Calling all forensics experts!
These questions have been on my mind for a while, and a recent data breach makes me want to get some answers from the experts.
On plenty of breaches I read the following lines:
“We have no reason to believe that this information was accessed by unauthorized individuals…”
“It cannot be determined with certainty that any data was pulled from a computer by infectious software…”
“there is no indication that any of the information has been misused…”
These lines seem to be from the first pages of the “Breach Notification for Dummies” because I have hardly read an announcement without one of these type of statements. My questions are how do they know that it has not been misused and if they know that is has not been misused, why can it not be determined if the data has been pulled from the computer? I kinda thought that this was the whole point of forensic investigation, finding out what the bad guy did once they were on the machine. Is it money, time, notification time (i.e cannot analyze the drive quick enough before notification is necessary), historical data (obviously every breached computer with PII does not lead to ID fraud) or a combination of everything?
Am I missing something here? I would love to hear what everyone thinks.
UPDATE 04/16/2009: Dave Hull tweeted a link the Security Breach Notification Symposium that should give some great insight to the topics discussed in this post. The audio/slides for the talks have recently been posted. Thanks everyone for the great comments!
Related posts: