What to do if your organisation experienced a data breach

A data breach is a critical incident that occurs when unauthorised individuals gain access to sensitive or confidential information, potentially compromising the security and privacy of individuals or organisations. In today’s interconnected digital landscape, the risk of data breaches is a pressing concern for businesses and individuals alike. Recognising and promptly addressing a data breach is crucial not only for mitigating the immediate impact but also for safeguarding against long-term consequences.

This article aims to guide you through the essential steps of responding to a data breach – from understanding why reporting is imperative to outlining the process of reporting. In the ever-evolving realm of cybersecurity, knowledge is critical, and being equipped with the right information empowers individuals and organisations to navigate the challenges posed by data breaches effectively.

 

Is data breach a serious incident ?

Short answer: Yes, it is. The organization that experienced a data breach will be legally required to take some steps, which vary depending on the extent of the data breach. In some cases, notifying the relevant Data Protection Authority will be required.

Where to report data breach in UK ?

In the UK, the relevant Data Protection Authority is the Information Commissioner’s Office (ICO) – website ico.org.uk

Its approach is to encourage compliance. Where it finds issues, it take fair, proportionate and timely regulatory action to guarantee that individuals’ information rights are properly protected. If a data breach occurs, and it is likely to result in a risk to the rights and freedoms of individuals, organisations are generally required to report the breach to the ICO.

The reporting of a data breach is subject to the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

Does every incident must be reported ?

You need to consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach . . . if it’s likely there will be a risk then you must notify the ICO; if it’s unlikely then you don’t have to report. You do not need to report every breach to the ICO

No, not every incident must be reported. As we can red on ICO website: “You need to consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach . . . if it’s likely there will be a risk then you must notify the ICO; if it’s unlikely then you don’t have to report. You do not need to report every breach to the ICO

Source: ico.org.uk/for-organisations/report-a-breach/personal-data-breach-assessment

On the same subpage there is also possibility to carry out a self-assessment that is necessary to determine whether your organisation have to report to the ICO or not.

Timeline for Reporting

Organisations must report a data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

According to the information found on the ICO website, organisations must report a data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it

Source: ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide

Report it even if you do not have all the details about a particular breach, and mention that you will provide the information within a few days. This is important.

If the breach is likely to result in a high risk to the rights and freedoms of individuals, the affected data subjects (individuals whose personal data has been compromised) may also need to be informed, usually by email or any other legally accepted means.

How to report a breach to the ICO?

For guidance use that page ico.org.uk/for-organisations/report-a-breach

You can find there 4 sections that help to determine where to report

  • UK GDPR personal data breach (DPA 2018)
  • Trust service provider breach (eIDAS)
  • Communications services security breach (PECR)
  • Digital Service Provider incident reporting (NIS)

Keep in mind that if there is a breach impacting individuals in EEA countries, it will involve the EU GDPR. Consequently, in your breach response strategy, it is crucial to determine the European data protection agency that would serve as the primary supervisory authority for the affected processing activities.

Information to include in the report

The GDPR specifies the information that should be included in a breach report to the ICO. This includes details about the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and the measures taken or proposed to address the breach.

If you have any doubt, seek for advice from the ICO

How internal reporting can help the organisation ?

Organisations are encouraged to have internal processes in place to detect, report, and investigate data breaches promptly. Internal reporting should involve the organisation’s data protection officer (if applicable) and relevant personnel.

It is crucial for organisations to document their response to the data breach, including the decision-making process, actions taken, and any communication with data subjects or the ICO. This documentation is essential for demonstrating compliance with the GDPR.

ICO is more likely to impose lower penalties or do not impose at all if it is seen that organisation take every possible step to prevent data breach or mitigate the possibility its occurrence. Organisations that can show they have implemented robust security measures, provided adequate training, and promptly responded to breaches are more likely to receive favourable consideration. Demonstrating a strong commitment to data protection and actively implementing measures to prevent breaches is always viewed positively.

