DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Kroll Advisory Solutions Releases 2013 Cyber Security Forecast

Posted on December 29, 2012 by Dissent

Right before the holidays, Kroll Advisory Solutions released its predictions and advisory. They identified four unexpected cyber forces to be reckoned with in 2013 and offered some recommendations for addressing them:

1. Vampire Data: Organizations Get Bitten by the Data They Never Knew They Had

Data exists in myriad locations and in a multitude of formats within an organization, and we’ve seen too many instances where clients just didn’t know the data existed until they experienced an attack. We call this vampire data – basically, any data that can’t seem to be killed, but comes back to drain the life out of the organization. Examples include backup tapes and archiving that go back decades (even though they were scheduled to be destroyed); emails that should be destroyed after 90 days but exist indefinitely on employees’ desktops; and material that has been copied to portable or cloud storage without the organization’s consent or knowledge. While it may not be a sanctioned copy of data, it may still be a discoverable one, and it can certainly be stolen or lost, causing a data breach that just shouldn’t have happened.

What organizations can do now to prepare: Take a data inventory, classify it by confidentiality or sensitivity level, and handle it accordingly. Only allow users to access the data they need and provide employees with regular data handling training to avoid unnecessary data propagation or transmission. Investigating a breach of vampire data can put significant strain on internal resources, so it is a good idea to engage an outside consultant to help you determine what was lost.

2. Forgotten Forensics: Organizations Gain New Appreciation for Data Forensics in the Wake of a Breach

Like any applied science, forensics requires certain real-world tools and applications in order to be successful. During a forensics investigation, we sometimes have limited resources at our disposal because organizations aren’t properly logging or documenting their activities. As a result, organizations will spend more money to discover whether the breach occurred and what was lost, and may wind up sending notifications based on reasonable assumption rather than concrete evidence of exposure. As organizations come to understand the reputational and financial importance of forensics investigations, we will see a shift.

What organizations can do now to prepare: Turn on your logs and make sure they are retained long enough to be useful. But it’s also helpful to perform a security assessment and train key employees in the basics of immediate breach response. Those employees who are most likely to be first responders in a breach should know how to respond without wiping out vital evidence needed to understand the incident, or if applicable, meet the requirements set by the cyber insurance policy carrier.

3. Hackers Out for the Kill: Hackers Aren’t Out to Steal Your Data, They’re Out to Destroy Your Company

It used to be that insider attacks were generally perceived as the most malicious – if a breach was perpetrated by a malicious insider, especially one with an axe to grind and easy access to sensitive information, the results could be pretty nasty. But the latest batch of cyber attackers are delving deeper into the cyber warfare and cyber terrorism space. They have a rapidly evolving ideology and agenda – namely, they are coming to destroy the secure network, erase pertinent data, wreak havoc with physical equipment, and ultimately take your company down. Kroll worked on a handful of very large engagements in 2012 that involved this type of attack, and in each case, the company was hit by an attack that destroyed data on a large number of machines throughout the global enterprise.

What organizations can do now to prepare: While this seems like a problem strictly for large enterprises, players are already beginning to develop and deploy these tactics on organizations of all sizes and in all industries. These groups may be looking for profit, perhaps holding your data for ransom, but the end result is still the same, and the stakes are high. Make sure you have a backup plan. Don’t assume that because you have backup tapes you have a plan for restoration. If you are outsourcing IT functions, make sure your third parties understand their role in getting you back up and running – and you’ll want to test their ability to do so.

4. The Gift of Gab: The Luxury of Nondisclosure Is a Thing of the Past

While the academic debate on this issue will continue in 2013, we’ll start to see more and more organizations speaking up – even when the loss is not personally identifiable or protected health information (PII and PHI). In some cases, nondisclosure will simply not be an option. For instance, if you experience a data destruction attack, everyone will know once your systems are down. In other instances, the stakes will be too high; the threat will be insurmountable without help from security consultants and government entities. We’ve already seen an increase in the number of breaches where clients have been notified by a government entity or security firm that they’ve lost sensitive data; we expect to see that trend only accelerate in 2013.

What organizations can do now to prepare: It is becoming increasingly important to contract with outside resources – an investigation and forensics partner, a privacy law firm, and/or a breach notification partner. When a security incident occurs, having providers in place to assist with the investigation, advise on current legal requirements, and prepare a response should it experience a breach of PII will save time and expense for the affected organization.

“If we’ve learned one thing from the changing climate of data security in 2012, it is that 2013 will definitely not be a time to employ the same old tactics,” said Tim Ryan, managing director at Kroll Advisory. “Boards of Directors are becoming more engaged on this subject, in part because it deals with corporate risk and also because the regulators are on the lookout. 2013 will require a review of information security governance, identification of information risk and controls, and preparation for the inevitable: a breach of sensitive data, a looming threat for every organization.”

Category: Uncategorized

Post navigation

← Eletronorte, Power Plants of Northern Brazil Hacked, Data Leaked
Your Mobile Device and Health Information Privacy and Security →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • International cybercrime tackled: Amsterdam police and FBI dismantle proxy service Anyproxy
  • Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
  • N.W.T.’s medical record system under the microscope after 2 reported cases of snooping
  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.