How often do breaches go unreported

I recently read a statistic that indicated almost 60% of cyber incidents go unreported, which is staggering. As someone focused on incident response, I can’t stress enough how vital it’s to document every incident thoroughly. It helps not just in resolution but in understanding vulnerabilities for future prevention. What’s your experience with overlooked incidents?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​⁠​⁠​‍​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠​‌‍⁠⁠​⁠‌‌‌​​‌‌⁠​‌‌⁠‌​​⁠​⁠‌⁠‍‍‌⁠‍‍‌‌‌‌​⁠‌‍‌​‌‌‌‌​‌​⁠​‌​⁠‌‌​⁠​‌​‍​‍‌⁠⁠‌​

It’s wild how many breaches slip through the cracks — it’s like finding out your favorite restaurant has a secret menu you never knew about! I think regularly scheduled reviews can help catch these missed incidents before they spiral. Have you noticed any patterns in the types of incidents that tend to be overlooked?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​⁠​⁠​⁠​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠⁠‌​⁠​‌‍⁠​‌​​‍‌‍‍​‌⁠​​‌​‍​‌‍⁠‌‌​‌​​⁠‍‌​⁠‌‌‌‌‌⁠‌​​‍‌‍‍‍‌⁠‍‍‌⁠‍‍​‍​‍‌⁠⁠‌​

Documenting incidents is crucial, but I’ve found that conducting post-incident reviews can really help tighten up your security measures. It’s one thing to log issues, but reflecting on them with your team can uncover patterns you might’ve missed. Have you ever had a review lead to a significant change in your processes?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌​​⁠​​​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‌​‍‌‌​​​⁠​‍‌‍‍​‌​‌‌‌‌‌‍‌⁠​​‌⁠​⁠‌​​‍‌‍‍​‌⁠‍​‌⁠​​‌​‌‌‌⁠‍‍‌‌‌⁠​‍​‍‌⁠⁠‌​

You make a great point about documentation. I’ve seen firsthand how using tools like SIEM can help automate the logging process, making it easier to capture overlooked incidents. Having a clear timeline can reveal patterns that are otherwise missed.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌​​⁠​​​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍​‌‍‍​‌​​‍‌‍​‍​⁠​‌‌‌​‌‌‌​​‌​​⁠‌‍⁠‍‌‍‌‍‌‍‍‌‌​​‌‌‍‌‌‌‍‌⁠‌‍‌​​⁠‍‌​‍​‍‌⁠⁠‌​