Fines and Penalties if you fail to report to ICO

For serious breaches of the data protection principles, ICO has the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.

Failure to report a data breach when required to do so can result in fines and penalties. As we can read on ICO website “For serious breaches of the data protection principles, we have the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.

Source: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/enforcement-of-this-code

When to notify Law Enforcement ?

In certain cases, especially if the breach involves criminal activity, notifying the police or specialised cybercrime units may be necessary. Criminal activities associated with a data breach involve the use of the compromised information for illegal purposes. This may include activities such as hacking, identity theft, fraud, unauthorised financial transactions, ransom demands, cyber extortion, or other offences that exploit the data obtained through the breach. The criminal activities are the actions taken by malicious actors or cybercriminals who exploit the breached data for personal gain or to cause harm.

If you have any doubt what to do. There is a few organisations that provide help. The most important is The National Cyber Security Centre (NCSC). The NCSC may become involved to offer assistance, advice, and expertise.

Their website: ncsc.gov.uk

What is the Financial Conduct Authority (FCA)

You might have heard that if the data breach involves financial information or affects financial institutions you need to notify FCA as well. No, you do not need.

In the United Kingdom, there is a Memorandum of Understanding (MoU) between the Information Commissioner’s Office (ICO) and the Financial Conduct Authority (FCA). According to this MoU, if a personal data breach occurs in the financial services sector, the primary responsibility for notifying the FCA lies with the ICO.

Your responsibility is notifying the ICO. If necessary, the ICO will deal with the FCA directly.

Law you need to familiarise yourself with

It’s important for organisations to familiarise themselves with the specific requirements of the GDPR and the Data Protection Act 2018 and to update their data breach response plans accordingly. Do it in advance. Seeking legal advice can also be beneficial to ensure compliance with data protection regulations in the UK.

WPA2 vs WPA3

WPA2 (Wi-Fi Protected Access 2) and WPA3 (Wi-Fi Protected Access 3) are both modern wireless security protocols designed to secure Wi-Fi networks. WPA2 is the current industry standard, which is considered to be secure. However, WPA3 is the newest and more advanced in comparison to WPA2. In this article we will talk about some crucial differences between them. I will try to explain this as clearly as possible. However, if you don’t understand some of my explanations, don’t hesitate to send me a message. I will compare both methods taking into consideration some aspects listed in the table of content below

 

Encryption Method

WPA2: The Advanced Encryption Standard (AES) with a 128-bit key for encryption. So far, this is considered highly secure, or at least enough secure in most cases. Full name of that algorithm is AES-CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol)

WPA3: WPA3 primarily uses a 256-bit Advanced Encryption Standard (AES) in Galois Counter Mode Protocol (GCMP) for encryption, which is significant improvement compared to the encryption used in WPA2.

Authentication

WPA2: We have here two options. WPA2-PSK – All devices connected to the network share a common encryption key, called Pre-Shared Key (PSK). It means that if an attacker obtains the key, they can potentially decrypt all network traffic. Second option is WPA2-Enterprise – It provides individualised and unique credentials for each device.

WPA3: Implements customized data encryption. This means that each device (PC, tablet, or whatever else) possesses its own unique encryption key, so even if one device’s key is compromised, it will only affect that specific device. The rest remains unaffected.

It uses the Simultaneous Authentication of Equals (SAE) protocol with 192-bit encryption key, to establish a secure connection. This protocol is designed to protect against offline dictionary attacks, which by itself provides even more security. 192-bit security key applies to the strength of the cryptographic operations used within the SAE protocol. It does not directly correspond to the length of the encryption key used for data encryption in AES

Note that this additional 192-bit encryption key in WPA3 does not apply to AES – online data encryption, but to SAE – additional encryption that prevent offline dictionary attacks.

Brute Force Attacks

WPA2: Vulnerable to offline brute force attacks, where attackers attempt to guess the network’s passphrase by repeatedly trying different passwords. Not necessarily manually.

WPA3: Offers protection against offline dictionary attacks by implementing a more robust key derivation process, making it significantly harder for attackers to crack the passphrase. See also the previously explained SAE.

Public Open Wi-Fi

WPA2: Does not have any built-in support for encrypting open public networks. Open networks are susceptible to eavesdropping. This is reason why I always discourage people from using Public Wi-fi

WPA3: Introduces Opportunistic Wireless Encryption (OWE), which provides encryption for open public Wi-Fi networks, enhancing privacy and security even on networks that does not require a password/passphrase. WPA2 does not provide similar security for public networks. So I can tell you this is a significant improvement.

Summary

These are major improvements that WPA3 introduced over WPA2 in terms of security and privacy. It offers stronger encryption, personalized data protection, resistance to offline attacks, improved support for public Wi-Fi networks. WPA3 is still not so popular, mostly due to lack of compatibility with older devices, but soon it become more widely used and integrated into newly manufactured devices and routers. Always check compatibility when upgrading your network.

Read also article about history of wireless security protocols

From WEP to WPA3: The History of Wireless Security Protocols

In today’s digital age, ensuring the security of each wireless network is critical. But how did we reach the level of security we enjoy today? What were the pivotal stages in enhancing wireless communication security? Wireless network security protocols have come a long way from the insecure WEP to the robust and continually evolving WPA3. The evolution continues to adapt to constantly emerging threats and technological advancements in wireless communication.

In this article, I will take you on a journey to uncover the development of wireless security protocols. These are the tools and techniques that have evolved over time to protect our wireless connections from different potential threats.

 

What is a security protocol

A security protocol is like a set of rules and procedures that protect a Wi-Fi connection from unauthorised access. This is a sort of secret handshake between devices and the router to ensure that only users who knows that secret code have access to the network. This protocol helps encrypt data transmitted over Wi-Fi, so it’s like sending information in a locked box that only you and your devices can open.

WEP

WEP stands for Wired Equivalent Privacy. It was formally released 1997 and 1999 and designed to provide some level of privacy and data security over wireless networks that was considered equivalent to the security of wired networks. However, WEP had serious security flaws and is now considered highly vulnerable. It used 40-bit encryption key, and weak initialisation vectors (IVs) that repeat over time, making it easier for hackers to decipher the static encryption key.

Note that some older devices and legacy systems may still rely on WEP for compatibility reasons, but in general, using WEP in modern networks is strongly discouraged due to its security weaknesses, so replace your old wireless device with a new one.

WPA

WPA stands for Wi-Fi Protected Access. It is a security protocol designed to address the vulnerabilities and weaknesses of its predecessor, WEP (Wired Equivalent Privacy). WPA uses TKIP (Temporal Key Integrity Protocol) as its encryption algorithm which dynamically generates unique encryption keys for each data packet, making it much harder for attackers to crack the encryption compared to the static keys used in WEP.

WPA offers a PSK (Pre Shared Key) mode, also known as WPA-PSK or WPA Personal, which allows home users and small businesses to use a passphrase as a shared secret key for authentication purposes, simplifying network setup. WPA also supports an enterprise mode, known as WPA-EAP or WPA-Enterprise, which is typically used in larger organisations. It integrates with authentication servers like RADIUS (Remote Authentication Dial-In User Service) for more secure and scalable user authentication.

WPA also had some security vulnerabilities, so it was replaced by WPA2.

WPA2

WPA2, stand for Wi-Fi Protected Access 2. It is widely used security protocol for wireless networks. It represents a significant improvement over its predecessor, WPA. Here are some important features of WPA2.

This protocol uses the Advanced Encryption Standard (AES) protocol, which is considered highly secure. AES is a symmetric key encryption algorithm that encrypts data with a 256-bit key, making it extremely difficult for attackers to decipher intercepted data.

It also improved key management in comparison to previous WPA. It utilises a 4-way handshake process to securely exchange encryption keys between the client device and the wireless access point (AP). This process boost security.

