Data Breaches : The Fallout
Summary
For example, the ICO gave British Airways the biggest ever fine (to date) under GDPR at £183 million for a data breach where the personal details of 500,000 customers were accessed by hackers. Carrying on with the example of Facebook’s Cambridge Analytica scandal, following a £500,000 ICO fine for data breaches, the social media giant was hit with a £266 billion lawsuit by the Australian Information Commissioner. This can amplify the effects of one data breach through one company as their personal details are sold and shared among other cybercriminals who may use credential stuffing to access other websites for the same user. The bigger potential problem was that Biostar 2 is part of the AEOS access control system, which is used by over 5,700 organizations in 83 countries, including big multinational businesses, SMEs, governments, banks, and even the UK Metropolitan Police. For example, a good approach to dealing with a data breach may be evaluating the situation, closing loopholes and removing the threat, then offering transparent and open communications e.g. notifying customers, notifying the ICO, issuing a public statement (on the website) and opening communication channels with customers (online chat, social media, telephone, and email).