
In the event of a cyberattack, both public institutions and private companies that process personal data are exposed to risks associated with data breaches, as well as to significant financial losses. Specialists from biznes.gov.pl, based on the ESET “Threat Report,” estimate that the average cost of such an attack exceeds one million zlotys. However, the total costs can be much higher, especially if there is a loss of data, loss of trust from business partners, and damage to market reputation. Therefore, it is essential for organizations to implement appropriate measures and mechanisms that enable a swift response to such situations.
Challenges for Businesses in Cybersecurity
According to the report “Cybersecurity – Challenges for Business,” prepared by the Employers of the Republic of Poland, in 2022 there were 322,479 reported cybersecurity incidents (including those that were ultimately not classified as incidents). At the same time, there was a noted increase in cybersecurity incidents of 182% comparing 2021 to 2020 and 178% comparing 2022 to 2021. Statistics for 2023 are not yet known, but further increases in trends should be anticipated.
The pandemic prompted many organizations to implement remote or hybrid work. The transition from an office environment to remote work, where many processes occur online, has increased vulnerability to cyberattacks. Traditional control methods have been replaced by new, often less tested pathways and tools for accessing IT systems. Another factor influencing (in)security in cyberspace was the escalation of the conflict in Ukraine. Along with traditional warfare, the risk of criminal activity in the digital space has increased (which is also related to heightened disinformation in social media). In response to the growing threats arising from the specific geopolitical situation in Poland and detected aggressive actions in cyberspace that bore signs of potential terrorism, the Prime Minister issued a regulation on January 18, 2022, introducing a nationwide alert level designated as ALFA-CRP. On February 21, 2022, due to the escalating actions against Ukraine, the Prime Minister introduced a third alert level in the field of cybersecurity, designated as CHARLIE-CRP, which remained in effect until the end of 2022.
It should be emphasized that no device can guarantee complete protection online. Security in cyberspace largely depends on our actions and awareness. Over 90% of attacks are based on user interaction, where the user is typically encouraged to open an attachment in an email or click on a link contained in a text message. Additionally, we increasingly share too much information and data that should be confidential, which facilitates cybercriminals in preparing and executing an attack.
In 2020, the Ministry of Digital Affairs published a guide titled “How to Protect Yourself Against Cyber Attacks? Practical Tips for Parliamentarians and Others.” It contains concepts related to cybersecurity, advice on how to reduce the risk associated with cyber attacks, and real examples of such attacks, such as phishing. The guide also presents methods for creating secure passwords and indicates how to maintain safety on social media, where cyber threats are becoming more common. However, three years have passed since the publication of this material, which in the era of rapid technological development may seem (too) long.
Guide from German Authorities “How to Defend Against Cyber Attacks?”
Recently, substantive support has been provided by German authorities, namely the Federal Office for Information Security (BSI) and the Data Protection and Freedom of Information Authority of North Rhine-Westphalia, which developed the guide “How to Defend Against Cyber Attacks?” This guide serves as a source of valuable information and advice on what actions to take in the event of a cyber attack, how to minimize potential damage, and how to protect personal data processed within the organization. The German guide outlines a six-step process for responding to cyber attacks.
-
Mitigating the Effects of a Cyber Attack
The first step is to identify the infected systems and disconnect the device from the internet and internal network. This action aims to secure the data from further access by third parties and to prevent the spread of malware. Next, the infected systems and all connected devices are thoroughly analyzed. Remaining systems on the same network that do not show signs of external malicious activity should be continuously monitored. The goal is to immediately detect potential backdoor viruses that may have been created but have not yet been located. This refers to elements of malware that may have bypassed security measures. At this stage, it is advisable to consider seeking support from external specialists in the field of cybersecurity. They possess the necessary experience in combating malware and can assist in more advanced investigations and effectively cleaning infected systems.
-
Conducting a Cyber Investigation
In the event of a cyberattack, it is advisable to seek external support, such as that offered by experts in digital forensics and post-breach analysis. If the cyberattack has affected data processors acting on behalf of the data controller, a significant portion of the investigation process will rest with these entities. An audit of the data controller's systems will also be useful to ensure that the attack does not impact these systems.
