data breach

How to Prevent Data Leaks in Your Company

The year 2021 will be remembered as the worst in history when it comes to data breaches, especially those of companies, which are the main targets of cybercriminals .

New technologies, laws, and customs have been implemented to reduce risks and keep corporate data protected and confidential.

In this material you will find information about data breaches, major cases from 2021, and most importantly: how to prevent data breaches in your company.

Tools, actions, materials, and articles, all completely free and available for you to learn once and for all how to avoid this digital incident.


Download the eBook for this content.

No time to read now? Download the eBook with all the content on this page and learn definitively how to prevent data leaks in your company.


Index

  1. What is a data breach?
  2. How does a data breach happen in a company?
  3. Biggest data leaks of 2021
  4. LGPD and its influence on data breaches
  5. 5 steps to deal with a data breach
  6. What not to do to prevent data leaks
  7. An efficient and affordable solution for businesses
  8. Trends and news about data leaks
  9. Free materials

Note: Each topic has a button that automatically takes you back to the Index. We hope this feature is helpful.


What is a data breach?

A data breach is the improper and unauthorized exposure of personal, sensitive, confidential, biometric, behavioral, or confidential data, such as registration or browsing data.

A serious problem that exponentially increases the risks and occurrence of online scams and fraud.

Data breaches cause all kinds of damage: financial, property-related, moral, strategic, competitive, personal, etc.

A data breach is a process that involves at least three stages:

  • (Unauthorized) access
  • Collection (unauthorized).
  • Public disclosure or sale.

That is, before the unauthorized disclosure by the "data owners ," there will be violations of improper access and collection.

In other words, data breaches don't happen overnight or in isolation. According to the definition of "process," the crime of improper data disclosure occurs as a "continuous and ordered sequence" of actions.


How does a data breach happen in a company?

Data breaches are typically caused by vulnerabilities and/or failures in information security and internet access . They can also occur in situations such as:

  • Data theft
  • Cyberattacks
  • Malicious codes
  • Using weak passwords
  • Action by current or former employees
  • Loss or theft of equipment
  • Negligence in the disposal of equipment and media.
  • Data being transferred without protection.
  • Intrusion into personal, business, or data storage systems.
  • Improper and/or illegal collection of browsing data
  • Malicious apps and websites
  • Excessive data collection without users' knowledge.
  • Lack of data security
  • Outdated or pirated software and applications
  • Account hacking
  • Incompetence and/or recklessness online
  • Insecure connections

Biggest data leaks of 2021

Brazil jumped from sixth to first place globally in data breaches . A sad statistic. See below some events that made this fact a reality.

PIX vulnerability

In August, there was a leak of 414,500 Pix keys per phone number from the Bank of the State of Sergipe (Banese). At the time, registration data was leaked, but sensitive data (passwords and bank balances) was not exposed.

Finally, the same article reports a recent data breach on January 21, 2022: more than 160,000 Pix keys were exposed.

The security incident, which occurred between December 3 and 5, 2021, exposed names, CPF numbers (Brazilian taxpayer ID), institutions, branch numbers, and account numbers . According to information from the Central Bank, the data breach did not affect the transactions of the 160,100 clients of Acesso Soluções de Pagamento .

Click here to access the full article.

These are good examples of the risks and damages that data breaches can cause to individuals and companies.

The first in the world

On December 18, 2021, CNN Brazil published an interview with digital crime expert Wanderson Castilho .

In the report, the expert states that, after calculating the number of data points exposed by the hacker attack on the Ministry of Health's system, "more than 227 million data points belonging to Brazilians were exposed ."

Thus, Brazil surpassed the United States by more than 14 million data points exposed. Learn more .

Monster leak

A public website leaked 426 million personal data records and 109 million CNPJs (Brazilian company tax IDs), as well as Brazilian vehicle license plates . "A perfect opportunity for cybercriminals to carry out social engineering scams," the article states.

This massive data breach was detected by the dfndr enterprise . After identifying the "suspicious indexing," the dfndr lab (Psafe's digital security laboratory) forwarded a report to the National Data Protection Authority (ANPD).

