Data Breach
A data breach is the moment private customer information leaves your control, whether a thief took it or someone simply sent it to the wrong address.
Also known as security breach data leak information leak
Definition
A data breach is what happens when private information ends up in hands it was never meant to reach. That can be customer names and phone numbers, card details, medical notes, or the passwords your staff use every day. Sometimes a thief takes it, and sometimes an employee emails a spreadsheet to the wrong address. Either way the information has left your control, and that moment is the breach.
Owners assume the theft itself is the expensive part, and it rarely is, because the bill arrives afterwards. You have to tell every customer whose details were taken, and letters, emails and calls all cost money. In many countries you must tell a regulator within days. Your system then sits switched off while someone works out what happened, so a business that cannot take an order for three days loses three days of income. After that some customers quietly stop coming back, and your bank may hold your card payments or raise its fees while the case is open.
The first three steps, in the order that helps, are short ones. Stop the leak by disconnecting the affected computer or server and changing the passwords used to get in. Then write down what you know and the time you learned it, because that record decides how a regulator and an insurer treat you months later. Only then tell the people whose information it was, in plain words, before they hear it from somebody else.
The common mistake is destroying the proof. Someone reinstalls the server the same afternoon to get the shop trading again, so nobody can show what was taken or when the attacker got in. Insurers ask for that proof and so do lawyers, which is why you keep the logs, even the dull ones.
Most breaches Linkysoft is called in to examine involved no clever attack at all. The cause was an old password, a login with no second step, or a plugin nobody had updated in two years. Closing gaps like those is ordinary work, and it is where a cybersecurity review begins. So if your customer records live in your own web application, ask who can export the whole table and whether that export leaves a trace. Linkysoft asks that question early, and the answer is usually uncomfortable.
Questions about Data Breach
How do I know if my business has been breached?
Do I have to tell my customers?
What does a data breach cost a small business?
Is a small shop really a target?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.