business: breach: Breach, Response, Plan, Reports
Cascading Data Breaches
by Brent Kirkpatrick
(Date Published: 2/2/2018.)
When a breach is discovered, it is because hackers broke through the defenses and were able to copy data. This means they obtained administrative access. In the process, they may have modified data, changed configurations, or otherwise wormed their way deeper into the systems. Hackers do this in order to retain access after your team tries to clean-up and block their access.
A data breach usually has cascading security breaches associated with it. The IT team discovers the original breach and fixes some obvious vulnerabilities. Everyone hopes that the hackers are blocked from accessing the systems. However, usually the hackers have entrenched their position, and they re-gain access. This usually happens several times in succession while the defensive team continues to patch vulnerabilities.
Data breaches can have cascading intrusions that continue for months. This entire time frame would be referred to as one incident. This happens even when there is only one attacker.
defendIT. AI-driven security measures derived from security incident data.