The short answer
Large breaches make headlines because of their scale, but the causes are usually ordinary: databases left open to the internet, reused or stolen passwords without multi-factor authentication, unpatched systems, over-privileged accounts, weak oversight of suppliers and slow detection. The lessons apply to organizations of every size. Four stand out.
- Data you do not keep cannot be stolen.
- Exposed systems and weak identities are the usual way in.
- Detection speed decides how bad it gets.
- Your response, including legal reporting, is part of your security.
This article discusses patterns seen across many public breaches rather than any single incident, and does not repeat figures that cannot be verified.
Why this matters in the US
CISA and the FBI publish ongoing #StopRansomware advisories because ransomware keeps hitting organizations of every size, from hospitals and school districts to manufacturers and local governments. Ransomware actors are opportunistic: they go after whatever is exposed and unpatched. Modern ransomware groups typically steal data before encrypting it, so a ransomware incident is often also a data breach.
Lesson 1: data you do not keep cannot be stolen
Many of the largest breaches exposed records the organization no longer needed: former customers, old applicants, duplicate exports, test copies of production databases. Large, centralized datasets are attractive targets, and every copy is another place to protect.
What to do:
- Keep an inventory of where personal and sensitive information lives, including spreadsheets, file shares, backups and SaaS applications.
- Set retention periods and delete data when they expire, subject to legal retention requirements.
- Never use real personal information in test or development environments without masking it.
- Encrypt sensitive data at rest and in transit.
Lesson 2: exposed systems and weak identities are the usual way in
Common entry points include cloud storage or databases configured for public access, remote access portals without multi-factor authentication, unpatched internet-facing software and credentials harvested by phishing or reused from earlier breaches.
Widely used frameworks such as the NIST Cybersecurity Framework 2.0 and the CIS Controls cover most of these directly: regular patching, secure configuration, strong authentication, perimeter defenses, secure cloud use and least-privilege access control. The FTC's data security guidance makes similar points for businesses of all sizes.
What to do:
- Turn on multi-factor authentication everywhere, starting with email, remote access, cloud consoles and administrator accounts.
- Patch internet-facing systems first and fastest, and retire software that no longer receives security updates. CISA's Known Exploited Vulnerabilities catalog is a useful priority list.
- Review cloud storage and database permissions regularly; public access should be deliberate and rare.
- Give each person only the access their role needs, and use separate accounts for administration.
- Include suppliers: require security commitments in contracts and remove vendor access when it is no longer needed.
Lesson 3: detection speed decides how bad it gets
In many large breaches, attackers were inside for weeks or months before anyone noticed. The longer they stay, the more data they find and copy.
What to do:
- Deploy endpoint detection and response (EDR) on computers and servers, with someone monitoring the alerts. See EDR vs antivirus.
- Centralize logs from key systems (identity, email, firewalls, cloud) and keep them long enough to investigate.
- Alert on unusual activity such as mass downloads, new administrator accounts or logins from unexpected locations.
- CISA's #StopRansomware guidance lists logging and alerting, network segmentation, least privilege and offline, tested backups among its core preventive measures.
Lesson 4: your response is part of your security
The organizations that suffer most after a breach are often those that respond slowly, communicate poorly or do not meet their legal obligations.
There is no single federal breach notification law for most businesses. Every state has its own, with different triggers and timelines. Health data brings the HIPAA Breach Notification Rule (HHS), which requires notice to affected individuals without unreasonable delay and no later than 60 days, with additional reporting to HHS and, for larger breaches, the media. Non-bank financial institutions may face FTC Safeguards Rule notice duties, and public companies must consider SEC Form 8-K Item 1.05. Texas, for example, expects individuals to be notified within 60 days and the Attorney General within 30 days when 250 or more Texans are affected. Whatever applies to you, keep a record of every incident and the decisions made, whether or not notice turned out to be required. This is general information, not legal advice. For the details, read responding to a data breach in the US.
What to do:
- Write a short incident response plan: who decides, who investigates, who communicates, who contacts legal counsel and insurers.
- Keep contact details for your IT provider, legal counsel and cyber insurer somewhere that does not depend on your own systems.
- Practice with a tabletop exercise at least once a year.
- Make sure backups are offline or immutable and that restores have been tested. See backup vs recovery plan.
Breach-readiness checklist
- We know where our sensitive and personal data is stored.
- We delete data we no longer need, on a schedule.
- Multi-factor authentication is on for email, remote access, cloud and admin accounts.
- Internet-facing systems are patched promptly and unsupported software is retired.
- Cloud storage and database permissions have been reviewed this quarter.
- EDR is deployed and alerts are monitored.
- Key logs are collected and retained.
- Supplier access is documented and reviewed.
- We have a tested incident response plan and breach record log.
- Backups include an offline or immutable copy, and restores are tested.
Limitations
No set of controls prevents every breach. The aim is to make attacks harder, detect them sooner and limit what can be taken. Priorities depend on your data, systems and risk tolerance, which is why a risk assessment is a sensible first step.
Next step
Our cybersecurity services help organizations put these controls in place and monitor them, with 24/7 monitoring and support for managed-service clients. If you are unsure where you stand, start with a security assessment.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- #StopRansomware, Cybersecurity and Infrastructure Security Agency (CISA)
- NIST Cybersecurity Framework 2.0, National Institute of Standards and Technology (NIST)
- Data security guidance for businesses, Federal Trade Commission
- Breach Notification Rule, U.S. Department of Health and Human Services
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.