Before the Breach: The Controls That Determine How Bad It Gets
Apogee Global RMS · January 10, 2024
The question most organizations ask after a data breach is what they should have done differently. The more useful question to ask before one is what separates organizations that contain incidents quickly from those that do not.
That distinction is not primarily a function of how sophisticated the attack was or how large the organization's security budget was. It is a function of whether specific governance decisions were made and control investments were in place before the incident began. The controls that determine how bad a breach gets are largely in place or absent before the first alert fires.
The Governance Decisions That Precede the Incident
Organizations that manage breaches effectively have made explicit governance decisions before any incident occurs. These decisions are not complex, but they require deliberate action rather than passive intent.
Data is classified. Leadership has defined what categories of information exist in the environment, where it is stored, who has access to it, and what level of protection each category requires. Without that foundation, breach response degenerates into discovery: attempting to determine what was accessed, where it was stored, and who is affected while the incident is still active.
Access is governed. Accounts are provisioned and deprovisioned through a defined process. Privileged access is reviewed on a regular schedule. Multi-factor authentication is enforced on systems that hold sensitive data and on remote access paths. When an incident occurs, the organization can immediately answer questions about what access existed and whether it was authorized.
Third-party relationships are inventoried and assessed. Vendors and service providers with access to systems or data have been evaluated for their security posture. Contractual provisions define notification obligations and security requirements. The organization knows who its third parties are and what they can reach.
The Detection Controls That Reduce Dwell Time
Dwell time, the period between initial compromise and detection, is one of the strongest predictors of breach severity. An incident detected within hours produces materially different outcomes than one that persists for weeks or months.
Reducing dwell time requires visibility into the environment: monitoring of network traffic and user behavior capable of identifying anomalies that warrant investigation, and a defined process for reviewing and acting on what the monitoring produces. Alerts without a review process produce no reduction in dwell time. The monitoring investment is only as effective as the response process attached to it.
Endpoint detection across managed devices, log aggregation from critical systems, and alerting on authentication anomalies and unusual data access patterns represent the baseline visibility that makes early detection possible. Organizations without any of these capabilities are relying on external notification, which typically means the incident has already progressed significantly before they are aware of it.
The Response Readiness That Contains Damage
The decisions made in the first hours of a detected incident determine whether the event is contained or whether it expands. Those decisions are made better when the response playbook has been developed and tested in advance.
An incident response plan defines who is notified, in what sequence, and what decisions each person is authorized to make. It identifies the external relationships that need to be activated: legal counsel, forensic investigators, notification specialists, and regulatory contacts. It addresses the communications questions that will arise before the response team has complete information. And it has been reviewed by the people who will execute it, so that the first time anyone follows it is not during an active incident.
Organizations without a tested incident response plan discover their gaps under the worst possible conditions. The cost of that discovery, measured in extended downtime, expanded regulatory exposure, and reputational consequences, consistently exceeds the cost of developing the plan in advance.
Schedule a Risk Briefing
Apogee Global RMS assists leadership teams in assessing pre-incident control posture, identifying governance gaps, and building incident response readiness appropriate to the organization's risk profile. To discuss where your organization stands on the controls that determine breach outcomes, schedule a consultation with our team.
Ready to take a unified view of enterprise risk?
Schedule a conversation with M.K. Palmore to explore how Apogee Global RMS can serve your organization.
Schedule a Consultation