Privacy Perils: Data Breach Strikes Cybersecurity Training Company

Bass, Berry & Sims PLC
Contact

Bass, Berry & Sims PLC

Most of us have never heard of SANS, a prominent and well-respected cybersecurity training company.  As its website states, “SANS is the most trusted and by far the largest source for information security training in the world.” However, even the organization least likely to experience a data incident can fall victim. On August 11, Bleeping Computer reported SANS disclosed a single successful phishing email that enabled the attacker to set up an email-forwarding rule that transmitted 513 emails containing 28,000 records of personally identifiable information (PII) to a suspicious external email address. To its credit, apparently SANS discovered and disabled the rule quickly, and promptly disclosed the incident. Importantly, SANS was transparent about what had happened. As described in a {ride the lightning} information security blog, SANS turned the event into an educational opportunity by hosting a webcast to “walk through the technical details of the incident, how it happened, our investigation details, current indicators of compromises, and finally our overall lessons learned and security awareness recommendations to prevent these incidents in the future.”

The point? Even those employed at a sophisticated, knowledgeable and cyber-aware organization are not immune to successful cybersecurity attacks. Each of us must continually be mindful and prudent when dealing with our email. Haste can lay waste. Remain alert and attentive, as “[t]he battle, sir, is not to the strong alone; it is to the vigilant, the active, the brave.” – Patrick Henry.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Bass, Berry & Sims PLC | Attorney Advertising

Written by:

Bass, Berry & Sims PLC
Contact
more
less

Bass, Berry & Sims PLC on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide