Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Listen to Jay-Z’s first verse since 2022 on Beyoncé’s ‘Morning Dew (Donk)’ remix

    August 6, 2026

    SpaceX created a new class of ultrawealthy. Here’s what comes next

    August 6, 2026

    JUST IN: Senator Ron Johnson Says He Obtained Fauci’s COVID-Era iPhone from HHS Ahead of Contempt Vote

    August 6, 2026
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Science»Data Vu: Why Breaches Involve the Same Stories Again and Again
    Science

    Data Vu: Why Breaches Involve the Same Stories Again and Again

    By AdminJuly 26, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Data Vu: Why Breaches Involve the Same Stories Again and Again



    In the classic comedy Groundhog Day, protagonist Phil, played by Bill Murray, asks “What would you do if you were stuck in one place and every day was exactly the same, and nothing that you did mattered?” In this movie, Phil is stuck reliving the same day over and over, where the events repeat in a continual loop, and nothing he does can stop them. Phil’s predicament sounds a lot like our cruel cycle with data breaches.

    Every year, organizations suffer more data spills and attacks, with personal information being exposed and abused at alarming rates. While Phil eventually figured out how to break the loop, we’re still stuck: the same types of data breaches keep occurring with the same plot elements virtually unchanged.

    Like Phil eventually managed to do, we must examine the recurring elements that allow data breaches to happen and try to learn from them. Common plotlines include human error, unnecessary data collection, consolidated storage and careless mistakes. Countless stories involve organizations that spent a ton of money on security and still ended up breached. Only when we learn from these recurring stories can we make headway in stopping the cycle.

    The main plotline of so many data breach stories is human error. Over and over, people fall for phishing scams, fail to patch vulnerable software promptly, lose devices containing vital data, misconfigure servers or slip up in any number of other ways.

    Hackers know that humans are the weak link. Many break-ins to company databases occur less by technological wizardry and more by con artistry. For instance, hackers can trick an organization’s employees by sending an e-mail that looks like it’s coming from one of their supervisors. Doing so is easy: anyone can readily learn the names of supervisors by looking them up on LinkedIn and can then spoof an e-mail address. Essentially, hackers hack humans more than they do machines.

    Despite the fact that human error is an aspect of most data breaches, many organizations have failed to train employees about data security. As for the organizations that do, they often use long and boring training modules that people quickly forget. Not enough attention is paid to making training effective.

    It’s reasonable to expect that even with a well-trained workforce, some people will inevitably fall for hacker tricks. We must approach data security with realism that people can be gullible and careless, and human nature isn’t going to change. That means we need systems and rules in place that anticipate inevitable breaches and minimize their harm.

    In many data breaches, an enormous amount of information is lost all at once. because hacked organizations were collecting more data than absolutely necessary, or keeping such information when they should have been deleting it.

    Over time, organizations have been collecting and using data faster than they have been able to keep it secure—much like in the 19th-century industrial revolution when factories sprouted up before safety and pollution controls were introduced. Instead of hoarding as much information as possible, they should enact policies of data minimization to collect only data necessary for legitimate purposes and to avoid retaining unnecessary data.

    To make matters worse, many organizations have stored the vast troves of information they amass in a single repository. When hackers break in, they can quickly access all the data all at once. As a result, breaches have grown bigger and bigger.

    Although many organizations fear a diabolical hacker who can break into anything, what they should fear most are small, careless errors that are continually being made.

    For instance, an entirely predictable mistake is a lost device. Lost or stolen laptops, phones and hard drives, loaded up with personal data, have played a big role in breaches. Companies should assume that at least some losses or thefts of portable devices will occur—and to prevent disaster, they should require that the data on them be encrypted. Far too often, there is no planning for inevitable careless mistakes other than hoping that they somehow won’t happen.

    Money alone is not enough to stop hackers. In fact, many of the organizations that have had big data breaches were also big spenders on data security. They had large security teams on staff. They had tons of resources. And yet, their defenses still were breached. The lesson here is that money must be spent on measures that actually work.

    In the case of the Target breach in 2013, the company had spent a fortune on a large cybersecurity team and on sophisticated software to detect unusual activity. This software worked and sent out alerts—but security staff members were not paying enough attention, and reportedly they had turned off the software’s automatic defenses. Having the best tools and many people isn’t enough. A security team must also have a good playbook, and everyone must do their part.

