What is Data Breach?
A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information. It includes potential access by an unauthorized person and access by an authorized person for an unauthorized purpose. A breach is a type of security incident. Not every alert or system failure is a breach; an investigation must determine whether data was affected and define the scope.
Why it matters
A breach can expose data, harm people and operations, and show that one or more controls failed. Fast, evidence-based response can limit further access and support accurate recovery work.
How it works
- Prepare an incident-response capability with data inventories, logging, roles, contacts, backups, and tested procedures.
- Detect and analyze the event, preserve evidence, identify affected data and accounts, and determine the current scope.
- Contain the access, remove the cause, recover services, complete required communications, and use the findings to improve controls.
Example
A storage audit log shows that an unknown credential downloaded customer records from a misconfigured bucket. The team disables the credential, closes the public path, preserves the logs, identifies the downloaded objects, and starts its response plan.
Pomerium boundary
Pomerium authorization and access logs can provide identity, route, request, and policy-decision evidence for traffic that passed through Pomerium. This evidence can support an investigation. Pomerium cannot determine the full breach scope or protect data paths that bypass it.
Limits and non-claims
- Missing, altered, or short-retention logs can prevent a complete scope determination.
- A control can reduce the chance or impact of a breach without proving that no breach occurred.
- Access-proxy evidence does not cover direct storage access, offline copies, or unrelated application paths.
Evaluation checklist
- Which data crossed which confidentiality, integrity, or availability boundary without authorization?
- What initial access, credential, lateral path, application action, and exfiltration path produced the event?
- Which evidence supports containment, affected-scope analysis, credential response, and safe recovery?
