# Data Privacy vs COVID-19

_Last updated: 2024-03-11_

In March 2020, Virgin Media suffered a data breach affecting nearly one million customer details after a marketing database was left open for 10 months. The Chief Executive decided not to notify customers because "we all have enough on our plate with coronavirus." Simultaneously, COVID-19 forced millions into home-based work using personal equipment without corporate firewall protection, creating opportunities for online criminals to access data and scam people more easily.

## Cybersecurity Expert Perspectives

Two cybersecurity leaders shared insights on protecting data during the pandemic:

- **Andy Smith**, Chief Marketing Officer at Laminar Security (which secured a $32 million Series A investment), specializes in data security.
- **Shimrit Tzur David**, Chief Security Officer at Secret Double Octopus, leads passwordless, multi-factor authentication solutions.

## Top Threats to Businesses

Data breaches remain the foremost threat. Authentication vulnerabilities create the largest attack surface, enabling ransomware attacks that typically begin with compromised credentials. In the past year, 6 out of 10 companies suffered ransomware attacks, causing an average of 6 days of downtime per affected business.

## Critical Security Errors

Companies commonly lack visibility and monitoring of sensitive data stored in the cloud. Organizations often fail to recognize that security depends on the "weakest" user or use case—attackers need only one employee to choose a weak password or click a malicious link to access the internal network. Insufficient defense in depth and lack of zero trust models contribute to successful breaches.

Once inside a system via compromised credentials, attackers download ransomware quickly. Billions of leaked credentials circulate; hackers need to find only one valid account.

## Most Vulnerable Data Types

Pay card data, personally identifiable information (PII), and health records are actively sought by attackers. "Shadow data"—data unknown to security teams—is particularly vulnerable. Credentials represent the highest-value target because they provide the first entry point for attackers.

## Most Common Cybercrime Forms

Ransomware has overtaken phishing as the #1 attack vector. Other prevalent methods include phishing, dictionary attacks, password guessing, and social engineering—all aimed at obtaining credentials.

## Cybersecurity Workforce Gap

The global cybersecurity workforce must grow 65% to defend critical organizational assets. Automation with cloud-native security solutions can address this shortfall. Additionally, cybersecurity roles are no longer exclusive to IT backgrounds; employees from other disciplines can transition into cybersecurity with specialized training now readily available.

## Data Protection for Marketers

Marketers handling customer data should:

- Establish continuous monitoring solutions to discover, prioritize, and protect sensitive data in the cloud.
- Ensure both local data and third-party data are saved and managed securely, including access management, passwordless authentication, and data-in-motion security.
- Verify that third-party vendors meet your organization's security standards.
- Use password managers and enable two-factor authentication (2FA) wherever possible.

## Third-Party Vendor Risk

If external vendors manage email lists, CRM systems, or other data repositories, their security standards must match yours. Only 69% of the world's countries have formalized data protection legislation. With remote work expanding, organizations must monitor vendors and data processors closely.

## Employee Education and Access Controls

Security awareness campaigns should engage employees meaningfully rather than rely on generic corporate emails. Marketing and communications teams can translate technical security guidance into relatable, engaging formats.

Organizations should make 2FA mandatory for staff login to work platforms, particularly as remote access to corporate shared drives increases. However, global access permissions require ongoing attention. Cloud collaboration tools like Google Drive allow easy link-sharing and document copying, creating risk if an attacker gains employee credentials. Microsoft solutions offer stronger controls—IT teams can enforce global security standards around document downloads, external sharing, and other permissions to limit breach damage.

## Evolving Security Paradigm

Security practitioners must shift from viewing themselves as gatekeepers to acting as business gate-openers with proper guardrails. Remote work increases attack surface as employees access sensitive data via unsecured networks, personal devices, and without organizational security oversight.

Security is fundamentally about data, not the infrastructure hosting it. The industry is evolving from system-centric to data-centric security models. Securing an organization requires multiple steps and vendor partnerships; choose each vendor carefully to match your specific needs without compromising security or user experience.