WPA2 offers both PSK (WPA2-PSK or WPA2-Personal) and Enterprise (WPA2-EAP or WPA2-Enterprise) modes. In PSK mode, a pre-shared passphrase is used for authentication, while Enterprise mode employs a RADIUS (Remote Authentication Dial-In User Service) server for more robust and scalable user authentication.

Over time, some vulnerabilities in the WPA2 protocol have been discovered, such as the KRACK attack (key reinstallation attack). To mitigate the problem, security patches/updates have been developed. WPA2 is the industry standard – a widely used and recognised wireless security protocol, compatible with all modern Wi-Fi devices.

It is worth noting that as technology evolves, new safety standards are introduced, such as WPA3. As it is the newest one, it is not compatible with older devices.

WPA3

WPA3 introduced a significant improvement in comparison to WPA2 in terms of security and privacy features, such as stronger encryption, personalised data protection, high resistance to offline attacks and improved long-term security with forward secrecy. WPA3 will become widely used and integrated into new devices and routers some point in the future. However, please note that the current availability of WPA3 support depends on network hardware and devices, so it is worth checking compatibility when updating your network.

If you are interested, you can read an article with comprehensive comparison WPA2 and WPA3

The Security Threats of Unencrypted HTTP Traffic and How to Stay Safe

Running a website is an exciting journey, but before you dive in, let’s talk about some crucial steps to ensure a smooth and secure online presence. Shockingly, many renowned websites worldwide are still clinging to an insecure method known as HTTP. While some might believe the risk is minimal, there are cases where SSL/TLS certificates are not just a good idea but a legal requirement, especially if your website handles sensitive data.

In the upcoming sections, we’ll explore the dangers and potential consequences of choosing HTTP over HTTPS, shedding light on why HTTPS is the superior choice for your website’s security and user trust.

 

What is HTTP

HTTP, or Hypertext Transfer Protocol, is the foundation of data communication on the World Wide Web. Throughout its history, HTTP has played a fundamental role in making the World Wide Web accessible and user-friendly. Its evolution has been driven by the need for faster, more efficient web communication, adapting to the changing demands of internet users and the technology landscape. Plain HTTP lacks inherent security, necessitating the introduction of HTTPS for enhanced protection.

Is HTTP website really risky ?

I’d like to clarify that visiting an HTTP site can indeed be risky, but this risk primarily applies when the website offers services involving data downloads, data exchanges, or processing – every situation in which users engage with these services actively by using contact or registration forms, credit card payments, login options and similar services. It is something more that simply browsing website passively. For purely informational websites that don’t involve user interaction or data exchange, HTTP poses minimal interception risk since nothing is being exchanged.

However, many web browsers display a warning message when user attempts to open such a website

“Your connection is not private” message

Many visitors of some websites have likely come across this message at some point while browsing the internet. Some of them don’t fully grasp the inner meaning of “Your connection is not private” message with a warning that attackers might be trying to steal your information. Sounds scary, but you need to know something…

“Your connection is not private” message does not indicate whether a website is infected or not.

“Your connection is not private” message does not indicate whether a website is infected or not. It is not about malware. We are talking here about traffic encryption and the consequences if it is intercepted. That message it simply means that your web browser has detected a potential security issue related to lack of encryption.

I use the term ‘potential’ because a web browser has no knowledge of a specific website’s functionality, so it automatically rejects displaying most HTTP pages as a precaution, regardless of their functionality.

What happens when HTTP traffic is intercepted by hackers?

With HTTP, all the data traffic originated to and from website is sent in an open text – unencrypted format. This means that if hackers intercept this traffic they will see your passwords, logins, usernames, credit card numbers, and other sensitive information you have entered on that website.

