What Is a Data Breach?

Related problems: Customer or employee data may have been exposed; Not sure what we would legally have to do after a breach; Sensitive files shared outside the company without control; Cyber insurer asking about our breach response plan

A data breach is an incident in which sensitive, protected or confidential information is accessed, copied, disclosed or stolen by someone who is not authorized to have it. It can result from an outside attack, a misconfigured system, a lost device or an insider misusing access. For a business, the technical cleanup is often only part of the cost; legal obligations, customer trust and insurance follow.

At a glance

  • A breach is defined by unauthorized access to or disclosure of data, not by how it happened.
  • Causes include stolen credentials, ransomware with data theft, misconfigured cloud storage, lost devices and insiders.
  • Notification duties depend on the data type, the people affected and their location, and rules vary by jurisdiction.
  • Response combines technical investigation, legal advice, communications and often insurer involvement.

What problem it solves

A data breach is an outcome to prevent and prepare for, not a product. For buyers it raises three practical problems. First, prevention: knowing where sensitive data lives, who can reach it and how it leaves the company. Second, detection: many breaches go unnoticed for weeks or months, and the longer an attacker has access, the more data is exposed. Third, response: once a breach is suspected, the company has to find out what was taken, stop it, meet notification obligations and manage customers, regulators and insurers, often all at once.

Mid-sized companies face the same legal duties as large ones with far fewer people to handle them. A breach that would be routine for a large enterprise’s in-house team can overwhelm a small IT department, which is why planning and outside help are arranged in advance.

How it works

Exposure. Data is exposed through an attack (stolen passwords, phishing, exploited vulnerabilities, ransomware groups that copy data before encrypting), through error (a public cloud storage bucket, a misdirected email, a lost laptop without encryption), or through misuse by someone with legitimate access.

Discovery. The breach is found by security monitoring, by an alert from a vendor or law enforcement, by an extortion demand, or sometimes by customers who notice fraud.

Response. An incident response (IR) process contains the threat, preserves evidence and works out what data was affected. Many companies call on an incident response retainer firm and outside legal counsel at this stage, often coordinated through the cyber insurer.

Notification and recovery. Counsel decides who must be notified and when, based on the data involved and the applicable laws, for example state breach laws in the US or sector rules such as HIPAA for health data. The company then fixes the root cause and may offer credit monitoring or other support to affected people.

Prevention tools. Data loss prevention (DLP) watches for sensitive data leaving through email, uploads or devices, and a cloud access security broker (CASB) brings similar visibility and control to cloud applications. Encryption, access reviews and multi-factor authentication reduce how much one mistake or one stolen password can expose.

When it matters for buyers

  • When you handle regulated data. Health, payment, financial and personal data each bring their own obligations.
  • When cyber insurance renews. Insurers ask about controls and about your incident response plan.
  • When a peer or vendor is breached. Check whether your data was involved and whether your own plan would hold up.
  • When moving data to the cloud. Misconfiguration is a common cause of exposure, and visibility tools may need to follow the data.
  • When customers ask. Security questionnaires increasingly ask how you would detect and report a breach.

We cover preparation and outside help in our incident response overview.

Questions to ask vendors

  • How would your product or service help us detect that data is leaving, and how quickly?
  • What evidence do you keep, and for how long, to show what data was accessed?
  • If we suffer a breach, what will you do in the first 24 hours, and what costs extra?
  • Do you work with our cyber insurer’s approved panel, or would we need to switch providers?
  • Where is our data stored and processed, and who at your company can access it?
  • How would you notify us if a breach on your side affected our data?

How it differs from a security incident

A security incident is any event that threatens the confidentiality, integrity or availability of systems or data: a malware infection, a phishing email someone clicked, a denial-of-service attack. A data breach is the subset of incidents in which protected data is actually accessed or disclosed without authorization. Many incidents never become breaches, and whether one legally counts as a reportable breach depends on the data and the jurisdiction. Treat every serious incident as a possible breach until the investigation shows otherwise.

Frequently Asked Questions

Do we have to report a data breach?
Often, but it depends on what data was involved, whose data it was and where those people live. In the US, every state has its own breach notification law, and sector rules such as HIPAA add their own requirements; other countries have their own regimes. Deadlines can be short, so involve legal counsel early.
Is every security incident a data breach?
No. A security incident is any event that threatens your systems or data, such as a malware infection or a blocked attack. It becomes a data breach when protected data is actually accessed or disclosed without authorization, and whether it legally counts as a notifiable breach is a question for counsel.
Can a data breach happen without hackers?
Yes. Misconfigured cloud storage, an email sent to the wrong recipient, a lost unencrypted laptop or an employee taking files to a new job can all expose data. Accidental exposure is a common cause, which is why access controls and data loss prevention matter alongside defenses against attackers.
What does a data breach cost?
Costs vary widely with the amount and type of data, the industry and how quickly it is contained. They typically include investigation, legal advice, notification, credit monitoring for affected people, regulatory penalties where applicable, lost business and higher insurance premiums.
Does cyber insurance cover data breaches?
Many cyber policies cover breach response costs such as forensics, legal counsel, notification and credit monitoring, and some cover liability claims. Coverage, sublimits and exclusions differ between policies, and insurers may require you to use their approved response firms.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.