{"id":5250,"date":"2024-01-22T13:43:41","date_gmt":"2024-01-22T17:43:41","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=5250"},"modified":"2024-01-22T13:50:15","modified_gmt":"2024-01-22T17:50:15","slug":"calculating-the-damage-of-a-data-breach","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/","title":{"rendered":"Calculating the Damage of a Data Breach"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5251\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg\" alt=\"Data Breach\" width=\"786\" height=\"393\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg 786w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach-300x150.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach-768x384.jpg 768w\" sizes=\"(max-width: 786px) 100vw, 786px\" \/><\/p>\n<p><strong><em>Solutions Review\u2019s\u00a0<a class=\"fui-Link ___1idfs5o f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh ftqa4ok f2hkw1w fhgqx19 f1olyrje f1p93eir f1h8hb77 f1x7u7e9 f10aw75t fsle3fq f17ae5zn\" title=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" href=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Link Contributed Content Series\"><u>Contributed Content Series<\/u><\/a> is a collection of contributed articles written by thought leaders in enterprise software categories. Dan Draper of <a href=\"https:\/\/cipherstash.com\/\" target=\"_blank\" rel=\"noopener\">CipherStash<\/a> puts a number on the real cost of a data breach, and walks us through best practices to prevent them.<\/em><\/strong><\/p>\n<p>As more people engage with the internet, and as more businesses collect user data to gain insights and stay connected to potential customers, the number of data compromises &#8212; and the overall cost of those breaches &#8212; has exploded.<\/p>\n<p>In 2021, a record 1,862 data compromises were recorded \u2013 up from just 157 in 2005. Although the number of hacking incidents dipped a year later, the total number of people affected by those breaches \u2013 more than 422 million \u2013 increased. The total average cost of a data compromise for a business peaked in 2022 \u2013 only to be topped in 2023, at $9.48 million.<\/p>\n<p>Calculating these exact numbers requires a degree of speculation, but suffice to say that falling short in protecting sensitive user information is extremely bad business. And it may be even worse for forward-facing brands.<\/p>\n<h2><strong>Calculating the Damage of a Data Breach<\/strong><\/h2>\n<hr \/>\n<p>The largest confirmed data compromise of 2023 (through September) was marked by the exposure of 3.8 billion user records, the responsibility of which fell to a company called DarkBeam. It\u2019s an objectively awful look \u2013 one with undeniable consequences \u2013 for an organization whose business is the monitoring and managing of supply chain cybersecurity risk. But ask yourself: Does the average consumer have a clue what DarkBeam does? Have they even <em>heard<\/em> of the company?<\/p>\n<p>Compare that scenario with that of Yum! Brands. The parent company of fast food chains KFC, Taco Bell and Pizza Hut, Yum! revealed in the spring that a January incident had exposed certain corporate data, and upon further review found that some employee data had also been compromised. Although it seems no customer information was involved in the breach, and even though Yum! only handles sensitive data as a matter of course \u2013 not as a core area of its business \u2013 the implications could be nightmarish for a company featuring so many recognizable pillars.<\/p>\n<p>After all, the average consumer likely eats at Taco Bell more often than they have ever interacted with, say, DarkBeam. Yum! reportedly closed almost 300 locations in the U.K. in the wake of its data breach, and it has cost the company dearly to clean up the mess. But given the organization\u2019s profile, as well as the vast landscape of alternatives from which consumers have to choose, the real damage to its brands may be far greater than the math suggests.<\/p>\n<h3><strong>Why Hacks Happen \u2013 and How to Avoid Them<\/strong><\/h3>\n<p>The uncomfortable irony is that many, and perhaps most, data-breach incidents today might have been prevented by looking at data protection through a different lens. Among the most common sources of modern data leaks are:<\/p>\n<ul>\n<li>Misconfigured software settings<\/li>\n<li>Social engineering<\/li>\n<li>Recycled or leaked passwords<\/li>\n<\/ul>\n<p>These issues are typically considered as part of an <em>end-user<\/em> security program. Educating staff about good password hygiene or how to avoid falling prey to phishing scams are important strategies but put significant onus on individuals to maintain data security. Even if the majority of employees do an excellent job maintaining best practices, there will always be some who fall victim to an account compromise or scam.