Last week it happened again. News of the Quora Security Breach was officially announced late Monday afternoon in a company blog post and email directly notifying 100 million affected users. This kind of shocking news is no longer shocking, and everyone in the industry needs to prepare for the day it will happen to them. Instead of shaking fingers at Quora for falling victim, I’d like to point out a lot of things that Quora apparently did very well.
In my experience as a SOC manager in an elite military technology unit and a security consultant for leading financial and commercial enterprises, I have seen time and again that too much emphasis is placed on preventing breaches. Of course, prevention will always be a top priority in information security, but it can become a dangerous illusion to think that a perfectly secured perimeter will keep your organization safe. Every organization I have worked with was constantly under attack and fielding hundreds, even, thousands of security alerts per day. The harsh reality is, no matter how good your security is, eventually a hacker will manage to break through. The real question is, how will your organization react?
From a SOC manager point of view, the Quora security breach seems to have been handled extremely well and the response times were much faster than other recent mega-breaches. According to Quora, the breach was discovered November 30 and users were notified and logged out just 4 days later, on the afternoon of December 3. In contrast, last year’s Equifax breach, that involved months of illegitimate access to sensitive credit data of 143 million people, took the company 6 weeks to disclose. The now infamous Yahoo! data breach of August of 2013, that affected all 3 billion user accounts, was disclosed 3 years later. The failures to secure accounts and notify users of breach led the company to pay out a $50 million settlement package to users and a $350 million drop in final price paid for the company by Verizon Communications.
Users show their appreciation of fast notification of Quora Security Breach on Twitter
So instead of the usual victim blaming, I think Quora needs to be applauded for their fast and comprehensive response. Though neither Cyberbit nor I have ever worked directly with Quora, I can make a few suppositions about what Quora did to prepare itself for the inevitable breach that allowed it to respond so well.
There is nothing ‘perfect’ about getting hit with a cyber breach, but with planning and practice you can be prepared to respond ‘perfectly’. The recent Quora security breach sets the bar for a new standard of fast, effective response to data breaches. Every organization needs a thorough incident response plan. Make risk assessment, penetration testing, and realistic training a regular part of ongoing operations. Running full-scale simulations of a variety of attack scenarios will allow your team to practice and perfect operating each specific type of attack. In addition, attack simulations give you a chance to test out playbooks and identify vulnerabilities in your architecture or inefficiencies in your response plan so they can be addressed promptly before a hacker exploits them. We all dream of building an impenetrable network, but until that dream comes true, be ready to be breached.
Yarden Altmann is a Cyber System Analyst at Cyberbit
Learn How to Prevent the Next Cyberattack with Next-Gen Technology