Data Breach
A security incident where protected or confidential data is accessed by unauthorized parties.
Also known as: Security breach, Data leak, Information breach
Category: Concepts
Tags: security, privacy, risks, incidents, data
Explanation
A data breach is a security incident where protected, confidential, or sensitive data is accessed, stolen, or exposed by unauthorized parties. Breaches can result from: external attacks (hacking, malware), insider threats (malicious or negligent employees), accidents (misconfigured servers, lost devices), and third-party compromises (vendor breaches). Types of breached data: personal identifiable information (PII), financial data, health records, credentials, intellectual property, and communications. Consequences include: identity theft for affected individuals, regulatory fines for organizations, reputational damage, legal liability, and operational disruption. Prevention involves: security fundamentals (encryption, access controls, patching), employee training, incident detection systems, and vendor security assessment. Response requirements: contain the breach, assess the damage, notify affected parties and regulators, and remediate vulnerabilities. The breach landscape: breaches are increasingly common, costs are rising, and no organization is immune. For knowledge workers, understanding data breaches helps: protect personal information, implement security practices, respond appropriately to breach notifications, and recognize that data protection is everyone's responsibility.
Related Concepts
← Back to all concepts