Skip to main content

Data Breach

A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information.

What is Data Breach?

A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information. It includes potential access by an unauthorized person and access by an authorized person for an unauthorized purpose. A breach is a type of security incident. Not every alert or system failure is a breach; an investigation must determine whether data was affected and define the scope.

Why it matters

A breach can expose data, harm people and operations, and show that one or more controls failed. Fast, evidence-based response can limit further access and support accurate recovery work.

How it works

  1. Prepare an incident-response capability with data inventories, logging, roles, contacts, backups, and tested procedures.
  2. Detect and analyze the event, preserve evidence, identify affected data and accounts, and determine the current scope.
  3. Contain the access, remove the cause, recover services, complete required communications, and use the findings to improve controls.

Example

A storage audit log shows that an unknown credential downloaded customer records from a misconfigured bucket. The team disables the credential, closes the public path, preserves the logs, identifies the downloaded objects, and starts its response plan.

Pomerium boundary

Pomerium authorization and access logs can provide identity, route, request, and policy-decision evidence for traffic that passed through Pomerium. This evidence can support an investigation. Pomerium cannot determine the full breach scope or protect data paths that bypass it.

Limits and non-claims

  • Missing, altered, or short-retention logs can prevent a complete scope determination.
  • A control can reduce the chance or impact of a breach without proving that no breach occurred.
  • Access-proxy evidence does not cover direct storage access, offline copies, or unrelated application paths.

Evaluation checklist

  • Which data crossed which confidentiality, integrity, or availability boundary without authorization?
  • What initial access, credential, lateral path, application action, and exfiltration path produced the event?
  • Which evidence supports containment, affected-scope analysis, credential response, and safe recovery?

Sources and further reading

Keep learning

Security Operations and Risk

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

Learn this term
Security Operations and Risk

Ransomware

Ransomware is malware used to deny access to data or systems and demand payment. Many operators also steal data and threaten disclosure.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo