data breach
Article

Data Breach: Causes, Costs and How to Respond Fast


Warning: Trying to access array offset on value of type bool in /var/www/new_portal/html/wp-content/themes/cyberx/single.php on line 61

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /var/www/new_portal/html/wp-includes/formatting.php on line 4558

Warning: Trying to access array offset on value of type bool in /var/www/new_portal/html/wp-content/themes/cyberx/single.php on line 61
Writer:
Huzaifa.Hamza

Most organisations plan for the wrong scenario. They imagine a sophisticated intruder defeating their firewall.

In reality, a data breach usually starts with something far more ordinary: a stolen password, a misconfigured storage bucket, or an employee who clicked a link on a Tuesday morning.

This guide covers what actually causes a data breach, what one costs in 2025 terms, the first 72 hours of response, and the notification duties that apply in Saudi Arabia and the EU.

What Counts as a Data Breach?

A data breach is any incident where information is accessed, disclosed, altered, or destroyed without authorisation.

That definition is broader than most people assume. It covers far more than a hacker exfiltrating a customer database.

Breach vs. Incident vs. Leak

Getting the vocabulary right matters, because your legal obligations attach to specific terms.

Security incident — any event that may affect confidentiality, integrity, or availability. Most incidents are not breaches.

Data breach — an incident where personal or sensitive data was actually exposed or compromised. This is what triggers notification duties.

Data leak — data exposed through error rather than attack, such as a public storage bucket. Still a data breach under most regulations.

The practical implication: a leak with no attacker involved can carry the same reporting obligation as a full intrusion.

What Actually Causes a Data Breach

Data breach causes cluster into a short list, and most of them are preventable with controls you already understand.

Phishing and Stolen Credentials

The single most common entry point. An employee enters credentials on a convincing fake page, and the attacker logs in through the front door.

No exploit, no malware, nothing for a perimeter tool to flag. Understanding how phishing works is the foundation of preventing this category.

The scale is documented. The FBI’s 2024 Internet Crime Report recorded USD 16.6 billion in total reported losses, with phishing among the most frequently reported crime types.

Misconfiguration and Exposed Storage

Cloud storage left public, a database without authentication, an internal dashboard reachable from the internet. These require no attacker skill at all — just a scanner.

Insider Error and Insider Misuse

Two very different problems with one label.

Error — a spreadsheet emailed to the wrong recipient, an attachment sent to a full distribution list, a laptop left in a taxi.

Misuse — a departing employee copying client records, or someone browsing files outside their role.

Third-Party and Supply-Chain Exposure

Your data sits with vendors, processors, and integration partners. A data breach at any of them is functionally a breach of yours, and your customers will hold you accountable for it.

Ransomware and Double Extortion

Modern ransomware steals data before encrypting it. Even if you restore cleanly from backups, the exfiltration has already occurred and the disclosure obligation stands. Our guide to ransomware explains the mechanics.

The Real Cost of a Data Breach

The financial picture for data breach response shifted meaningfully in the most recent data.

IBM 2025: A First Decline in Five Years

According to IBM’s Cost of a Data Breach Report for 2025:

The global average cost fell to USD 4.44 million, down about 9% from USD 4.88 million the year before.

This was the first global decline in five years.

In the United States, the average rose to USD 10.22 million, driven by regulatory penalties and slower detection.

Organisations identified and contained a breach in a mean of 241 days — the lowest figure in nine years.

Attackers used AI in 16% of breaches, primarily for phishing and deepfakes.

Why the Global Figure Fell

Faster containment, largely credited to AI-assisted detection. The correlation across the dataset is consistent: shorter dwell time means lower cost.

That is the actionable insight. You cannot guarantee prevention, but you can compress detection and response.

Beyond the Invoice

The reported average excludes much of what actually hurts:

Customer churn and the cost of replacing lost accounts.

Contract losses where security review becomes a procurement blocker.

Executive time diverted for months.

Cyber insurance premium increases at renewal.

Long-term brand damage that no line item captures.

The First 72 Hours: A Response Checklist

Data breach response is judged on speed, not elegance. Work in this order.

Hour 0–4: Contain and Preserve

Activate the incident response plan and name a single decision-maker.

Isolate affected systems without powering them down, so volatile evidence survives.

Revoke compromised credentials, sessions, and API tokens.

Preserve logs immediately, before retention windows rotate them out.

Hour 4–24: Scope and Assess

Determine what data was accessed, how much, and whose.

Identify the entry point and confirm it is closed.

Check for persistence: new accounts, scheduled tasks, forwarding rules.

Engage legal counsel and, if the scope is unclear, external forensics.

Hour 24–72: Notify and Communicate

Notify the supervisory authority within the statutory window.

