Recent breaches making headlines all share a troubling characteristic. In each breach detailed below, the intrusions of company networks lasted months - or in other cases, even longer than a year. While no company is impervious to a breach, one thing organizations can control is how quickly they respond to security incidents. The longer compromises remain neglected and unresolved, the more likely that a large-scale breach will occur, resulting in significant data loss.
CareFirst BlueCross BlueShield
On May 20, CareFirst BlueCross BlueShield said 1.1 million records had been compromised. These included birthdays, social security numbers, email addresses, and insurance identification numbers. CareFirst acknowledged that a database was first accessed in June 2014, nearly one year ago. The recent breach of Premera Blue Cross, also a healthcare provider, lasted roughly 8 months.
Penn State University
Pennsylvania State University announced on May 15 that a breach compromised servers containing information on roughly 18,000 people. During the investigation that followed, an intrusion on their network was found dating back to 2012. While it is very difficult for universities to fully regulate all of their IP space, the fact that an intrusion may have lasted three years without remediation is troubling, especially given that they and many other universities have valuable intellectual property.