Three Step Pogram: Pre-Breach Remedies To Contain The Costs Of A Cyber Attack

Data breaches are very costly. Organisations should consider three basic steps to ensure they are prepared to remedy a future breach.

Over the last year there have been a variety of high-profile security breaches ranging in severity, from TalkTalk, which was fined £400,000 for its 2015 breach, to Yahoo, which had $1 billion of its potential value wiped by the news of its own hack.

When looking at most security breach cases it’s clear that the size of their financial implications is often vastly underestimated. Companies need to put the same amount of effort into protecting against the immediate aftermath of a breach, as they do in its initial prevention.

Mobile breaches present a particularly unique challenge for organisations. Responding to any cyber breach is complicated, but the complexity is often worsened due to the personal nature of a mobile device itself.

A tangled web of data cross-pollination is being created due to the increasing popularity of BYOD and work emails on personal devices. This means that productivity can increase among employees, but with greater mobile use comes significant complications around clean-up and remediation when those mobiles are breached.

With employees innocently pushing forward with productivity, IT departments must take control of the security implications.

A recent study from Wandera found that companies spend three times as much on remedying a mobile security breach than they could have spent to simply prevent it in the first place.

In the UK alone, the average cost of remedying an enterprise mobile security breach stands at an astounding £167,000. To avoid this, organisations need to consider three basic but crucial steps to ensure they are sufficiently prepared to remedy a future breach.

1.    Assess and notify

This should be at the top of the to do list when a breach occurs. The news will need to be shared within your organisation immediately. Too often businesses are silent when data breaches occur, as though the fear of external discovery outweighs the importance of having a wider discussion throughout the organisation.

In terms of a mobile data breach, businesses need to realise that the situation is different. The split personality of a mobile device, by definition, involves an individual as well as the business. The faster the company notifies everyone involved and shares intelligence on what was breached, the less of a ripple effect the breach will have.

Passwords will need to be changed, including all device passwords, not just those used within the company, but any that were put at risk. Defensive steps will also need to be taken if sensitive data such as contact lists, credit cards, business or personal images and location information was leaked.

2   Perform a forensics analysis

To truly clean up a breach, there must be a clear understanding of how it occurred and what was put at risk. Performing a post-breach forensics investigation must start with visibility across the mobile fleet in the first place.

To get ahead before a breach occurs, companies should invest in a mobile threat defence solution that can provide data on how the breach occurred, which users were impacted and provide clues as to which data may have been compromised.

With complete visibility of the issue, businesses will be aware of what the next move needs to be to minimise further damage.

3.    Improve defences

The visibility that is obtained during forensics investigation can also pave the way for improved defences via policy controls in the future. Typically, IT teams roll out an open mobility program to start allowing users to install their own apps and ensure there are no restrictions on websites they can access.

As breaches occur, compliance violations are observed and as productivity concerns are raised, IT will often need to take a step back and implement mobile data policies to ensure that these corporate resources are used effectively and securely.

Companies need to take a close look at their access policies after a breach and ensure that adequate steps are in place to protect mobile data, while simultaneously safeguarding users’ productivity.

Security breaches don’t have a consistent formula or uniform. They come in different shapes, sizes and levels of damage, meaning there isn’t one way for businesses to protect themselves against a breach.

The sad reality is that it’s a case of ‘when’ a security breach will happen, instead of ‘if’ now, and organisations must be prepared for the aftermath.

As the probability of a hack increases, and the use of employee devices increases alongside this, organisations must take the above three steps into consideration to ensure that issues after the breach are minimised.

Information-Age:       Tech Jobs Would Be Great, If It Wasn’t For The Users:

 

 

« Social Media & The New Advertising Model (£)
Spies Use Tinder »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Blueliv

Blueliv

Blueliv is a leading provider of targeted cyber threat information and intelligence. We deliver automated and actionable threat intelligence to protect the enterprise and manage your digital risk.

2|SEC Consulting (2-SEC)

2|SEC Consulting (2-SEC)

At 2|SEC Consulting, we deliver an end-to-end service of cyber and information security solutions which are tailored to each client’s exact security needs.

Bulletproof Cyber

Bulletproof Cyber

Bulletproof offer a range of security services, from penetration testing and vulnerability assessments to 24/7 security monitoring, and consultancy.

Masergy Communications

Masergy Communications

Masergy delivers hybrid networking, managed security and cloud communication solutions to enterprises around the globe.

Centre for Cyber Security (CFCS) - Denmark

Centre for Cyber Security (CFCS) - Denmark

The Centre for Cyber Security is the Danish national IT security authority, Network Security Service and Centre for Excellence within cyber security.

Galois

Galois

Galois specializes in the research and development of new technologies that solve the most difficult problems in computer science.

Trapezoid

Trapezoid

Trapezoid is a cybersecurity company developing Firmware Integrity Management solutions designed to detect unauthorized changes to firmware & BIOS across the entire data center infrastructure.

Hypori

Hypori

Hypori is a virtual smartphone solution that makes truly secure BYOD a reality for organizations in healthcare, finance, government, and beyond.

Bounga Informatics

Bounga Informatics

Bounga Informatics provides Digital Forensics, E-Discovery, and Endpoint Security software, hardware, and training in Singapore and other countries in Asia Pacific.

CyBOK - University of Bristol

CyBOK - University of Bristol

CyBOK is a comprehensive Body of Knowledge to inform and underpin education and professional training for the cyber security sector.

Cloudsine

Cloudsine

Cloudsine (formerly Banff Cyber Technologies) is a cloud technology company specializing in cloud adoption, security and innovation.

Trustify

Trustify

Trustify is a Managed Security Service Provider offering a suite of world-class Cyber Risk Management services.

BlueHalo

BlueHalo

BlueHalo is purpose-built to provide industry capabilities in the domains of Space Superiority and Directed Energy, Missile Defense and C4ISR, and Cyber and Intelligence.

Hyperproof

Hyperproof

Hyperproof is a cloud-based compliance operations software. Launch new programs immediately, collect evidence automatically, and manage a compliance program intelligently.

Spinnaker Support

Spinnaker Support

Spinnaker Support is a premier global provider of on-premise and cloud-based enterprise software support services.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.