During the cyber investigation, it is necessary to analyze the timeline of the attack, the cause or path of the attack, as well as its scope, including duration, affected systems, and data. Furthermore, in fulfilling the obligations imposed by Article 32 of the GDPR, it is essential to investigate whether personal data was exposed to risk during the attack. In this regard, it is worth considering the following issues:
- Was there a data breach, such as destruction, loss, alteration, unauthorized disclosure, or access? Were the data encrypted or deleted? Were the data used illegally (e.g., for sending harmful emails)?
- Are there possible other types of data protection breaches (e.g., were the data copied and then transferred or published, or were they modified)? For what period did unauthorized individuals have access to the systems? To what extent were the data copied (e.g., in software used by the attackers or in operating system logs)? Is it possible to identify the location of the publication of this data?
- What categories of individuals were affected by the attack?
- How many individuals were affected by the breach and how many records might this involve?
A preliminary assessment of the risk of infringement of the rights and freedoms of natural persons should be conducted within 72 hours of the disclosure of an attack. Data processors are obliged to inform data controllers without undue delay – regardless of the risk – and to assist them in fulfilling their legal obligations (in accordance with art. 28(3)(f) and art. 33(2) GDPR).
-
Assessment of the impact of a cyberattack on the individuals whose data is affected
Based on the conducted cyber investigation, the data controller is required to determine the risk of infringement of the rights and freedoms of natural persons. They should perform an analysis to establish whether there has been an infringement of the rights and freedoms of the individuals whose data is affected, taking into account the nature, scope, context, and purposes of the processing. According to Recital 76 of the GDPR, it can be indicated that when assessing the risk of infringement of the rights and freedoms of natural persons, the severity of the event resulting from the infringement should be considered, namely the extent of the damage that the event may cause to the individual whose data is affected, as well as the likelihood of its occurrence. The consequences of an infringement may include: identity theft, discrimination, financial losses, loss of reputation, breach of professional secrecy, unauthorized reversal of pseudonymization.
If the attackers have the ability to view or copy data, the individuals whose data is affected will lose control over it. If it is not possible to directly assess the severity of the infringement, the analysis may be based on potential subsequent damages resulting from the loss of control (such damage includes, for example, identity theft).
In assessing the severity of the infringement, the following questions may be useful:
- To what extent have personal data been attacked (number of records or category)?
- Are these ordinary data or special category data, e.g., medical data, information about treatment, test results, etc.?
- Is there a possibility of unauthorized identification of specific individuals or taking specific actions against them?
-
Do the disclosed data allow for more detailed identification of individuals, e.g., regarding wealth or social status?
When was the last time
you conducted a risk analysis?Risk and DPIA are fundamental elements in building a data protection system.ORDER A QUOTE - Can other conclusions regarding individuals, such as individual treatment, chronic diseases, or allergies, be drawn from the disclosed data?
- Are the data non-critical, and does their disclosure not entail serious consequences?
- For what (unauthorized) purposes may the data be processed?
- Are there backup copies from which lost or damaged data can be recovered and which can be used to verify the data and make changes to it?
- Are there ways to recover lost data from other sources, e.g., directly from the individuals to whom the data pertains?
- Does the data controller have means to mitigate the effects of data loss or alteration, e.g., through compensation?
- Can an attack lead to negative social or economic consequences, such as loss of reputation, discrimination, or financial losses?
After thoroughly analyzing the situation, the next step is to assess the likelihood of a breach occurring. In this process, various factors should be considered, such as: the source of the attack (e.g., actions of ethical hackers (i.e., cybersecurity experts specializing in penetration testing, securing IT systems, and applying various methodologies to ensure cybersecurity), targeted attacks on specific individuals, systematic exploitation of vulnerabilities, or the dissemination of malicious emails with demands from attackers, the possibility of obtaining financial benefits from the disclosed data, and the risk to individuals associated with the disclosure of their identities.
The provisions of the GDPR impose an obligation on the data controller to report incidents of personal data breaches to the supervisory authority that may lead to potential violations of the rights and freedoms of individuals. However, these provisions do not provide guidelines for a specific assessment of the existence of risk. The same applies when there is a need to notify the individuals whose data has been breached – the GDPR refers to "high risk" of violation of rights and freedoms as a basis for taking appropriate actions, but leaves the assessment of this risk to the data controller.
-
Minimizing the effects of a cyberattack
After identifying the risk, data controllers and data processors must consider what actions to take to mitigate the potential consequences of a cyberattack. These primarily include activities aimed at restoring lost or compromised data, regularly monitoring data to detect unauthorized changes, and restoring the normal functioning of services that may have been disrupted by the attack.