<\/p>\n<p>When assessing the data security risk within an organization, we must ask two fundamental questions:<\/p>\n<ol>\n<li><em>Is the data available strictly on a need to know basis?<\/em><\/li>\n<li><em>Is every data access recorded accurately?<\/em><\/li>\n<\/ol>\n<p>How an organization answers these questions can have a profound impact on its ability to defend against data breaches.<\/p>\n<h3><strong>Limiting Access<\/strong><\/h3>\n<p>Seventy percent of employees have access to data they shouldn&#8217;t, so the goal is to limit data access only to those who genuinely need it to do their job. This means that if an employee is compromised, the likelihood an attacker will get something of value is greatly diminished.<\/p>\n<p>However, eliminating or even minimizing data access in practice can be a challenging task. Data is like sand after a day at the beach. Somehow, even after thoroughly washing your feet, a little sand seems to end up everywhere from in your sneakers to the floor of your car. While the database is often where data\u2019s journey starts, you\u2019ll almost certainly find some in a spreadsheet, on a file server or in multiple forms across a dozen different systems.<\/p>\n<h3><strong>The Core Issue of Data Security<\/strong><\/h3>\n<p>Herein lies the core issue&#8211; Traditional approaches to protecting data don\u2019t actually protect data at all! They protect the systems where data resides. But strong access controls on the database provide no protection for data that has found its way into a spreadsheet on an employee laptop.<\/p>\n<p><em>Encryption-in-use<\/em>, traditionally known as row-level or field-level encryption promises to protect data directly. Newly collected data can be encrypted immediately and remain so from that point forward, no matter where it might end up. Such an approach can even <em>cryptographically tag<\/em> data so that access and retention policies can be applied when access is eventually needed by an authorized user. The encryption becomes a universal, deny-by-default layer that works anywhere and everywhere.<\/p>\n<p>Despite its promise, encryption-in-use has had little adoption outside of specific use cases like protecting payment data. The reason is simple&#8211; encrypting individual data records means standard data tooling like SQL no longer functions correctly.<\/p>\n<p>Take a database storing customer names and email addresses. Common queries might include fetching a customer by their email address or performing a partial match on name (a search for \u201cDan Dr\u201d might match \u201cDan Draper\u201d and \u201cDaniella Dresden\u201d). It is also often desirable to sort results alphabetically or by update recency. Such tasks are a breeze for any modern database but encrypt the records with encryption-in-use and everything stops. None of the queries mentioned above will work any longer.<\/p>\n<h3><strong>Fully Homomorphic Encryption<\/strong><\/h3>\n<p>A recent attempt to address this, Fully Homomorphic Encryption (FHE) makes standard operations like those used by a database server, work on data even when encrypted. But FHE has failed to live up to the hype due to woeful performance and eye-watering costs. For perspective, a query that might take a standard database a tenth of a second over unencrypted data, would take <em>several hours<\/em> if the data was encrypted using FHE. Even the most paranoid and cashed-up companies have given up on it.<\/p>\n<p>However, another approach is not only showing great promise, it\u2019s now being actively used in real world applications. After a number of recent advancements, <em>searchable<\/em> <em>encryption<\/em> is finally allowing encryption-in-use to deliver on its promise: to protect data directly rather than just the systems in which it resides. Vendors like MongoDB, Vaultree and my own company, CipherStash are making encryption-in-use possible using the technology available today.<\/p>\n<p>Unlike general purpose FHE which supports all mathematical operations at the expense of efficiency, searchable encryption specializes to work just with the kinds of operations needed to retain query functionality in the database. A trade-off that makes it over 100,000x faster than FHE. Database queries using searchable encryption are so fast that end-users don\u2019t even realize the data is encrypted (that is until they try to access something they\u2019re not supposed to!).<\/p>\n<h3><strong>Data Access Logs<\/strong><\/h3>\n<p>Reflecting on the 2 fundamental questions I asked earlier, we\u2019ve so far answered one: by protecting data directly, the problem of limiting access to data finally becomes tractable. How do we tackle the issue of recording data access reliably? Believe it or not, encryption-in-use has an answer for that as well.