Financial Poise
defend against data breaches

How Threat-Savvy Companies Can Defend Against Data Breaches

Data Breach Prevention Measures Are Necessary in Today’s Climate

Data breaches are happening at an alarming pace. The variety of attack methods we see is just as disturbing as the volume of breaches. Data breach prevention should be on every company’s radar. Adopting a well-balanced approach incorporating leading cybersecurity control framework requirements, privacy regulations, and behavioral monitoring tools and techniques can help your company gain a competitive advantage in protecting critical information assets and personal information.

To give some idea of the problem and its rapid escalation, in 2024, there were 9,478 publicly disclosed data breach incidents. This number represents an approximate 200% increase over the number of incidents reported the year prior. Why are these incidents escalating at such a disconcerting rate? There are many reasons.

Many Companies Are Just Beginning To Address Data Privacy and Security Regulations

Understanding data elements that reside in or transverse organizational networks is essential for effective data privacy and security risk management. This understanding allows for the determination of investing in appropriate data safeguards based on data classifications (e.g., High, Moderate, Low). Often overlooked is the need to designate Data Custodians; however, this role is essential for managing and protecting data assets.

Furthermore, many organizations do not have mature processes for performing third-party due diligence third-party assessments for service providers that collect, store, or process data on their behalf. Without effective due diligence procedures, third parties may not be held to regulatory, security, and compliance standards, and in turn, this can result in ineffective data management and data compromise.

Advanced Persistent Threats

It should come as no surprise that the Payment Card Industry (PCI) and Healthcare industries are highly susceptible to Advanced Persistent Threats (APTs). With the high-resale value of credit card numbers, organizations that collect, store, or process credit card numbers have historically been subject to data breach vulnerabilities. However, recent history shows that healthcare providers are becoming more vulnerable to significant data breaches. As such, Health and Human Services (HHS) has been strengthening regulatory requirements that are intended to safeguard Protected Health Information of Covered Entities and Business Associates.

As hackers continue to see the high monetary value of ePHI, the pendulum continues to shift, and as such, healthcare providers must be prepared for cyberattacks. Unrestricted ePHI system access and/or weak network access controls can lead to accidental data disclosure or intentional by way of ransomware attacks, and the consequences to patients can be dire when doctors are prevented from accessing critical diagnostic information or ePHI system data.

Fines and Other Deterrents

Fines under GDPR and by the US Health Department might motivate large companies to improve IT controls. These fines can be up to 4% of an entity’s annual revenue. However, after considering the monetary penalties incurred after the data breach is reported to the authorities, smaller companies may have second thoughts about reporting a data breach incident. Consequently, these regulatory fines may not be an effective deterrent. Nevertheless, a single data breach incident in 2024 cost global companies approximately $4.88 million dollars. For this reason, it is worthwhile and cost-effective to proactively establish IT controls that may detect and prevent a breach from occurring.

So, what else can be done to deter threats? Threats may decrease with new security measures and access controls backed by repeatable, measurable, and manageable operational processes. Combining these measures with periodic expert assessments is a step in the right direction.

NIST Cybersecurity

To create sustainable risk management, organizations must adopt an IT controls framework. The National Institute of Standards and Technology Cybersecurity Framework (NIST CSF version 2.0) is a good option. NIST’s holistic approach includes preventive and detective controls, including procedures to follow during and after a breach. Organizations that adopt NIS CSF 2.0 and controls recommended by the Center for Internet Security (CIS) will further improve their threat prevention and detection.

Securing a Competitive Advantage with Anti-Data Breach Technology

Once a framework has been adopted, it must be supported by perceptive people, thorough processes, and effective technologies. If social awareness techniques are not instituted within an organization, the employees will continue to be susceptible to malicious attempts like phishing emails. This can result in unauthorized access to critical technologies and personal information. Some of this personal information can include health records, social security numbers, and genetic data.

Effective threat deterrence needs teamwork and knowledge of an organization’s threats. It also requires strong IT controls and quick incident response. Successfully combating APTs and preventing data breaches requires an understanding that threats are always present, risks need to be evaluated continuously, and the frequency of attacks will vary over time. Businesses that grasp these concepts will have a significant competitive advantage through sustainable and recoverable IT operations.


We think you’ll also like:

  1. 5 Important Considerations for Aspiring Franchise Investors
  2. 4 Vital Items Your Employee Benefits Package Needs to Remain Competitive
  3. Investing in a Collectible NFT is Neither Smart Nor Really Even Possible

[Editors’ Note: To learn more about this and related topics, you may want to attend the following on-demand webinars (which you can listen to at your leisure, and each includes a comprehensive customer PowerPoint about the topic):

  1. Introduction to US Privacy and Data Security: Regulations and Requirements
  2. Data Privacy Compliance
  3. Data Breach Response: Before and After the Breach

This article was originally published on April 10, 2019 and updated on November 29, 2021.]

©2025. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.

 

Share this page:

About Adam Sarote

Adam Sarote has over 25 years of IT consulting expertise and is the founder of Adaptive Consulting Services, a boutique cybersecurity firm. His passions include building meaningful business relationships, fostering collaboration, cybersecurity, data privacy, risk management, and baseball. Before establishing Adaptive Consulting Services, Adam led programs focused on data privacy, cybersecurity risk, IT audit, and…

Read Full Bio »

Follow Adam Sarote on: