Skip to content
English - United States
  • There are no suggestions because the search field is empty.

What Is a Data Breach and What Happens Next?

Unauthorized access to protected information, and what has to happen next.

A data breach is any incident in which someone gains unauthorized access to protected information: customer records, employee data, financial details, health information or intellectual property. It can be an attacker, a lost laptop, a misdirected email or an employee with more access than they should have.

How breaches usually happen

  • Phishing and stolen credentials, especially on accounts without multi-factor authentication.
  • Ransomware groups copying data before they encrypt it.
  • Unpatched systems and exposed remote access.
  • Misconfigured cloud storage or sharing links.
  • Lost or stolen devices without encryption.
  • Insiders with excessive access, whether malicious or careless.

What happens after a breach

  1. Containment. Stop the access, disable the accounts, isolate the systems.
  2. Investigation. Determine what was accessed, how, for how long and whether data left the environment. This is forensic work and it should not be rushed or overwritten by a hasty rebuild.
  3. Notification. Laws in Texas and most states require notice to affected individuals within a set period, and to regulators above certain thresholds. Contracts, cyber insurance policies and frameworks like PCI add their own obligations. Legal counsel should be involved early.
  4. Recovery. Restore systems, reset credentials, close the entry point.
  5. Prevention. Fix the root cause and document what changed.

What it costs

Response and forensics, legal fees, notification and credit monitoring, downtime, lost customers, higher insurance premiums, and in regulated industries, fines. For a small or mid-sized business the total is frequently large enough to threaten the company, which is why cyber insurance and prevention both matter.

Reducing the odds

MFA, endpoint detection, patching, least privilege, encryption on laptops, email filtering, and a tested incident response plan address the majority of causes above.

Mentis Group provides breach remediation through our IT Project Services and prevention through Enhanced Cybersecurity. See does Mentis Group offer breach remediation.

For a longer look at this topic, read Why Cybersecurity Is No Longer Optional for Growing Businesses on the Mentis Group blog.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.