Organizations should ensure that it is possible to detect improper use of data or potential attacks at an early stage in the future. It is essential to monitor the actions of attackers, such as attempts to further contact the victims or publish their data.
Interestingly, German supervisory authorities recommend informing individuals whose data has been affected by a cyberattack, even if there is no such obligation under the provisions of the GDPR. This is argued on the basis that individuals have the opportunity to prepare for the consequences of the attack, for example, by remaining more vigilant in the event of potential fraud attempts. In contrast, Polish doctrine indicates that only if a personal data breach may result in a high risk of infringing the rights or freedoms of natural persons, the data controller is obliged to notify the individuals concerned without undue delay.
The scope of the notification should include, among other things, a description of the nature of the incident, contact details for the Data Protection Officer (DPO), an indication of the possible consequences of the incident, and information regarding the measures taken, including those aimed at minimizing any potential effects of the breach. Communication should be conducted in a direct manner, e.g., via email, letter, or phone, unless this would require disproportionate effort. In such cases, it is permissible to use a public means of communication, such as press, television, or online media.
-
Adjusting the security level of systems to current risks
To ensure that malware no longer poses a threat, it is necessary to restore or reset the system to a secure state and then strengthen its protection. Furthermore, the security level of systems must be adjusted to potential future threats and subjected to regular testing, assessment, and evaluation of the systems ensuring data processing security. Improving the level of protection of systems can be achieved through:
- rapid identification and remediation of critical security vulnerabilities using information and alerts from product manufacturers or service providers,
- abandoning open and unsecured interfaces,
- encrypting transmitted data,
- monitoring data traffic through firewalls at network gateways,
- separating systems and applications processing data for different purposes, e.g., through segmentation and network isolation,
- restricting access to data according to the need-to-know principle based on roles and permissions, particularly through restrictive allocation of administrative privileges,
- monitoring the data processing process through logging,
- regular checks to detect malware,
- having the capability to detect system overloads, such as DDoS attacks, and to counteract such overloads,
- utilizing secure authentication procedures, including multi-factor authentication, and applying password guidelines,
- effectively responding to cyberattacks and other IT security incidents, including crisis management,
- separating data backup copies from production systems,
- verifying the ability to restore data backup copies,
- cyclical training and raising employee awareness regarding personal data protection and IT security,
- regularly testing the effectiveness of actions, including conducting penetration tests.
Adjusting the level of protection of systems to current threats is a key element in ensuring the security of data processing within organizations.
-
Register of Cyberattacks
Repelling a cyberattack requires the data controller to create internal documentation and present it to the supervisory authority responsible for data protection. This documentation must include at least:
- the data controller's information and contact details for providing further information,
- information about other entities involved in the incident (if applicable),
- a brief description of the incident,
- a chronological description of events and actions taken (including traditional and electronic correspondence, notes from phone calls, etc.),
- justification for any delay in reporting or notifying the authority about the breach (if applicable),
- an assessment of the severity of the breach,
- indication of the categories of individuals whose data are affected and an approximate number of those individuals,
- indication of the categories of data,
- a description of the likely consequences of the incident, including an assessment of the risk to the rights and freedoms of natural persons,
- description of the measures taken or proposed (including notification of the data subjects),
- in the case of anticipated high risk – a template for information for the data subjects whose data has been breached, along with a description of the notification or justification as to why notifying these individuals was not possible or necessary,
- reporting the breach to the data controller in accordance with Article 33(2) of the GDPR, specifying the time of the report,
- description of the measures taken or proposed to prevent the recurrence of the incident, along with assurance of maintaining an appropriate level of data protection in the future.
Summary
It is worth noting that in the face of the dynamically evolving cyberspace and changing threats, European authorities are actively striving to respond to the need for effective protection of personal data processed by various organizations. An essential aspect of this process is adjusting the level of protection of systems to current risks, systematically monitoring security measures, and continuously assessing their effectiveness. Furthermore, the importance of regular employee training is continually emphasized to enhance their awareness and skills in cybersecurity. At the same time, it should be highlighted that responding to a cyberattack is a process that requires ongoing improvement and adaptation to changing realities. All these actions aim to reduce the potential impacts of cyberattacks and ensure the security of personal data within organizations.