Without identifying the origin or the manner in which this data leak occurred, the article warns of the seriousness of the situation. According to the report, with the exposed data, it would be possible to "open fake companies and accounts on social media .
Learn more .

From bad to worse

According to a report published on CanalTech on December 16, 2021, in the first 11 months of the year, 24.2 million profiles were exposed "due to attacks or breaches in systems." Learn more .

Coincidence?

On October 4, 2021, WhatsApp, Facebook, and Instagram went offline . It definitely wasn't a good year for CEO Mark Zuckerberg.

Coincidence or not, on that same day (October 4, 2021), news emerged that data from 1.5 billion Facebook users was for sale on a hacker forum on the dark web .

Olhar Digital website , in this case, the data leak did not originate from a hacker attack. This database was allegedly obtained through scraping: a process that collects information left available due to user carelessness (public profiles). Learn more .


LGPD and its influence on data breaches

The General Data Protection Law (LGPD) seeks to protect freedom and privacy. In practice, it demands changes in the way personal data is collected, stored, processed, and used.

As a result, it impacts the administrative, legal, communication, and marketing areas. But, primarily, it impacts internet access technologies and information security .

Therefore, the LGPD (Brazilian General Data Protection Law) encourages the adoption of measures against data leaks and to protect privacy.

Its purpose is to try to ensure that personal data is handled lawfully , appropriately, and securely.

includes both stored data (locally or in the cloud) and data in transit . Because of this, individuals and businesses have been seeking and researching secure and privacy-focused solutions, such as VPNs and DNS firewalls .

When we talk about LGPD (Brazilian General Data Protection Law) and data breaches, we must be extra careful. After all, the fines are hefty . But, above all, because the damage to a company's reputation can be irreversible.


5 steps to deal with a data breach

Implement data protection compliance solutions, tools, and processes . See what else is needed to address a data breach in your company and other security incidents.

  • Invest in and improve measures for managing and controlling internet access and for information and data security.
  • To structure an internet access, data control and security policy in accordance with existing regulations and legislation ( LGPD ).
  • Create and maintain a crisis management team. Qualified personnel who must know what to do, how to do it, and when to do it to stay ahead of the company and its actions during data breaches or other security incidents.
  • Planning and incorporating a tactical and operational plan for crisis situations into internet access and control policies, as well as data security and control, will serve as the guide for the crisis management team .
  • Notify the victims (owners of the leaked data) and the National Data Protection Authority (ANPD). At a minimum, the company must complete the incident reporting form provided by the ANPD (click here to access).

What not to do to prevent data leaks in your company

Knowing the enemy and their strategies is important. In this digital war against cybercriminals, knowing what not to do wrong online can be crucial to preventing data breaches in your company.

  • Verifying identity through static information – It no longer protects as it once did. Static information is an invitation to data leaks, and fraud prevention techniques based on it are becoming outdated and increasingly susceptible to scams.
  • SMS for two-factor authentication – Mobile phones are very easy to clone and, therefore, a direct channel for data leaks within a company. The National Institute of Standards and Technology (NIST) has already stated that SMS is an unreliable technology as a security method for authentication.
  • Password authentication in mobile applications – Passwords and cell phones are insecure. Furthermore, usability and user experience are much better without passwords. The trend is to use other more secure authentication methods, such as facial or fingerprint recognition, for example.
  • Confirming or providing data online – Do not provide or confirm data by phone or unsecured applications (WhatsApp, Telegram, and Signa, for example). Even if the requesters seem genuine. Especially when they appear to be real, such as banks, the Judiciary, the Public Prosecutor's Office, large companies, etc.
  • Responding to SMS messages – To prevent data leaks by employees, companies should provide information and knowledge. Therefore, when receiving SMS messages that, for example, report an unusual and recognized transaction, the correct action is not to reply! Furthermore, replying provides data that can confirm personal or business identity.
  • Accessing links in SMS or WhatsApp – No link is trustworthy if received via SMS or free messaging apps (such as WhatsApp, Telegram, and Signal). This is especially true for messages like “the prize is yours, just…”, “this notification refers to the fine…”, “see the forbidden photos of the celebrity…”. These links likely contain viruses and malicious software that can cause significant damage, such as collecting bank and social media passwords. When the internet is corporate, the risk of data leaks by employees is extremely high.
  • Making payments or transferring funds – This guidance is aimed at employees in company finance departments. After all, they are the targets of this type of scam. Cybercriminals use apps or make phone calls, aided by previously leaked data and information. They invent stories and situations very close to reality and abuse the good faith (and lack of training and information) of employees. Thus, using social engineering, they try to dissuade employees from paying or depositing undue amounts. In 100% of companies that do not invest in data security and staff training, the chance of this scam succeeding is very high.

