Home  ›  Glossary  ›  Data Breach

What is a data breach?

A data breach is a security incident in which data is accessed, disclosed, altered, lost or destroyed without authorization. It covers deliberate attacks, misuse by insiders and accidental exposure, and the data involved can be personal information, financial records, intellectual property or operational data.

Destruction and alteration count as breaches too

The legal definition reaches well beyond theft. Under GDPR Article 4(12), a personal data breach includes accidental or unlawful destruction, loss or alteration of personal data as well as its disclosure. Ransomware that encrypts customer records is therefore a breach even if not a single file left the building, and whether the data can be restored becomes part of how the breach is assessed.

The backup repository sits on both sides of that definition. It is the means of reversing destruction, and it is also a store holding copies of most of the organization's data, often going back months or years, which makes it a place where a breach can happen.

Confidentiality, integrity and availability breaches

TypeWhat happens to the dataTypical causeCan a restore undo it
ConfidentialitySeen or copied by someone unauthorizedExfiltration, a publicly readable bucket, a misdirected email, an unencrypted laptopNo
IntegrityAltered without authorizationTampering through stolen credentials, or an insider exceeding their roleYes, from a copy taken before the change
AvailabilityLost, destroyed or locked awayRansomware, deletion, lost devices, a breached supplierYes, if an intact copy survived

Ransomware often produces two types at once, copying data out and then encrypting it, the pattern behind double extortion ransomware. Backups answer the integrity and availability halves of such an attack and have no answer to the confidentiality half. That split shows in the breach report: an organization able to show that encrypted records were back from an intact copy within hours is reporting a different incident from one that lost them outright.

Data breach prevention around the backup repository

Data breach prevention is the layered set of controls that makes unauthorized access less likely and limits what an intruder reaches: identity controls such as MFA and separate admin roles, network segmentation along zero trust lines, configuration that blocks public access to storage, encryption in transit and at rest, monitoring, and administrative and physical measures such as access reviews and documented destruction of retired drives.

Prevention programs often cover production databases and file shares and leave out the biggest data store of all. In many mid-sized environments the S3 key the backup software uses sits in a configuration file on the backup server with rights to every bucket, the repository can be reached from the network that user workstations sit on, and offsite copies go to disks or a provider with looser controls. Each of those turns the backup system into a shortcut to the whole organization's data.

Retention as both recovery and exposure

Data that is no longer held cannot be stolen. An organization keeping ten years of customer records that cuts back to three shrinks the exposed set by about 70%, assuming similar volume each year. Backup retention pulls the other way: every extra month of restore points adds recovery options and also preserves records that production deleted long ago, all of them readable by whoever reaches the repository.

ARTESCA and data breach

ARTESCA's security implementation guidelines close several repository gaps at the storage layer: Block Public Access enforced at account and bucket level, IPMI management traffic kept on a dedicated out-of-band network, and rotation and removal of access keys that are no longer used.

Those measures narrow the confidentiality side of a breach. They cannot recall data that has already left, and they govern only the storage: a key leaked from the backup server still reads whatever its policy permits.