Data Controller Notification
Requirements (UK vs US):
In the UK, data controllers must
notify their data subjects of data security breaches that pose a high risk to
individuals' rights and freedoms, according to the General Data Protection
Regulation (GDPR). Notification should occur "without undue delay"
and, where feasible, within 72 hours of the breach being discovered.
In the US, there is no single
federal law mandating data breach notification. Instead, notification
requirements vary by state, with different laws governing when and how
individuals must be notified of breaches.
The Largest Data Breach of the
21st Century: The largest data breach occurred with Yahoo in August 2013,
which was discovered and publicly disclosed in December 2016. Data breach details
include:
- Number of Records Stolen: 3 billion user
accounts
- Type of Data Exposed: Usernames, email
addresses, hashed passwords, and security questions and answers
- Method of Attack: Exploitation of
vulnerabilities in Yahoo's systems
- Impact on Users: Potential identity theft,
unauthorized account access, and phishing attacks
- Response by Yahoo: Notification to affected
users and enhancement of security measures
- Financial Impact: The breach affected
Yahoo's acquisition deal with Verizon, resulting in a reduced purchase
price
Most Common Causes of Data
Security Breaches:
- Weak and Stolen Credentials
- Application Vulnerabilities
- Malware
- Malicious insiders
- Human Error
Real-Life Examples of Common Causes:
- Weak and Stolen Credentials: The 2013 Yahoo
data breach affected 3 billion accounts due to stolen credentials,
compromising usernames, email addresses, and security questions and
answers.
- Application Vulnerabilities: The 2017
Equifax data breach exposed personal information of 147 million
individuals. Attackers exploited an unpatched vulnerability in the Apache
Struts framework, leading to significant financial and reputational damage
for Equifax.
Comments
Post a Comment