Does Size Matter?

Does Size Matter?

This last month I spent some time conducting a very unscientific experiment to see how social media responds to data breaches and cybercrime, and this past couple of weeks I noticed something that made me decide to finally write this blog.

I will start by saying that LinkedIn hasn’t disappointed me, and my industry hasn’t let me down… but it was with a wry smile that I began to write this blog this morning because it’s just so apparent what an interesting (and prudish) lot we are! Allow me to explain…

Capital One and others

In recent months we’ve heard about Capital One and their Data breach which has the potential of affecting 100 million customers. We also heard about how Oyster Card systems were hacked, resulting in 1,200 account details being stolen, and this came shortly after it was revealed that a care service on the Isle of Man had lost personal details of almost 100 people either in its care or working for them. These and other Data breaches, large and small have been reported with a varying degree of focus over the last thirty-or-so days.

But of these three mentioned here you’ll most likely have seen a lot of activity on social media focused on Capital one, but perhaps not on the others. Of course this could be simply down to the size of the breach; Neither the Oyster card nor Manx attacks came close to the 1 million mark, so perhaps like an earthquake that doesn’t register higher then 2 on the Richter scale – it’s not important!?

I believe this is worrying trend for a number of reasons. The first is that people seem to be coming blasé to data breaches and attacks, unless the number is reaching the multiple of millions. Like the lives of 1,200 people aren’t quite as important. Of course this could also be because they’re not as widely reported as the larger breaches, which brings me to my second point. As professionals in this industry shouldn’t we being taking as much notice of smaller breaches as the larger ones? Or are we also becoming blasé to smaller breaches, and simply chasing the bigger and sexier stories that are ‘trending’.

But if you want sexy…

Given my thoughts above it was really interesting to note that 14 days ago a breach occurred which has the potential of affecting 1.2 million users, yet it barely caused a ripple on LinkedIn (at least not amongst my 4k contacts and followers). How could this be? Admittedly it wasn't as big as the Capital One data breach, but at 1.2 million records I was surprised to see it barely commented on by the industry luminary! What was going on?!

The answer was simple… The company in question is classified as an ‘Adult-content sharing site’ (because apparently uttering the word ‘Porn’ can see you go straight to hell, do not pass GO, do not collect £200!?). ‘Luscious’ exposed the personal details of almost 1.2 million users on an unsecured database, which was discovered by researchers. It isn’t yet known if this information is now in the wild or if the information is being used to carry out sextortion (a form of blackmail carried out on individuals who are linked to some sexual act/imagery). But still... 1.2 million people affected - potentially.

Ashley Madison 2.0 (AM2.0)

Of course many people will have heard about the other big data breach which occurred in 2015, which affected 37 million users. When ‘Team Impact’ carried out the attack on the 'Alternative dating site', Ashley Madison. Here they threatened to release the details of people who had provided detailed personal information about themsleves and their sexual preferences, unless the site was shut down. It wasn’t. So they did.

To date we know that thousands received demands for money in return for 'silence' from the Cybrcriminals, thousands more most likely paid (we have no way of knowing). But we do know that for some, the shame, embarrassment and fear was just too much to handle, resulting in eight people sadly taking their own lives. All as a direct result of that breach.

And now we have AM2.0. Slightly smaller in size, but the issues are no less worrying, and I can only hope that any one of the 1.2 million affected seeks professional advice should they fear the worse.

So does size matter?

The size of the breach shouldn’t dictate if or how we respond to it. We should learn from those who suffer a breach and ask “What does this teach us?”, “What can I learn from this?”, and “How can I ensure WE are not the next headline?” We need to have these conversations irrespective of the company who is the victim of the attack or cause of the breach.

Data breaches come and go… but the lessons are there for us all to learn from, if we are paying attention.

Cybercriminals know that they can pray on fear, uncertainty and doubt and there is nothing (it would appear) that we humans fear more than having our personal sexual preferences and details exposed to the world. Cybercriminals know this… and I hope that those running ‘Adult-sharing-content’ sites(!) know this too and are taking every available precaution available. But then again, we all need to be thinking more about personal protection, shouldn’t we?

Mark Roebuck, MSc, MBA

Founder of ProvePrivacy: Data protection compliance platform.

5 年

Are you auditioning to be a Shutterstock model?

Paul Lewis AIGP FIP CIPM CIPT CIPP/C CIPP/A CISSP

Senior Privacy Manager, Country Privacy Leader & Data Privacy Officer, Canada. Johnson & Johnson.

5 年

Ref the article I think dating sites are just dating sites in whatever context or interpretation applicable - no idea what an Alternative Dating site is, as there is no correlation to a baseline of some norm. Anyway, I digress, my basic answer to the question posed is.... may depend upon the correlation to a level of success or a failure, and associated outcomes.

Ian West

Business strategy advisor, executive mentor and leader, driving Digital Business Change, Growth, Compliance and Innovation.

5 年

Gary - size always matters!

?? Donald Allen ????

#StandWithUkraine | Multiple Times Best-selling Author. Keynote Speaker. Top 50 Global Thought Leader & Influencer on Cybersecurity, Marketing, Startups, EdTech by Thinkers360. Founder & CEO, dacybersecurity.com

5 年

Yeah, I think we should talk more about all data breaches. If we don't, SMBs will still think that nobody targets them (which is not true at all). Is it something around 60% of all cyberattacks target SMBs?

要查看或添加评论,请登录

Gary Hibberd FCIIS的更多文章

  • June: It has been busy!

    June: It has been busy!

    This is a quick round up of our month at Consultants Like Us! I post almost everyday, so there might be things you…

  • Knowing and doing are not the same

    Knowing and doing are not the same

    You might not have seen the movie 'The Matrix', but you'll probably have heard the phrase "I know Kung Fu". It's a…

  • 5 Cybersecurity lessons that Star Wars can teach us

    5 Cybersecurity lessons that Star Wars can teach us

    “A long time ago… in a galaxy far far away … A data breach occurred and launched one of the biggest Business Continuity…

    12 条评论
  • Security Policies - More than Words

    Security Policies - More than Words

    Why do people turn into robots when they write Security Policies? Or worse..

    31 条评论
  • 16th April - Titanic - The Aftermath

    16th April - Titanic - The Aftermath

    Monday, 16th April 1912 Many of those who perished on the RMS Titanic were crew members and third-class passengers, but…

    2 条评论
  • 15th April - Titanic - Her Final Destination

    15th April - Titanic - Her Final Destination

    Sunday, 15th April 1912 The glancing blow with the iceberg was fatal to the Titanic. As the berg, scraped and ground…

    10 条评论
  • 14th April - Titanic - Iceberg! right ahead!!

    14th April - Titanic - Iceberg! right ahead!!

    Saturday, 14th April 1912 As dawn brakes and the day began on the Titanic, Senior wireless operator, Jack Phillips…

    7 条评论
  • 13th April - Titanic - an 'uneventful' day?

    13th April - Titanic - an 'uneventful' day?

    Friday, 13th April 1912 Titanic’s passengers and crew continue to familiarise themselves with the ship. There's plenty…

    6 条评论
  • 12th April - Titanic - All calm

    12th April - Titanic - All calm

    Thursday, 12th April 1912 After leaving Queenstown, the Titanic set sail for her final destination, immortality. The…

    1 条评论
  • 11th April - Titanic is already on Fire!

    11th April - Titanic is already on Fire!

    Wednesday, 11th April 1912 On this day, the Titanic had already visited Cherborg, France to collect passengers and now…

    5 条评论

社区洞察

其他会员也浏览了