Majority of businesses remain in the dark over data breaches

Updated happygeek 2 Tallied Votes 467 Views Share

New research by Varonis has revealed that only 25% of those companies questioned were able to answer yes to the question: "Are you able to detect when files containing sensitive data are uploaded to a third party cloud service?" Which left a staggering three-quarters of businesses in the dark about the potential for data leakage. It's a growing problem, what with the increasingly widespread availability of public cloud storage such as Dropbox and Google Drive to employees during the last couple of years. The research paper 'Security Incidents and Real-time Alert' also suggests that companies are in the dark about other important security issues. Not least the ability to spot when there has been a data breach.

272d294adccdf9dd9feddfdbdf2bca98

This 'Red Alert Research Report' was based upon survey data from some 248 information security professionals attending industry events in the UK and US, so the results are about as good a painting of the real-world business IT security landscape as you are going to get. The people being questioned were, after all, those tasked with the job of actually protecting corporate data. Unfortunately, the portrait revealed leaves something of a bad impression. With earlier research showing 67% of data breach incidents taking 'several months' to discover and 70% finding out about them through customers or partners instead of the internal IT department, it's perhaps a little sad to now discover only 6% have implemented any kind of automated breach detection and notification system. Especially when previous research suggests that basic detective and preventative control systems could have stopped a great many breaches in their tracks.

DaniWeb spoke to Andy Green, Technical Content Specialist at Varonis, who said: "Our Red Alert Data Breach survey shows that companies have a long way to go in detecting breaches that have slipped through front line safeguards. Only 6% of our sample had fully automated capabilities to monitor privilege escalations, unusual data access patterns and file access changes, and suspicious email. The good news is that breach detection and monitoring controls are finally receiving validation from security experts. For example, the Federal government has recently called for “continuous monitoring” as a key part of its new cyber security program for the nation’s critical infrastructure. The bottom line is that IT departments should also be putting more resources into incident response and risk mitigation as part of their security efforts.”

Certainly, from speaking to IT security professionals about overall security strategies during the last year or so, one point has been cropping up again and again in our conversations and that is how real-time monitoring of activity and an ability to alert the relevant IT guys about suspicious behaviour, is fast becoming non-optional for any organisation which actually wants an effective data security strategy in order to take the bad guys on with.

Dani AI

Generated

As highlighted, the core problem here is visibility — many organisations lack reliable signals that sensitive files are leaving corporate control. That gap makes detection slow and containment harder, and it ties into ’s point about insider/physical leaks and ’s concern that the issue has persisted for years. The following is a practical, prioritized approach that fills the “what next?” gap left by the thread.

  • Inventory and classify first. Identify the small set of data types that would cause the most harm if exposed (customer PII, payment data, IP) and map where those files live.
  • Discover and control cloud usage. Use API-based discovery and network logs to find sanctioned and unsanctioned cloud services, then apply policies (sharing defaults, domain-only sharing, access revocation).
  • Enforce identity controls. Centralise authentication (SSO), require MFA, and implement least-privilege role-based access so stolen credentials have limited scope.
  • Deploy focused DLP and endpoint controls. Start with a few high-confidence detection rules (sensitive patterns, large exports) and tune aggressively to reduce false positives.
  • Add behavioral detection and logging. Feed file-access events and cloud audit logs into a central analytics engine (SIEM/UEBA) to spot mass downloads, unusual external uploads, or privilege escalations.
  • Automate containment and playbooks. Have simple automated actions for common incidents (revoke tokens, quarantine accounts, block transfers) and scripted playbooks for escalation.
  • Cover physical vectors and culture. Controls for removable media, secure printing, clear-desk rules, and role-specific training reduce accidental leaks almost immediately.

Caveats: start small, measure MTTD/MTTR for the highest-risk data, and involve legal/HR when designing monitoring to respect privacy and compliance. Incremental wins — a small, well-tuned set of detection rules and automated responses — will reduce exposure far faster than unfocused, high-volume alerts.

mmcdonald 28 Posting Pro

This is so very concerning - especially when the value of most companies lies in one asset: their data! I've always taken security very seriously and for that reason wouldn't open a single office without having a dedicated security professional. A 2nd/3rd line support technician jst doesn't cut it (and neither does a firewall for all you lazy individuals out there!).

I wouldn't actually be surprised if the majority of data leaks are physical and were the fault of arrogant employees who fail to see the sensetivity of most documents.

Member Avatar for Member #949455
Member #949455

"Our Red Alert Data Breach survey shows that companies have a long way to go in detecting breaches that have slipped through front line safeguards. Only 6% of our sample had fully automated capabilities to monitor privilege escalations, unusual data access patterns and file access changes, and suspicious email. The good news is that breach detection and monitoring controls are finally receiving validation from security experts.

So this has been going on for years til now that security experts are now monitoring the situation? That is really disturbing because it's on going.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.