Data Breaches

Crisis and Opportunity

Specificaties
Paperback, blz. | Engels
Pearson Education | e druk, 2019
ISBN13: 9780134506784
Rubricering
Juridisch :
Pearson Education e druk, 2019 9780134506784
Verwachte levertijd ongeveer 9 werkdagen

Samenvatting

Why do some organizations emerge from a data breach unscathed, while others are badly damaged, or even collapse? How can you make smart choices to protect your organization before and after a data breach? This book exposes the high-octane world of data breach disclosure and response, where IT help desk staff have the power to save or destroy a company, and cutting-edge attorneys must often parachute in to save the day. You’ll watch as one of the world’s most experienced cybersecurity professionals dissects high-profile data breaches, reveals what happened, and reveals exactly what you can do to navigate a massive data breach -- quickly mitigating damage to your digital assets, finances, and organizational reputation.

 

Sherri Davidoff teaches through storytelling, making this book powerfully accessible and practically useful to everyone from the boardroom to the server closet. Along the way, she reveals what the press didn’t cover about attacks on ChoicePoint, TJ Maxx, Heartland, Target, Anthem, and many other leading organizations -- and presenting specific lessons you can start applying right now, regardless of your technical or business infrastructure.

 

Drawing on her immense personal experience with digital forensics, incident response, security awareness training, penetration testing, and web security assessment -- and her work teaching in venues from Black Hat to the Department of Defense -- Davidoff introduces today’s most comprehensive and practical framework for data breach response. You’ll discover: Critical turning points throughout data breach events, and how to respond to each of them How breach response lifecycles are changing: why classic incident response approaches are no longer sufficient, and what to do instead How internal politics can affect data breach response, and what to do about it How to read between the lines of public statements and notifications (or lack thereof) What you need to know about breaches in retail and other specific industries -- and the limitations of standards such as PCI/DSS How to protect against and recover from ransomware How to assess products and services such as Commercial Off-The-Shelf Breach Response, cybersecurity insurance, and crisis management services What you can do right now to make breach response less traumatic An insider’s guide offering a new, systematic, and practical framework for data breach response: finally, an accessible, comprehensive playbook for what to do when Built around in-depth and highly-specific case studies: what really happened at ChoicePoint, TJ Maxx, Heartland, Target, Anthem, Sony, Children's Hospital Boston, and more Identifies critical decision points in high-profile data breaches, and explores the risks and benefits of the choices that were made at the time Written by the hacker featured in the bestseller 'Breaking and Entering: The Extraordinary Story of a Hacker Called "Alien"

How to protect your organization against massive data breaches, and mitigate the financial and reputational consequences if they happen An insider’s guide offering a new, systematic, and practical framework for data breach response: finally, an accessible, comprehensive playbook for what to do when Built around in-depth and highly-specific case studies: what really happened at ChoicePoint, TJ Maxx, Heartland, Target, Anthem, Sony, Children's Hospital Boston, and more Identifies critical decision points in high-profile data breaches, and explores the risks and benefits of the choices that were made at the time

Specificaties

ISBN13:9780134506784
Taal:Engels
Bindwijze:Paperback

Inhoudsopgave

Preface xvii<br>Acknowledgments xxiii<br>About the Author xxv <br> <br> Chapter 1: Dark Matters 1 <br>1.1 Dark Breaches 3 <br>1.2 Skewed Statistics 13 <br>1.3 Why Report? 18 <br>1.4 What’s Left Unsaid 20 <br> <br> Chapter 2: Hazardous Material 23 <br>2.1 Data Is the New Oil 30 <br>2.2 The Five Data Breach Risk Factors 33 <br>2.3 The Demand for Data 34 <br>2.4 Anonymization and Renonymization 41 <br>2.5 Follow the Data 44 <br>2.6 Reducing Risk 51 <br>2.7 Conclusion 54 <br> <br> Chapter 3: Crisis Management 55 <br>3.1 Crisis and Opportunity 57 <br>3.2 Crisis Communications, or Communications Crisis? 60 <br>3.3 Equifax 70 <br>3.4 Conclusion 75 <br> <br> Chapter 4: Managing DRAMA 77 <br>4.1 The Birth of Data Breaches 79 <br>4.2 A Smoldering Crisis 81 <br>4.3 Prodromal Phase 85 <br>4.4 Acute Phase 94 <br>4.5 Reducing Harm 98 <br>4.6 Chronic Phase 108 <br>4.7 Resolution Phase 111 <br>4.8 Before a Breach 114 <br>4.9 Conclusion 117 <br> <br> Chapter 5: Stolen Data 119 <br>5.1 Leveraging Breached Data 121 <br>5.2 Fraud 121 <br>5.3 Sale 123 <br>5.4 The Goods 135 <br>5.5 Conclusion 141 <br> <br> Chapter 6: Payment Card Breaches 143 <br>6.1 The Greatest Payment Card Scam of All 144 <br>6.2 Impact of a Breach 146 <br>6.3 Placing Blame 150 <br>6.4 Self-Regulation 153 <br>6.5 TJX Breach 160 <br>6.6 The Heartland Breach 167 <br>6.7 PCI and Data Breach Investigations 171 <br>6.8 Conclusion 174 <br> <br> Chapter 7: Retailgeddon 177 <br>7.1 Accident Analysis 179 <br>7.2 An Ounce of Prevention 191 <br>7.3 Target’s Response 199 <br>7.4 Ripple Effects 223 <br>7.5 Chip and Scam 227 <br>7.6 Legislation and Standards 236 <br>7.7 Conclusion 237 <br> <br> Chapter 8: Supply Chain Risks 239 <br>8.1 Service Provider Access 242 <br>8.2 Technology Supply-Chain Risks 245 <br>8.3 Cyber Arsenals 252 <br>8.4 Conclusion 254 <br> <br> Chapter 9: Health Data Breaches 257 <br>9.1 The Public vs. the Patient 258 <br>9.2 Bulls-Eye on Healthcare 260 <br>9.3 HIPAA: Momentous and Flawed 263 <br>9.4 Escape from HIPAA 274 <br>9.5 Health Breach Epidemic 279 <br>9.6 After a Breach 295 <br>9.7 Conclusion 300 <br> <br> Chapter 10: Exposure and Weaponization 303 <br>10.1 Exposure Breaches 305 <br>10.2 Response 310 <br>10.3 MegaLeaks 323 <br>10.4 Conclusion 336 <br> <br> Chapter 11: Extortion 337 <br>11.1 Epidemic 339 <br>11.2 Denial Extortion 340 <br>11.3 Exposure Extortion 348 <br>11.4 Faux Extortion 356 <br>11.5 Conclusion 357 <br> <br> Chapter 12: Cyber Insurance 359 <br>12.1 Growth of Cyber Insurance 361 <br>12.2 Industry Challenges 361 <br>12.3 Types of Coverage 362 <br>12.4 Commercial Off-the-Shelf Breach Response 364 <br>12.5 How to Pick the Right Cyber Insurance 367 <br>12.6 Leverage Your Cyber Insurance 386 <br>12.7 Conclusion 388 <br> <br> Chapter 13: Cloud Breaches 389 <br>13.1 Risks of the Cloud 393 <br>13.2 Visibility 400 <br>13.3 Intercepted 409 <br>13.4 Conclusion 413 <br> <br> Afterword 415 <br> <br> Index 417

Net verschenen

Rubrieken

Populaire producten

    Personen

      Trefwoorden

        Data Breaches