Prepare communications for affected individuals, staff, and customers before the story reaches them elsewhere.

What Not to Do

Do not wipe or rebuild affected systems before evidence is captured.

Do not speculate publicly about scope before it is confirmed.

Do not delay notification while waiting for a complete picture. Regulators accept phased reporting.

Do not handle a significant data breach without legal involvement.

Notification Duties You Need to Know

Data breach notification clocks start when you become aware, not when you finish investigating.

Saudi Arabia — PDPL

Under the Personal Data Protection Law, overseen by SDAIA:

Controllers must notify the authority no later than 72 hours after becoming aware of the breach.

There is no materiality threshold — the obligation applies regardless of apparent size or impact.

The notification must describe the incident and how it occurred, the category and estimated number of affected individuals, an assessment of likely consequences, and the containment measures taken or planned.

Where the breach poses significant risk to individuals, affected data subjects must be informed promptly, with DPO contact details provided.

EU — GDPR

If you process data on EU residents, GDPR imposes a parallel 72-hour notification duty to the relevant supervisory authority, with notification to individuals where the risk to their rights and freedoms is high.

Practical Consequence

Many organisations discover their 72-hour clock has already expired while they were still deciding whether the incident qualified as a data breach at all. Build the decision tree before you need it, not during.

How to Cut Your Exposure Before It Happens

This prevention work measurably reduces both data breach likelihood and cost:

Enforce phishing-resistant MFA across all accounts, with no executive exemptions.

Minimise what you collect and retain. Data you do not hold cannot be breached.

Encrypt sensitive data at rest and in transit.

Segment networks so one compromise does not become total access.

Run continuous configuration reviews on cloud storage and databases.

Maintain isolated, tested backups that ransomware cannot reach.

Assess third parties and write breach notification duties into contracts.

Rehearse the response plan with a tabletop exercise at least annually.

Train staff continuously and measure whether reporting rates actually improve.

That last point deserves emphasis. Since credential theft through phishing remains the leading entry route, a workforce that reports suspicious messages quickly is a genuine detection layer. Practical habits in our cyber security tips guide cover the daily behaviours that close this gap.

Who Is Most at Risk

Every organisation holds data worth stealing, but exposure is not evenly distributed.

Sectors Attackers Prioritise

Healthcare — patient records carry high black-market value and cannot simply be reissued.

Financial services — direct monetisation and dense regulatory obligations.

Retail and e-commerce — large payment-card volumes and complex third-party stacks.

Government and education — broad citizen and student datasets across fragmented systems.

Organisational Traits That Raise Risk

Rapid cloud migration without a matching configuration review.

Growth through acquisition, leaving inherited systems nobody owns.

Heavy reliance on contractors with standing access.

No single accountable owner for a data breach response plan.

Conclusion

A data breach is rarely exotic. It is usually a known weakness that nobody closed in time.

Most breaches begin with stolen credentials, misconfiguration, or human error.

IBM put the 2025 global average at USD 4.44 million, and USD 10.22 million in the US.

Mean time to identify and contain sits at 241 days — the dominant cost driver.

Saudi PDPL and GDPR both impose a 72-hour notification clock from awareness.

Faster detection is the single most controllable variable you have.

Reduce Breach Risk at the Source

You cannot buy your way out of human error, but you can measure it and reduce it.

AwareX delivers continuous, role-based security awareness training with reporting that shows exactly how your workforce responds to real-world pretexts — and how that response improves over time. Book a demo to establish your baseline and shorten the gap between compromise and detection.

To discuss your requirements, contact CyberX or explore the full platform from our home page.

Frequently Asked Questions

What is the difference between a data breach and a cyber attack?

A cyber attack is an attempt to compromise systems. A data breach is the outcome where data is actually exposed. Many attacks fail and cause no breach; some breaches involve no attack at all, such as a misconfigured public database.

How long do I have to report a data breach in Saudi Arabia?

Under the PDPL, controllers must notify the competent authority within 72 hours of becoming aware, with no materiality threshold permitting self-assessment.

What is the average cost of a data breach?

IBM’s 2025 report put the global average at USD 4.44 million, down roughly 9% year on year, while the US average rose to USD 10.22 million.

How long does it take to detect a breach?

The 2025 mean was 241 days to identify and contain — the lowest in nine years, but still eight months of undetected access in the average case.

Should we pay a ransom to prevent data being published?

Payment offers no guarantee of deletion and may carry legal exposure depending on jurisdiction and sanctions. Involve legal counsel and law enforcement before any decision, and note that payment does not remove your notification obligation. For context on the threat model, see our overview of cybersecurity fundamentals.

Newsletter

Subscribe to our newsletter and never miss latest insights and security news.

Similar Articles

Languages: