How to avoid a data breach

The vulnerability of senior executives to cyber-attacks is often overlooked. Chief executives are privy to information that’s not widely known within their organisation, making them attractive targets to criminals. Consequently, they can often be imbued with trust, authority and power within the organisation, which can potentially make them a significant liability to the company.
Business Email Compromise (BEC) attacks are when a cyber criminal adopts the identity of a senior executive and sends emails to staff members in an attempt to trick them into doing something that they shouldn’t.
With information about businesses and their employees publicly available on company websites, LinkedIn, Facebook, Twitter and more, these attacks can be very effective.
Trying to avoid this involves enforcing security policies and procedures, authenticating all fund transfers with the finance department (or all data shares with the legal department), and making employees, no matter their seniority, aware of these practices.
Unusual requests to bypass company procedure, regardless of the source, should be considered suspicious and verified before any action is taken.
By cultivating awareness of it among employees, the threat can be hugely mitigated.
It’s easy to see a data breach as a cyber security problem: a failure of defences that enables criminal exploitation.
But the reality is that these breaches often tell us a lot about how firms have built up large repositories of sensitive data over time and may have failed to minimise and anonymise the data that they hold.
The recently disclosed Uber hack of 57m customers and drivers is a good indication of the scale of data that’s now being amassed by digital economy businesses. This raises privacy concerns and increases the risk of a major breach.
Cyber security and privacy are more closely linked than some believe – and a good approach may be to reduce data holdings to limit impact and exposure.
An interesting example is the recent decision by Wetherspoons to delete its customer email database to minimise held data.


