3 ms·
>how is it that a company cannot detect when someone downloads a giant database of sensitive personal information from their servers? Surely, there are ways to
by drone 13y ago
>how is it that a company cannot detect when someone downloads a giant database of sensitive personal information from their servers? Surely, there are ways to monitor access to this data and immediately flag suspicious behaviour
There are classes of products related to this specific task, generally we call them "DLP" or Data [Leak|Loss] Prevention.
What we don't know, is how the information was transferred from the servers, and how much different that traffic looked compared to normal activity. It's easy enough to catch a credit card number flying through a plain HTTP packet over the network in the wrong direction, but it gets much harder when the party trying to transfer that data is intentionally attempting to avoid detection.
> Isn't there some best practice security measures that can prevent of all of these things
Yes, but none of them are perfect, and even if they were, they would require perfection from human operators. (Perfectly configure, maintain, monitor, etc.) And, of course, they assume you can identify a threat before it leads to compromise.