These are 4 questions you need to consider after a data breach

By Albert Kuo

In the moments after a security breach is detected, moving quickly is incredibly important for Singapore businesses, especially now that the Personal Data Protection Commission (PDPC) plans to revise the Personal Data Protection Act (PDPA) to require companies to notify it of breaches within 72 hours.

Before these incidents occur, it’s vital to make a plan that will enable you to investigate incidents quickly and with greater accuracy. The decision-makers of the company need to understand where critical assets lie and the information that may need to be reported ahead of time, so that the Incident Response (IR) team isn’t significantly burdened after a breach.

To ensure that IR teams are prepared when an attack happens, here are four questions these teams should be prepared to answer from the moment a breach occurs to ensure all of the information needed for disclosing it to relevant stakeholders is readily available:

1. What’s the scope of this incident?
There’s only one thing worse than announcing leaked records, and that’s needing to make the same announcement more than once. Organisations need to understand exactly how extensive the breach was in order to avoid this faux pas—or, like some companies, be comfortable with announcing the maximum possible number of affected users before investigations are complete. There are pros and cons to playing it safe, but the best solution is to see what roadblocks exist in the IR team’s ability to investigate breaches and remove them wherever possible.

2. What kind of violation is it (e.g. PCI-DSS or HIPAA)?
If the IR team only has 72 hours to gather as much information as possible about a breach before reporting, it’s critical to know which policies to address. Requiring companies to report breaches does not just mean there’s less time before customers know about an incident. It also means that the organisation will be expected to answer more specific, technical questions about the incident in a shorter timeframe.

3. Who is affected?
Identifying which customers have been affected will require precision in order to mitigate the damage to the company’s reputation. Security breaches are a fact of modern life, but customers still expect stringent protections and data privacy. When a breach does occur, company leaders across functions will need deep visibility to answer these questions right away.

4. What did the attack campaign look like—and are the attackers still present?
According to a report from PwC, business leaders in Singapore who had experienced a cyber attack noted that these incidents primarily occurred through the exploitation of mobile devices and phishing. In addition to understanding how an attacker made it past the organisation’s defenses, these organisations also need to determine whether the attacker is still inside the environment. This goes hand in hand with the current breach detection gap. In 2018, attackers could dwell inside an environment for three months on average before the breach was detected.

As Singapore and other governments around the world continue to strengthen consumer protections and privacy rules, this last question will grow more and more important. We’re moving away from a time when security was primarily considered the responsibility of companies and the increase in publicised breach reporting will ultimately lead to customers putting their trusted organisations under more scrutiny.

Implementing frameworks like the Center for Internet Security (CIS) Top 20 Critical Security Controls can help organisations answer these questions quickly, but many need help extracting value from ambitious frameworks that require better visibility and a more efficient use of security resources. We have seen how an emerging category of security and analytics can help. 

Join Singapore Business Review community
Since you're here...

...there are many ways you can work with us to advertise your company and connect to your customers. Our team can help you dight and create an advertising campaign, in print and digital, on this website and in print magazine.

We can also organize a real life or digital event for you and find thought leader speakers as well as industry leaders, who could be your potential partners, to join the event. We also run some awards programmes which give you an opportunity to be recognized for your achievements during the year and you can join this as a participant or a sponsor.

Let us help you drive your business forward with a good partnership!

Top News

Lorem Ipsum text in year 2025
Contrary to popular belief, Lorem Ipsum is not simply random text. It has roots in a piece of classical Latin literature from 45 BC, making it over 2000 years old.
Lorem Ipsum is simply dummy text of the printing and typesetting industry.
Contrary to popular belief, Lorem Ipsum is not simply random text. It has roots in a piece of classical Latin literature from 45 BC, making it over 2000 years old. Richard McClintock, a Latin professor at Hampden-Sydney College in Virginia, looked up one of the more obscure Latin words, consectetur, from a Lorem Ipsum passage, and going through the cites of the word in classical literature, discovered the undoubtable source. Lorem Ipsum comes from sections 1.10.32 and 1.10.33 of "de Finibus Bonorum et Malorum" (The Extremes of Good and Evil) by Cicero, written in 45 BC. This book is a treatise on the theory of ethics, very popular during the Renaissance. The first line of Lorem Ipsum, "Lorem ipsum dolor sit amet..", comes from a line in section 1.10.32.

Exclusives

Cropping Issue on Responsive one
Contrary to popular belief, Lorem Ipsum is not simply random text. 
Artificial Inteliigence Testing
Contrary to popular belief, Lorem Ipsum is not simply random text. 
Lorem Ipsum is simply dummy text of the printing and typesetting industry.
Contrary to popular belief, Lorem Ipsum is not simply random text. It has roots in a piece of classical Latin literature from 45 BC, making it over 2000 years old. Richard McClintock, a Latin professor at Hampden-Sydney College in Virginia, looked up one of the more obscure Latin words, consectetur, from a Lorem Ipsum passage, and going through the cites of the word in classical literature, discovered the undoubtable source. Lorem Ipsum comes from sections 1.10.32 and 1.10.33 of "de Finibus Bonorum et Malorum" (The Extremes of Good and Evil) by Cicero, written in 45 BC. This book is a treatise on the theory of ethics, very popular during the Renaissance. The first line of Lorem Ipsum, "Lorem ipsum dolor sit amet..", comes from a line in section 1.10.32.
Lorem Ipsum Singapore Business Review
The text to display in the title bar of a visitor's web browser when they view this page. This meta tag may also be used as the title of the page when a visitor bookmarks or favorites this page, or as the page title in a search engine result. It is common to append 'Singapore Business Review' to the end of this, so the site's name is automatically added. It is recommended that the title is no greater than 55 - 65 characters long, including spaces.The text to display in the title bar of a visitor's web browser when they view this page. This meta tag may also be used as the title of the page when a visitor bookmarks or favorites this page, or as the page title in a search engine result. It is common to append 'Singapore Business Review' to the end of this, so the site's name is automatically added. It is recommended that the title is no greater than 55 - 65 characters long, including spaces.