published on
Businesses Beware: The Five Leading Causes of Data Breaches
Data loss or data breach are two of the scariest words in modern information security. Losing critical data can have reputational and monetary damage to organizations of all sizes, including long-running negative press, as they work to repair the issue that caused the breach. Over the past few years, the risk of a data breach has risen substantially between COVID and more people working from home globally, along with the cost.
According to an IBM report, the global average data breach cost in 2023 was US$4.45 million, a 15% increase over three years. These cost figures include all-in numbers for response and recovery, at least from a dollars-spent perspective. What it doesn’t quantify is lost staff time, impact on reputation, and the long-term adverse effect on revenue.
What is a Data Breach?
In simple terms, a data breach is any security incident where someone unauthorized gains access to sensitive or confidential information. This data can be personal data like Social Security numbers, bank account numbers, and health data, or it can be corporate data like customer data records and intellectual property.
Data breach is often synonymous with cyberattack, but that’s not entirely accurate. There are several types of cyberattacks, such as denial of service, where data is inaccessible or exfiltrated. In such situations, there was not a data breach. Data must be stolen for a breach to have occurred.
Now, as part of understanding a data breach, it’s worthwhile to examine the five leading causes of such events.
The Top 5 Causes of Data Breaches
The #1 Cause of Data Breaches: Human Error
Research conducted by Stanford University in collaboration with a significant cybersecurity organization found that human error continues to be the top contributor (88%) to overall data breaches. Employees often work fast and try to achieve their goals with minimal interruption. As a result, cybersecurity best practices can often fall by the wayside.
Here are some common ways that unintentional data breaches occur because of employees.
- Poor password hygiene: Password hygiene can make a big difference in data security. Best practices are already known, like not reusing passwords and making them complicated, but the reality is that people often choose expediency over security when it comes to choosing a password. In fact, many employees are known to use the word “password” itself as a password. Over 80% of confirmed breaches are related to stolen, weak, or reused passwords.
- A misdirected email: Let’s admit it! Most of us do this at least once in our lifetimes. We intend to send that confidential report to John Smith, but we end up sending it to Jon Smith, who’s a consultant or vendor. Now that the data is out of the organization and lies with an unintended recipient, you’ve lost control of it. Sending the wrong email to the wrong person can expose private information to people who shouldn’t have it.
- Forgetful employees: You may have deployed an email security solution requiring senders to manually apply security to sensitive emails. Will they remember every time? Highly unlikely! Relying on employees to manually add protection to emails is inherently risky. While you may be worried about data security, all your employees may not share your concerns on this subject.
- Mistakes: People are people. Data breaches can occur from something as simple as the engineering team deploying a cloud service incorrectly. Misconfigurations arise because of people making mistakes with their cloud infrastructure. Making and then not noticing an honest error can result in a data breach.
#2. Insider Threats
First, let’s define an insider. An insider could be your current or former employee, consultant, vendor, or partner with legitimate access to your network and data. The legitimate keys to the kingdom make it challenging to detect insider threats. It takes one rogue employee to cost you millions of dollars and damage your reputation.
The pandemic has fuelled the possibility of insider threats. According to a report, 81% of the global workforce of 3.3 billion people have had their workplace wholly or partly closed. The distress caused by layoffs, furloughs, and pay cuts combined with reduced visibility of IT and security teams in the work-from-home environment is a perfect recipe for a rogue employee to perpetrate a security breach.
Let’s look at a couple of recent incidents where friends turned foes.
- In December 2020, a former employee of CISCO accessed the company’s systems without authorization and deployed malware that cost the company more than 2 million dollars in damage.
- In 2015, a Google employee stole several trade secrets from its self-driving car program to start his venture. The stolen data included diagrams, source code, videos, PDFs, etc.
#3. Poor Access Control
Proper permissions given to the right people can save you from a potential data breach on most occasions. However, there are some inherent challenges in the currently used access management models, which can be challenging to navigate.
Let’s discuss the example of ECMs. Most ECMs allow you to set folder-level permissions, and everyone with access to a specific folder gets access to all documents in it, along with some documents that may not be meant for everyone. Furthermore, the security and permissions of the ECMs are not passed on to the downloaded copies.
Several employees quit, join, or get transferred to other departments daily in large organizations. Revoking permissions of former employees as soon as they left, assigning permissions to new joiners, and changing permissions for transferred employees can be a colossal admin overhead.
#4. Legacy Security Solutions
Enterprises have relied extensively on traditional security solutions such as Data Loss Prevention (DLP) and Cloud Access Security Brokers (CASB) to identify and monitor internal threats. They can even stop sensitive data from leaving the enterprise perimeter. However, relying solely on these solutions can turn fatal. For example, DLP can’t prevent data leaks when running only in “monitoring” mode.
Furthermore, legacy DLP solutions usually work with structured data. However, most data today is unstructured and, therefore, ignored by DLP. According to a report by IDC, 80 percent of your data will be unstructured by 2025.
#5. Vulnerable Mobile Devices
In recent years, enterprises have encouraged employees to use their mobile devices for work and have detailed BYOD policies. According to research, allowing employees to use their own mobile devices generates $350 in value per person per year. Moreover, people who can BYOD work an extra two hours per day on average.
With all the benefits, it’s no wonder that the number of people using their mobile devices for work has increased rapidly. Already, 95% of organizations allow employees to use BYOD in some capacity, with 87% depending to some extent on the ability of employees to access mobile business apps from their smartphones.
Although using mobile devices increases productivity, it comes with a host of security challenges. Enterprise-class malware, mobile botnets, outdated or rogue apps, using public internet services, loss, device theft, etc., are known to cause data breaches in such devices. According to Verizon’s Mobile Security Index report, one in three organizations suffers data breaches from mobile devices. And SlashNext recently found that 95% of security leaders say phishing attacks via private messaging apps are an increasing concern.
It’s clear that allowing employees to use their mobile devices is a good idea in many cases, but the reality is that doing so means opening up potentially sensitive corporate data to the risk of threat actors gaining access via employee mobile phones.
Protecting Data Wherever It Goes
While there are several other ways to experience a data breach, the ones listed above are the most common. Irrespective of the nature of the threat, there’s always a way to protect your data, even when stolen or leaked accidentally. Data-centric security could be a game-changer along with the security measures you’ve deployed.
Unlike traditional perimeter-based security that focuses on creating barriers of movement throughout a corporate network, data-centric protection emphasizes adding layers of defenses at the data level. As a concept, it protects sensitive information directly so that security moves with the data. Even if a malicious attacker, a rogue insider, human error, or poor mobile device security causes a data breach at the perimeter, your data will continue to be protected wherever it goes. Only authorized people can access your data based on their assigned permissions.
Given the rise of global data breaches, security that focuses on the data directly is important. Doing this also allows for flexibility in operations because when data is the thing that’s being secured, there is less of a need to rely on perimeter defenses to secure information. When you focus on data-centric security, you can get more done effectively and confidently.