Linda's idea

Linda has an idea... immediately crushed by Yumei.

Do not use the same password for multiple sites, because if discovered on one site, it could also be used on the others. Your personal data (including username and password) could be stolen through a Data Breach.

This is the story of a theft of confidential customer data from a well-known banking group.

What allowed the theft of confidential data from the banking group?

The vulnerabilities present in the application
The ability of hacker criminals
A powerful cyber attack

The severity of the data breach

A data breach is serious because:

  • It causes the leakage of a large number of personal and sensitive data, such as passwords, credit cards, images, chat conversations, sexual preferences (data breach of a dating site).
  • The subject to whom the data refers is often not notified.

What allowed the disclosure of confidential data of the hospital?

A SYSTEM ERROR
THE HUMAN ERROR
A CYBER ATTACK

Can you distinguish a Data Breach from a Data Leak?

Test yourself with the "Data Breach or Data Leak" game

PLAY

What sanction did the Privacy Guarantor issue against the banking group in the first case?

20.000€
100.000€
600.000€

Privacy by design

Consider security and privacy aspects already in the design phase of a new service or product.

Minimum security measures

Apply the minimum ICT security measures issued by the AgID and provided for in the GDPR.

Create written procedures

Define the procedures to be followed in the processing of personal and sensitive data to avoid accidental data loss caused by human error.

Verify Providers

The same level of security must be required of service provider companies.

Define emergency procedures

Provide roles and procedures to be activated in the event of a Data Breach in order to have rapid and effective reaction times.

Create an internal awareness

To train people on the subject of Data Breach and Data Leak to raise awareness on correct behavior, reducing the possibility of data leakage due to human error.