Blog: Data Breaches – how to Limit the Risks

In the first part of this two-part series, we told you what a data breach actually is and what the consequences can be. In this second part, we discuss how you can limit the risks of a data breach.

In today’s digital world, where data has invaluable worth, preventing data breaches is of utmost importance. Most data breaches occur when organizations share data. To ensure data security and prevent data breaches, there are three important domains to establish within the internal organization: legal, processes, and governance.

Legal

The first domain, legal, encompasses the legal aspects of data sharing. Before data can and may be shared at all, certain legal aspects must be established. A crucial step for sharing data is drafting a data processing agreement between the controller and the processor. This agreement contains arrangements about what the processor may and may not/must do with the personal data that the data controller provides. The security policy and the purpose of processing are some of the matters that must be included in this agreement.

Processes

The processes domain plays an essential role in preventing data breaches. Here, all steps and procedures of data sharing are documented and executed. First, it must be determined which data is shared. The principle of minimization is important here: if certain data is not needed, it should not be used or shared.

Additionally, it’s important to know where data comes from and how it’s brought together. Because separating data that doesn’t need to be stored together is also important for data security. However, it’s essential that if the data needs to be linked together, the right procedures are in place for this. This involves data quality and data management. Data quality is a crucial aspect to ensure that the data is reliable and accurate, and thus the right connections can be made across different databases.

Once these connections are made and a unique customer profile emerges, consideration must be given to the form in which data is shared. If data is leaked for any reason during a step in the process, you want to limit as much damage to the consumer as possible. Therefore, techniques such as hashing and encryption are often applied to ensure that if data is leaked, it’s not readable. Data quality comes into play here again. Encrypted data can only be recognized and matched if the data matches exactly. Quality and uniformity therefore form the basis for effectively deploying these techniques.

Once data is minimized, encrypted, and linked, and quality is optimized, it can be processed. The important consideration remains: for what purpose do you share data, how important is it for you as a company, and especially: what impact might it have on the consumer. In this context, it’s always important to consider which data you share and whether you subsequently achieve the intended purpose with it. Next, processed data must be delivered to the data controller. Although it sounds logical to also establish delivery through secure channels, it often happens, even at large organizations, that files are shared ‘simply’ via email. For example, because unauthorized persons or employees who don’t deal with data processing play a role in this process. This is one of the most common data breaches. Ways that data can be safely delivered are channels such as SFTP, an API, or cloud sharing. This also ends the process of data sharing and processing.

Governance

The third pillar, Governance, is crucial for ensuring data security during sharing. Although a large part of the responsibility is determined in the legal domain, the steps in the process must ultimately be carried out by people. It’s important to determine what roles these people hold and whether there’s separation of duties or if one person can do everything. It’s essential to have clarity about who performs which steps. Not everyone should have access to all data during the process. Specific data specialists can be responsible for certain datasets, while others have no access. During the process, consideration must also be given to data visibility. Data can be encrypted to prevent it from being unintentionally visible and to limit damage if leaked. Finally, there must be oversight of the processes and their security. This oversight can be exercised by the Data Protection Officer (DPO), the legal team, or other relevant stakeholders.

Holistic Approach

Preventing data breaches requires a holistic approach where legal, procedural, and governance aspects are integrated. Organizations must ensure they have a solid foundation in the legal area, where clear agreements are established. Processes must be optimized and data sharing must take place according to a well-thought-out plan. Additionally, governance structures must be set up to assign responsibilities, establish access restrictions, and oversee security. By considering these three domains, organizations can take proactive steps to prevent data breaches and ensure the confidentiality and integrity of data.

Tips to Prevent Data Breaches

Preventing a data breach therefore doesn’t have one golden rule or approach. Danger can come from a small corner. A holistic approach reduces the chance of a data breach, but isn’t integrated into daily operations overnight. Therefore, we give 5 pragmatic tips from our domain that will limit your data breach risks as much as possible starting tomorrow.

Data Minimization

Ensure data minimization within your organization. Only use data that you really need. For every step where data is used, ask yourself: “Do I need this data? Do I need to request it?” And if the answer to these questions is “no,” then don’t request it and don’t use it. So if you don’t need social security numbers, for example, despite being allowed to have them, don’t use them and remove them from the database. This way you limit the severity of a data breach, should one occur.

Security

Ensure good firewalls and software that’s up-to-date. It’s important to secure data on devices with multi-factor authentication. Should it happen that a device is lost, you limit the damage in a data breach. As mentioned earlier, hashing or encryption can also help here.

Create Awareness among Employees

Make colleagues and employees aware of possible risks. Provide training where necessary to minimize risks. Use secure passwords and don’t leave them lying around the office. Don’t use public local networks. Criminals can abuse these networks or even mimic them to monitor your computer.

And always think critically when you send sensitive data or are approached by people you don’t know. How sensitive is the data you’re working with? Is this the safest method of data transfer? Are you being approached by someone you don’t know? What do they want? What questions are they asking? Are there irregularities? Et cetera. Don’t trust it? Then contact the privacy officer within your organization.

External Help

While some aspects, such as creating awareness, are relatively pragmatic solutions to prevent the risk of a data breach, others like setting up a secure infrastructure, standardizing data, hashing, and matching are not easily accomplished for many organizations. This is especially true when you want to focus on your core business. Fortunately, there are organizations that can help secure your organization and processes as effectively as possible, so you don’t have to deviate from your core business. These “trusted third parties” assist your company in establishing and executing these steps.

For example, EDM helps organizations improve and standardize personal and address data through data quality. Data is hashed if necessary, and matching can be facilitated through smart and secure matching routines. The legal aspect also forms a prominent part of the service. With knowledge and experience in data processing, -engineering, -delivery, and cloud, EDM offers pragmatic solutions tailored to your specific needs, which will impact data security, process optimization, and risk reduction tomorrow.

If you want to know how EDM can make your organization future-proof, read more about our data & cloud expertise. Or contact us, and we’ll be happy to discuss this topic with you.