Commentary on OAIC Finding on Uber’s Data Breach

By   ISBuzz Team
Writer , Information Security Buzz | Jul 23, 2021 05:28 am PST

Australian Information Commissioner and Privacy Commissioner has determined that Uber interfered with the privacy of an estimated 1.2 million Australians. Uber provided details of the data breach back in 2017, stating that two individuals outside the company had inappropriately accessed user data stored on a third-party cloud-based service that Uber used.

Notify of
1 Expert Comment
Oldest Most Voted
Inline Feedbacks
View all comments
George Lee
George Lee , Regional Vice President for Asia Pacific and Japan
July 23, 2021 1:39 pm

<p>The privacy commissioner’s findings around the Uber data breach highlights the need for an effective data security strategy. It should act as a warning for organisations in Australia and indeed Asia, to review their current data security strategy in line with the various data privacy acts in place across the region. <u></u><u></u></p>
<p>Data security should never be an afterthought – but sadly it often is, particularly when organisations prioritise speed over security. With the rush to modernise and migrate to the cloud, organisations often treat data security as a secondary consideration – seeing the risk of falling behind as greater than the risk of potential data loss. But data is the lifeblood of the modern business, and any effective cybersecurity strategy needs to start with securing it.<u></u><u></u></p>
<p>An effective data security strategy means auditing data to understand exactly where it is stored and the level of risk it presents to the organisation – including dormant databases inside the corporate network, and new databases in the cloud. <u></u><u></u></p>
<p>Next, the organisation should only keep what’s necessary: data that has limited or no value as an asset, but high liability, should be deleted. Access to any remaining data should be strictly controlled: database administrators, software developers or marketing specialists don’t need access to the same data, and widening access increases the risk of leakage. <u></u><u></u></p>
<p>Finally, data needs to be monitored in a way that the organisation can identify and prevent data leaks, whether deliberate or accidental. These are the bare bones of an effective data security strategy, but they’re essential for effective cyber protection.<u></u><u></u></p>
<p>Too often, organisations migrate data to the cloud and assume data security is the responsibility of the cloud provider. Unfortunately, that’s not true. Organisations mistakenly believe their cloud providers have visibility and oversight into how sensitive data is being protected. By 2025, it’s believed that at least 95% of cloud security failures will be the fault of the company using the cloud service.<u></u><u></u></p>
<p>In a shared responsibility model, security teams must take ownership of legacy data security concerns, and must also account for potential vulnerabilities in new cloud environments. Further, there’s the added challenge of understanding where the data lives. Most security teams are doing little more than managing the collection of raw data, but that doesn’t fulfill compliance requirements.<u></u><u></u></p>
<p>This lack of focus on data security is likely to come home to roost in the year ahead, when data starts to show up across the dark web and customers are impacted.</p>

Last edited 2 years ago by George Lee

Recent Posts

Would love your thoughts, please comment.x