Data Breach

The moment private customer information leaves your control, and the notifications, downtime and lost trade that follow.

Also known as security breach data leak information leak

Definition

A data breach is when private information ends up in hands it was never meant to reach. Customer names, phone numbers, card details, medical notes, staff passwords. Sometimes a thief takes it. Sometimes an employee emails a spreadsheet to the wrong address. Either way, the moment that information leaves your control, you have had a data breach.

Owners assume the theft itself is the expensive part. It rarely is. The bill arrives afterwards. You have to tell every customer whose details were taken, and letters, emails and phone calls all cost money. In many countries you must tell a regulator within days. Your system sits switched off while someone works out what happened, and a business that cannot take an order for three days loses three days of income. Then some customers stop coming back without ever saying why. Your bank may also hold your card payments or raise its fees while the case is open.

The first three steps, in the honest order, are short. Stop the leak. Disconnect the affected computer or server and change the passwords that were used to get in. Then write down what you know and the time you learned it, because that record decides how a regulator and an insurer treat you months later. Then tell the people whose information it was, in plain words, before they hear it from somebody else.

The common mistake is destroying the proof. Someone reinstalls the server the same afternoon to get the shop trading again, and now nobody can show what was taken or when the attacker got in. Insurers ask for that proof. So do lawyers. Keep the logs, even the dull ones.

Most breaches Linkysoft is called in to examine involved no clever attack at all. An old password, a login with no second step, a plugin nobody had updated in two years. Closing gaps like those is ordinary work, and it is where a cybersecurity review begins. If your customer records live inside your own web application, ask who is able to export the whole table, and whether that export leaves a trace. Linkysoft asks that question early, and the answer is usually uncomfortable.

Questions about Data Breach

How do I know if my business has been breached?
Often you do not find it yourself. A customer, a bank or a supplier tells you, or you notice logins at odd hours and files that have moved. Look at your login records first.
Do I have to tell my customers?
If the loss could harm them, yes, and quickly. Say what was taken, what you have done and what they should do now. A short honest message keeps more customers than silence.
What does a data breach cost a small business?
The software is the cheap part. Most of the money goes on the days you cannot trade, the people who investigate, telling customers and the sales that never come back.
Is a small shop really a target?
Most attacks are not aimed at anyone. Programs scan the whole internet for a login that was never updated and take whatever opens. Being small makes you easier, not safer.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.