In order to secure such a website an SSL/TLS protocol must be installed

SSL/TLS protocol – How to encrypt website traffic

The protocol used for securing website traffic was called SSL (Secure Sockets Layer). It’s a technology that provides a secure and encrypted connection between your web browser and a web server. Please note that SSL protocol, which was widely used in the past for securing data in transit, has been succeeded by the more secure TLS protocol (Transport Layer Security). TLS offers similar services to SSL but operates at a higher level of security. While TLS inherits some of the core functions of SSL, it incorporates significant security enhancements, making it the preferred current standard for modern web communication. The terms SSL and TLS are often used interchangeably in casual conversation. So if you say you need SSL encryption on your website, any IT professional will correctly assume you need to implement TLS.

SSL/TLS ensures that the data exchanged between the two is protected from eavesdropping, tampering, or theft. After your website is encrypted it will receive “S” letter at the end and will be seen as HTTPS

If a particular website is encrypted, you will see a locked padlock icon in the search bar next to the website’s name. You can click on the padlock to read more details. These details are not so important for you, but for those interested, I will write a separate article about them in the future.

The main services provided by SSL/TLS protocol

Authentication

SSL/TLS helps verify the identity of the website you’re visiting. It ensures that you’re connecting to the real website and not a fraudulent one trying to steal your information.

Encryption

SSL/TLS encrypts all data transmitted between your browser and the website’s server (the place where the website is stored and displayed from). This means that even if someone intercepts the data while it’s in transit, they won’t be able to understand it without the encryption key.

Encryption is a very complicated process that makes data looks like random set of digits – a result of complex mathematical algorithms. So, even if someone intercepts your message, they can’t figure out what it says because it’s in this secret encrypted code.

To better understand the concept imagine you’re sending a highly private letter, so you decided to use some secret language to write the message – cryptography.

When your friend receives the message, they know how to decode it because they understand the secret language. But for anyone else who tries to read it, it just looks like a jumble of random letters. So, even if someone intercepts your message, they can’t figure out what it says because it’s in this secret encrypted code. That’s similar to how intercepted data from HTTPS traffic looks like.

Data Integrity

SSL/TLS also ensures that the data exchanged is not tampered with during transmission between a user’s browser and a website’s server. If someone tries to modify the data in route (it is called man-in-the-middle attack), the recipient can detect it, making the altered data invalid. It simply ensures that the data arrives in the same state as it was sent, free from unauthorised changes.

What kind of SSL/TLS certificate to consider ?

When considering the purchase of an SSL/TLS certificate, it is essential for the Client to plan the number of domains and/or subdomains it intends to protect as part of its business operations. It is important to note that subdomains (e.g., subdomain.maindomain.com) are treated as separate domains and won’t be protected if a company purchases a certificate for a single domain (e.g. maindomain.com).

Certificate Authorities (CAs) – the entities that issue SSL/TLS certificates, offer various options that fit to different needs. For example, providers like Sectigo (formerly Comodo) or Rapid SSL offer packages that can protect a single domain or multiple subdomains. CAs also provide different levels of guarantees and offer two types of validation: Domain Validated (DV) and Organization Validated (OV). With DV, only domain ownership is verified, while OV involves verification of both company details and domain ownership. If the Client has additional question, the entity (broker) that sells the SSL certificates “on behalf” of Cerificate Authorities will provide additional information.

Where to purchase SSL/TLS ?

To purchase an SSL/TLS certificate, you can chose an agent, typically a current hosting provider or domain registrar, who will facilitate the process

To purchase an SSL/TLS certificate, you can chose an agent, typically a current hosting provider or domain registrar, who will facilitate the process, but it does not necessarily need to be your current hosting provider, but any other authorised agent. After payment is done, the required information are exchanged, validated and the SSL/TLS cert is assigned to the domain. After its activation the entire website related traffic is encrypted and possibility of data breach mitigated.

How HTTP website impact google ranking

Apart of security, there’s another crucial factor to consider with HTTP. Google’s ranking algorithm tends to deprioritise or ignore HTTP sites when ranking them in search results. This can significantly impact a business’s visibility and reputation from a commercial perspective. This is yet another reason, in addition to security concerns, why investing in an SSL/TLS certificate is worthwhile.