An efficient and affordable solution for businesses

Data breaches are a serious and current security incident that can be easily prevented . When companies take the right precautions and actions, this type of security incident can indeed be resolved.

Beyond just prevention, there are solutions and tools that also offer advantages and benefits .

From compliance with the LGPD (General Law for the Protection of Personal Data) and the regulations of the ANPD ( National Data Protection Authority ), to security, cost reduction, productivity, information and reports that assist in the BI (business intelligence) analysis process.

Among the solutions available on the market, you will learn about Lumiun Box . However, I emphasize that business owners, IT professionals, and managers should research and compare .

Certainly, the best way to decide is to choose the solution that best meets the security and productivity needs, and that also offers features and functionalities that suit the company's requirements.

Lumiun Box is the internet access security and management service recommended for small and medium-sized businesses. Because, in addition to seeking efficient protection against internet threats and improved team productivity, they also look for cost savings and reductions .

Therefore, the main benefits of Lumiun Box are:

  • SECURITY – to protect against threats on the company's internet.
  • PRODUCTIVITY – to increase the productivity of work teams and reduce wasted time.
  • ECONOMY – to reduce expenses related to security and device maintenance.
  • INFORMATION – to generate management reports on employee internet usage.

Based on DNS filtering, Lumiun Box manages internet access requests on the corporate network, across all connected devices. In addition to blocking websites, it prevents access to harmful, dangerous, or work-related sites. Lumiun Box includes several features such as:

  • Business VPN
  • Internet Access Management and Control
  • Security and prevention against internet risks
  • Firewall and network protection
  • Internet traffic and performance management
  • Management information and reports
  • Compatibility and integrations
  • Support, customer service, and customer success

Learn more about some of the main features of the Lumiun Box .


10 trends and new developments regarding data leaks in companies

The increase in cyber risks and threats , starting in 2022, is a consensus among cybersecurity experts.

The highest number of digital privacy breaches in Brazilian history, occurring in 2021, signals that we will see an increase in the number of cyber threats and a greater risk of data leaks in companies starting in 2022.

That's why we focus so much on the importance of information , prevention , and investment in security solutions, technologies, and systems . Because the lack of these conditions is what makes data breaches in companies one of the most frequent .

The purpose is to share information so that business owners, IT professionals, and managers know that, despite its seriousness, preventing data breaches is possible.

So, what's coming next?

On the following pages you will see some predictions from internet security experts for the coming months.

In addition to the already known cyber threats, new cyber risks and security challenges will emerge in 2022. Here are some of the main trends.

1. Ransomware attacks

Ransomware significant losses for insurers and organizations worldwide.

2. There is a shortage of talent in cybersecurity

Recruiting and retaining the best cybersecurity professionals to meet the challenges presented by the current cyber threat landscape will certainly be a significant business challenge starting in 2022.

In 2021, there were approximately 4.19 million cybersecurity professionals worldwide . This represents an increase of over 700,000 compared to 2020, according to the 2021 Cybersecurity Workforce Study by the International Information System Security Certification Consortium.

Despite this rapid growth in the cybersecurity workforce, the study also notes that "global demand for cybersecurity professionals continues to outstrip supply.".

Furthermore, cybersecurity is no longer just an information technology or information security risk – it's a corporate governance risk.

3. Challenges of cloud services

As more businesses and processes migrate to cloud-based solutions, cybercriminals will look for ways to exploit and infiltrate them.

However, the shift to a cloud-based solution does not mean that companies no longer have to deal with security.

That's an inappropriate thought. While a cloud provider may offer some security, it's still up to companies to adopt additional security measures.

4. Insurance market against security incidents

Policyholders and potential insurance buyers can expect the cyber insurance market to remain tense in 2022.

Because the high frequency and substantial severity of incidents such as data breaches, coupled with increased legislative and regulatory oversight, have led cyber insurance markets to require certain minimum controls for insurance qualification, coverage limits, and capacity reduction and limits.

As insurers' understanding of the causes of losses deepens, underwriting requirements will evolve. However, the requirement for strong controls will not change, even if we may see prices begin to decline in late 2022 or sometime in 2023.

Access the complete material.

5. Accelerating regulatory activity regarding security incidents

Internationally, 2021 saw China's Personal Information Protection Law come into effect, penalties under Brazil's General Data Protection Law become applicable, and the EU's final implementation decision on standard contractual clauses.

The size and scope of regulatory activity will likely continue to increase. Starting in 2022, we will see the introduction of new regulations, as well as amendments, supporting regulations, adjustments, and notices related to many of these recently enacted laws.

6. Cybersecurity improves awareness and culture against data breaches

It's difficult to financially quantify the damage caused by cybercriminals in recent years. But the negative impact these attacks have had on individuals, businesses, and public entities is immense.

On the other hand, a positive impact of the current cyber risk environment is a greater awareness of the need for attention, risk management strategies, and business resilience.

In a 2021 survey, Gartner found that 88% of corporate boards now view cybersecurity as a business risk .

7. Growing threats from operational technology

With the acceleration of digital transformation came the convergence of operational technology (OT) and information technology (IT). Now, computer hardware and software are used to manage equipment and operating systems.

Vulnerabilities in OT environments cannot be neglected or ignored . After all, strategic infrastructure sectors depend heavily on OT (energy, industry, manufacturing, logistics, oil and gas, telecommunications, and public utility management).

8. Trust in machine learning and artificial intelligence

While many companies have begun adopting automated solutions, others are investing in artificial intelligence and machine learning to support operational and business functions. Some of this appears to be driven by the COVID-19 pandemic .

Although automation and machine learning have been around for some time, they are relatively new technologies. Therefore, problems can arise with coding, incorrect configuration, insufficient testing, and conflicts with other systems and platforms.

As more companies move towards automated solutions, cybersecurity risks must be managed properly and effectively.

9. Supply chain at risk

Targeted attacks against multiple supply chains create significant disruption. Despite impacting a large organization, they result in substantial destruction because many others depend on the target organization.

Cybercriminals will continue to deploy this strategy, which has already proven to be very lucrative – supply chain disruptions will continue throughout 2022.

10. More collaboration to prevent data leaks

The digital and digitized world has historically been considered an IT problem. But a recent report published by the JP Morgan International Council observed that “cyber is the world’s most dangerous weapon – politically, economically and militarily”.

Therefore, combating and mitigating risks and data leaks can only be achieved through shared responsibility between companies, employees, and customers.


Free materials

To help you improve your company's internet security and control, we've selected our best resources on the subject.

We periodically strive to produce materials that can help business owners, managers, and IT professionals in their quest to improve the control and security of their companies' internet infrastructure.

Below, you will find tools, ebooks, documents, infographics, guides, and kits with free educational content that can be applied to human resources and internet management in companies.

Feel free to share with your colleagues and friends, they're all free !

We developed this material so that professionals and companies can definitively learn how and why blocking websites in a business environment is important and beneficial in different scenarios.

We've prepared important information about one of the most suitable internet protection tools for businesses: DNS Firewall. Throughout this material, you'll see what a DNS Firewall is and also 7 of the main reasons to use this internet protection tool in your company.

The internet is a means of communication, a source of information, and a work tool in companies. However, a lack of control over internet access in the business environment can have negative results, especially on employee productivity.

Every day, companies produce information , regardless of their size. This information adds value and increases productivity and competitiveness in the market . When used online, this data needs to be protected, and for this reason, so many internet security systems and tools exist.

Learn how to use the internet more safely and stay protected from online threats.


Download the eBook for this content.

No time to read now? Download the eBook with all the content on this page and learn definitively how to prevent data leaks in your company.