    Although at the surface, data breaches look like a bunch of isolated incidents, they are actually symptoms of deeper, interconnected problems involving the whole data ecosystem. Solving them will require companies to invest in security measures that can ward off breaches long before they happen—which may take new legislation.

    With a few exceptions, current laws about data security do not look too far beyond the blast radius of the most recent breach—and that worsens the damage that these cyberattacks cause. Only so much marginal benefit can be had by charging increasing fines to breached entities. Instead, the law should target a broader set of risky actors, such as producers of insecure software and ad networks that facilitate the distribution of malware. Organizations that have breaches almost always could have done better, but there’s only so much marginal benefit from beating them up. Laws could focus on holding other actors more accountable, so responsibility is more aptly distributed.

    In addition to targeting a wider range of responsible entities, legislation could require data minimization. With reduced data, breaches become much less harmful. Limiting data access to those who need it and can prove their identity is also highly effective. Another underappreciated important protection is data mapping: knowing what data are being collected and maintained, the purposes for having the data, the whereabouts of the data and other key information.

    Government organizations could act proactively to hold companies accountable for bad practices before a breach occurs, rather than waiting for an attack. This strategy would strengthen data security more than the current approach of focusing almost entirely on breached organizations.

    But the law keeps on serving up the same tired consequences for breached companies instead of trying to reform the larger data ecosystem. As with Phil, until lawmakers realize the errors of their ways, we will be fated to relive the same breaches over and over again.

    This is an opinion and analysis article, and the views expressed by the author or authors are not necessarily those of Scientific American.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleAshton Kutcher, John Mayer on Working With B.J. Novak on ‘Vengeance’ – The Hollywood Reporter
    Next Article No NFTs in Minecraft? This Crypto Group Will Make Its Own Game

    RELATED POSTS

    Trump CDC pick Erica Schwartz confirmed to lead nation’s top public health agency

    August 6, 2026

    Gene-Edited Puppies Will Melt Your Heart—but Won’t Trigger Your Allergies

    August 5, 2026

    Wormholes could be the key to time travel

    August 5, 2026

    How Data Centers Broke American Politics

    August 4, 2026

    The U.S. military needs tungsten, but pristine NASA site may stand in the way

    August 4, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026
    latest posts

    Listen to Jay-Z’s first verse since 2022 on Beyoncé’s ‘Morning Dew (Donk)’ remix

    Jay-Z has delivered his first original rap verse in four years on a new remix of Beyoncé’s…

    SpaceX created a new class of ultrawealthy. Here’s what comes next

    August 6, 2026

    JUST IN: Senator Ron Johnson Says He Obtained Fauci’s COVID-Era iPhone from HHS Ahead of Contempt Vote

    August 6, 2026

    Trump slams Democratic Senate nominee Abdul El-Sayed on communism

    August 6, 2026

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026

    Trump CDC pick Erica Schwartz confirmed to lead nation’s top public health agency

    August 6, 2026

    Brand New Day’ Box Office Sets Record for Biggest Tuesday

    August 6, 2026
    Categories
    • Books (1,408)
    • Business (6,312)
    • Cover Story (9)
    • Film (6,251)
    • Lifestyle (4,311)
    • Music (6,322)
    • Politics (6,294)
    • Science (5,661)
    • Technology (6,246)
    • Television (5,942)
    • Uncategorized (3)
    • US News (6,297)
    popular posts

    Janet Yellen on insurance, climate change: ‘protection gap’

    Treasury Secretary Janet Yellen said the weather-related havoc playing out across the US is exposing…

    21 Reusable and Sustainable Products We Love (2024): Bags, Water Bottles, Straws, and More

    February 19, 2024

    Dark Winds Scores Season 2 Renewal at AMC

    June 22, 2022

    Alice Glass Has Her “Lips Apart” on New Single: Stream

    September 21, 2022
    Archives
    Browse By Category
    • Books (1,408)
    • Business (6,312)
    • Cover Story (9)
    • Film (6,251)
    • Lifestyle (4,311)
    • Music (6,322)
    • Politics (6,294)
    • Science (5,661)
    • Technology (6,246)
    • Television (5,942)
    • Uncategorized (3)
    • US News (6,297)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Trump CDC pick Erica Schwartz confirmed to lead nation’s top public health agency

    August 6, 2026

    Brand New Day’ Box Office Sets Record for Biggest Tuesday

    August 6, 2026

    Former ‘The View’ Host Speaks Out After Season 30 Reunion Snub

    August 6, 2026
    © 2026 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT