacker have privileged access to the system?
- How long were the data compromised?
- Did the attackers use specialised software? If so, which?
- Was the data breach intentional, and were external attackers involved?
6. Implementing Containment, Eradication, and Recovery Measures
Containment – the goal is not only to isolate compromised computers and servers but also to prevent the destruction of evidence that might assist the investigation. If possible, attacker activity should be monitored to determine whether data leakage continues during the investigation.
Eradication – it is crucial to remove all sources of the data breach. For example, if the breach was caused by an insider threat, security experts should disable all accounts used for leaking information. If the threat was external, such as malware, the affected system must be cleaned and the vulnerabilities patched.
Recovery – after successful eradication, the organisation must resume normal operations. This includes restoring affected systems to full functionality, installing patches, changing passwords, etc.
7. Notifying Affected Parties
Regardless of legal obligations, all individuals affected by the data breach must be informed so they can take protective measures.
Whom must be notified depends on the type of compromised data.
Certain regulations require notifying the competent authorities within a specific timeframe.
The General Data Protection Regulation (GDPR) requires notifying the appropriate supervisory authorities no later than 72 hours after discovering a data breach. GDPR sets a maximum fine of EUR 20 million or four percent of annual global turnover (whichever is higher) for data breaches.
8. Implementing Post‑Incident Measures
These activities include analysing the incident and its consequences and taking steps to prevent similar issues in the future. Every data breach must be thoroughly reviewed afterward:
- review the cybersecurity measures implemented by the organisation,
- analyse the causes of the data breach,
- create or revise a plan to prevent similar incidents in the future,
- revise policies and procedures based on lessons learned,
- improve cybersecurity awareness among employees.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight