Security breach
A security breach is an event, or a chain of them, that lets somebody unauthorised compromise the integrity, confidentiality or availability of data, systems or networks. What defines it is not the entry point but how long it goes unnoticed.
A security breach is an event, or a series of events, that allows unauthorised actors to compromise the integrity, confidentiality or availability of data, systems or networks.
Breaches vary enormously in scope and severity, from unauthorised access to a single record through to attacks that end in the loss of large volumes of confidential data or the interruption of operations the business depends on.
Identifying one and responding to it effectively is what limits the damage, and both of those are capabilities that have to exist before the breach rather than be assembled during it.
What characterises it
An entry point. Every breach starts somewhere: an exploited vulnerability, a misconfiguration, or a credential obtained through phishing. The entry point is usually the least interesting part of the story.
Exfiltration. In many cases sensitive data leaves: personal information, financial records, intellectual property or anything else stored on the systems reached.
Time spent undetected. A successful breach normally means the attacker stayed unnoticed for a significant period, which is what let them explore, collect and plan. This is the property that decides the size of everything else.
Collateral damage. Depending on what was reached, the consequences extend past the technical: loss of customer confidence, reputational damage, and legal and regulatory obligations that start running from the moment the breach is known.
The forms it takes
Data breach. Unauthorised access to confidential information. It can come from a direct attack, from a lost device, or from information accidentally exposed by a misconfiguration, which is a larger share of real cases than most people expect.
Ransomware. Critical data is encrypted and a payment demanded. Modern operations also exfiltrate first, so paying or restoring does not resolve the disclosure.
Unauthorised access. Somebody reaches internal systems or networks, whether by exploiting a vulnerability or by using stolen credentials. The second is by far the more common, and the harder to see.
A worked example
A financial services company suffers a breach.
The attacker reaches the internal network using the credentials of an employee who fell for a phishing message. Once inside, they explore, identify databases holding confidential financial information, and exfiltrate it without being detected.
The company discovers the breach when it notices unusual patterns in its network logs.
On investigating, it identifies the activity, closes the route in, revokes the compromised credentials and notifies the affected clients.
The detail worth reading twice is that nothing exotic happened. A password, an ordinary login, and time.
Why the interesting number is dwell time
The way a breach is usually discussed is by entry point, and that is the wrong emphasis for two reasons.
The first is that entry points are cheap and numerous. Assuming one of them will eventually work is not pessimism, it is the premise of an assumed breach engagement, and the reason that kind of test exists at all.
The second is that the damage is a function of time. An intruder detected in an hour has done what one hour allows. The same intruder detected in three months has mapped the estate, taken what they wanted and, in a ransomware case, found and deleted the backups first.
Which is why the questions that matter for a breach are not really about the perimeter. How long would somebody with valid credentials go unnoticed here. Which of our logs would show it, and does anybody read them. And when the answer arrives, who is authorised to disconnect a production system at three in the morning, because incident response that has to wait for a decision maker is response measured in hours nobody has.
In the EU there is a deadline attached to the answer: a personal data breach has to be notified to the supervisory authority within 72 hours of becoming aware of it, which makes the ability to establish what happened a legal capability and not only a technical one. That is what digital forensics is for.
Where to read more
Verizon Data Breach Investigations Report: the annual analysis of real incidents, and the most widely used reference for how breaches actually begin.
CISA, protecting sensitive and personal information from ransomware-caused data breaches: practical guidance on prevention and on what to do afterwards.