Data breaches are becoming almost routine.
Over the past few days alone, organisations ranging from a major French telecoms company and one of the world’s largest private equity firms to a children’s hospital, charities, a government department and a hardware wallet provider have disclosed incidents involving the theft or exposure of personal data.
Different organisations. Different sectors. Different technologies.
But there is a striking commonality.
The data is the target. And increasingly, the route to that data doesn’t necessarily run through the organisation’s front door. But data breaches aren’t slowing down
The scale of some recent incidents is difficult to ignore.
More than 2.1 million customer records were reportedly stolen in the SFR breach.
Apollo Global Management confirmed that attackers gained access to its cloud environment using a social engineering attack, taking names, dates of birth, addresses and Social Security numbers.
At Toronto’s Hospital for Sick Children, employee and job applicant information was exposed following a vulnerability in third-party software, although the hospital says clinical systems and patient records were not affected.
In the UK, Beacon CRM has told its charity customers that an unauthorised party gained access to its systems and that database backups were copied. The platform is used by more than 1,500 charities, potentially creating a much wider impact across multiple organisations. Within the past 24 hours, a mental health charity in North Wales, Conwy Mind, has confirmed it was targeted by a hacker as a possible result of the Beacon breach.
Meanwhile, data breaches involving French government systems exposed hundreds of thousands of personal and financial records, while a separate incident involving the country’s Bloctel telemarketing service exposed millions of telephone numbers.
Even Trezor, a company whose entire proposition is built around secure cryptocurrency storage, has seen customer information exposed through a breach at a third-party shipping provider.
The organisations could hardly be more different. So, what are we learning?
The target isn’t necessarily the organisation. It’s the data.
For years, cybersecurity discussions have focused heavily on protecting the corporate network.
Firewalls. Endpoints. Servers. Data centres. Intrusion detection.
All remain important, but modern organisations increasingly operate across a much more complicated environment.
Data can sit in a private cloud, public cloud, SaaS application, CRM system, HR platform, backup environment or with a third-party service provider.
Employees access it remotely. Suppliers connect to it. Customers interact with it. Applications exchange it.
The traditional perimeter has effectively disappeared, and that changes the question businesses need to ask. It’s no longer simply: “How secure is our infrastructure?”, it is: “How secure is everyone and everything that has access to our data?”
Your weakest link may not be yours
The Beacon incident is a particularly good illustration.
A charity doesn’t necessarily have to be directly attacked for its supporters’ information to be compromised. If the organisation’s CRM provider is breached, the charity’s data can potentially be caught in the same incident. The same principle applies elsewhere.
SickKids’ incident involved third-party software.
Trezor’s customer information was exposed through a shipping provider.
And across the wider cyber landscape, supply-chain attacks and compromises of trusted service providers continue to demonstrate that attackers don’t always need to break into the organisation they ultimately want to exploit.
Sometimes it’s easier to compromise someone the organisation trusts.
Your security perimeter now includes your suppliers, partners, platforms and service providers.
That makes third-party risk a security issue, not simply a procurement issue.
And then there are the people
Apollo’s breach highlights another uncomfortable reality.
The attackers reportedly used social engineering to impersonate IT support and persuade employees to provide credentials and multi-factor authentication codes. This is a very different proposition from an attacker trying to exploit a technical vulnerability. The technology may be working exactly as designed. The problem is that the person using it has been manipulated.
We have spent years telling organisations to implement multi-factor authentication, and rightly so. But MFA is not a magic shield if an attacker can persuade someone to hand over the information needed to bypass it. The lesson isn’t that technology has failed. It’s that technology, people and processes have to work together.
So, are we actually learning?
Perhaps the most important question isn’t why these particular organisations were breached. It’s whether the lessons from one breach are being applied somewhere else.
Because the warning signs are becoming remarkably consistent. Data is spread across multiple platforms and environments. Third parties have access to it. Credentials remain an attractive target, while social engineering continues to exploit one of the oldest weaknesses in any security system: people.
And once attackers gain access, they increasingly don’t need to disrupt systems immediately. They can simply take the data.
That data can then be used to threaten the organisation, sold to other criminals or used to launch highly convincing phishing, fraud and social engineering attacks against the people whose information has been stolen.
In other words, the data breach may be over, but the risk to the people affected may only just be beginning.
This is why organisations need to think beyond simply keeping attackers out. The real objective should be to understand where critical data sits, who can access it, what happens if those access controls are compromised and how quickly the organisation can detect, contain and recover from an incident.
What can organisations do?
There isn’t a single technology that eliminates the risk of data theft. Good security is about putting multiple layers of protection around the things that matter most.
The first step is knowing where your data actually resides. That sounds obvious, but modern businesses can have information spread across private and public cloud environments, SaaS platforms, CRM and HR systems, employee devices, backup platforms and third-party services. If you don’t have a clear understanding of where your data is held, it becomes very difficult to protect it effectively.(talk to us about Sovereign Cloud).
Then consider who can access it. Employees are only one part of the equation. Contractors, suppliers, applications and service providers may all have legitimate access to corporate information. That access needs to be appropriate, limited and regularly reviewed. The principle should be simple: people and systems should have access to what they need, and no more.
It’s also worth assuming that, sooner or later, a credential will be compromised. The important question is what happens next. If a stolen password or successful social engineering attack gives an intruder access to an entire environment, the potential damage is enormous. Strong identity controls, least-privilege access, segmentation and monitoring can make it much harder for an attacker to turn one compromised account into a much larger breach.
Then there is the supply chain.
The recent incidents involving third-party software, CRM platforms and service providers demonstrate why supplier security can no longer be treated simply as a procurement or compliance issue. Organisations need to understand what information their suppliers hold, how that information is protected, where it is stored, who can access it and what happens if the supplier itself suffers a breach.
Finally, organisations need to think seriously about recovery.
Prevention will always be the first line of defence, but no security strategy can guarantee that an organisation will never be breached. If critical systems or data are compromised, can the business recover quickly? Are backups protected from the same attack? Have recovery procedures actually been tested? Having backups is not the same thing as having a tested recovery strategy.
The weakest link isn’t always obvious. The uncomfortable truth is that there is no such thing as a perfectly secure organisation.
The objective is to make an attack difficult, limit what an attacker can access if they do get in, detect suspicious activity quickly and ensure that critical systems and data can be recovered.
That requires more than a firewall and more than an annual security review. It requires security built around the whole environment – people, identity, infrastructure, applications, data and recovery – together with an understanding of the organisations and services that sit around it.
Because your data doesn’t stop being your responsibility simply because someone else is storing it, and your security doesn’t stop at your network boundary simply because your infrastructure has moved to the cloud.
Your data is the target.
The question is whether your defences are strong enough to ensure that, when someone comes looking for it, they can’t get to what matters.
Protect what matters. Talk to vXtream about secure, resilient cloud and infrastructure.
————————————————————————————————————————————————————
Image © SFR sfr.fr


Comments are closed.