Blog

Insights from IBM's Cost of Data Breach Report 2025: Breach Lifecycle Summary (Part 3 of 4)

Data breaches have a 'lifecycle' similar to living creatures. Understanding the factors that extend or shorten this lifecycle is crucial for effective defense. Learn about phishing, supply chain attacks, and how to strengthen your cybersecurity posture.

Understanding the birth, life, and death of a data breach

This is the third article in a series based on IBM’s recently released “Cost of Data Breach Report.” The first post provided an overview of IBM’s assessment and the second reviewed how to reduce the time of the breach lifecycle. This article will dig a little deeper into what the breach lifecycle even means and some of the factors that make it longer or shorter.

The Data Breach Lifecycle Explained

The idea of a data breach “lifecycle” may seem strange to some. A data breach is not “alive” in the traditional sense, so someone reading IBM’s Cost of a Data Breach Report may be confused. However, a data breach truly has a “birth”, “active phase”, and “death”, just like living creatures. The data breach is “born” when an attacker identifies a target and “dies” when that target fully secures itself and then regains the trust of its customers once more. This is generally a lengthy process, and IBM has identified factors that extend or limit the timeframe during which the organization is impacted (e.g., losing money).

The Barbed Fishhook Analogy

A data breach attack can be compared to a barbed fishhook. A barbed fishhook at its most basic is designed to have one hook going in and several coming out, making it easy to penetrate and hard to remove. Similarly, an attacker tries to get in through one angle and then spreads out to be as hard to remove as possible. This is an apt analogy because Phishing attacks became this year’s most likely angle of penetration. And, in true fishhook fashion, a data breach across multiple environments took the longest to resolve.

Supply Chain Attacks: The Silent Threat

While phishing might be the most popular method for hackers to get into a system this year, it is not the one that gives them the longest-lasting penetration. That award goes to supply chain attacks. A supply chain attack is one in which the intruder got into the victim’s system by compromising some other company’s systems on which the victim relies. Supply chain attacks are considered a “trust-based attack,” because most organizations tend to trust their vendors and not look too closely and thus not protect themselves from their vendors’ software and systems. These attacks also tend to be deep in an organization’s infrastructure increasing the difficulty of getting the attacker out. Incidentally, supply chain attacks were also the most common cause of AI security incidents.

The Vendor Challenge

One reason why it may not be quick or easy to remove an attacker from the supply chain is it may require assistance (and competence) from the vendor. The vendor may not always be forthcoming and helpful because anything they share with you may be used against them in court in the event of a lawsuit. Accordingly, for these kinds of deep issues, the IBM report correctly encourages organizations to build “lifecycle” thinking into their defenses. One of their examples is the proper management (including revoking) of credentials. Another is the use of AI at all levels of the cybersecurity lifecycle: prevention, detection, investigation and response.

Taking Action

If your organization is trying to figure out how to strengthen your cybersecurity lifecycle to reduce your breach lifecycle, call Crimson Vista. We can help you with strategy and planning in order to achieve the best cybersecurity posture possible within the goals and parameters of your operating environment. Get expert guidance. It’s worth it. You can contact us at: hello@crimsonvista.com.

Continue

Keep reading.