<\/p>\n<p>Consider the challenge of reliably recording every data access using traditional technology. Recording data accesses in a database is not <em>too<\/em> difficult (though logging <em>who <\/em>accessed data is complicated by the fact that users often don\u2019t access the database directly but do instead via applications that are connected to the database). But what if the company has hundreds or thousands of databases? Or, sensitive data is accessed in a spreadsheet? How then do you identify, log and centrally store audit information for every access?<\/p>\n<p>Before answering this question, allow me to convince you why data access logging is so important. If a breach occurs, isn\u2019t a record of what was accessed after the fact useless? The data is already gone! While the first priority should always be prevention, early detection is very nearly as good.<\/p>\n<p>Most data breaches, particularly those of any scale, don\u2019t happen in an instant. They play out over hours, days or even weeks. In over 40 percent\u00a0of cases data is siphoned out of a data warehouse or file server using the credentials of a <em>legitimate<\/em> user. Ensuring that every access is logged along with exactly what was accessed, where from and the identity of the accessing user, makes unusual behavior easily detectable.<\/p>\n<h3><strong>Regulating Access with Data Keys<\/strong><\/h3>\n<p>Consider the digital patient records of a hospital. An oncologist working in the cancer ward suddenly accesses hundreds of patient records in the burn unit. Certainly, this unusual activity warrants further investigation. In the age of AI, not only are such anomalies easy to detect, but access can be revoked and a password reset sent to the doctor within the blink of an eye, well before a breach can take hold. The critical part of making all this possible is reliable and timely access data.<\/p>\n<p>As data regulators in the US and around the world increase their demands to not just be made aware of data breaches, but for detailed and timely information about their <em>materiality<\/em>, reliable access data is also fundamental in maintaining compliance.<\/p>\n<p>When a record protected with encryption-in-use is accessed, a decryption request is sent to a service called a key-server. The requesting user must identify themselves to the server and if the decryption is permitted, they will be returned a <em>data key<\/em> that decrypts only the exact record in question. Because the data key uniquely identifies the record, the key server can log what was accessed without ever seeing any sensitive data.<\/p>\n<h3><strong>Data Breach: Final Thoughts and Best Practices<\/strong><\/h3>\n<p>Airtight encryption practices can stave off much of the danger from the above scenarios, as well as other common risks. Reining in data access around an organization, and limiting the exposure of information to third parties, is another important step \u2013 one that is grounded as much in old-school standard operating procedure as it is in cybersecurity. And when data <em>is<\/em> interfaced by a company, comprehensive and clear logging of what is being accessed, by whom and for what reasons is an absolute must. If all else fails, records that paint a clear picture of the source of a data breach can help an organization more swiftly report an incident to the proper officials, offer greater transparency to ameliorate customers and begin filling the cracks in its cybersecurity foundation.<\/p>\n<p>There is no such thing as fool-proof data-compromise prevention. Humans are, and always will be, at the heart of business operations \u2013 which means the corporate protection of sensitive data will always be subject to human error. But there are basic principles of cybersecurity that can \u2013 and should \u2013 be followed by even the most spartan of operations. A small investment of financial resources, supported by a healthy dose of care and concern for your customers and brand, go a very long way in building a firewall between bad actors and the sensitive information that belongs to the people who keep your business thriving.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solutions Review\u2019s\u00a0Contributed Content Series is a collection of contributed articles written by thought leaders in enterprise software categories. Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them. As more people engage with the internet, and as more businesses collect user [&hellip;]<\/p>\n","protected":false},"author":1031,"featured_media":5251,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[551,1],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Calculating the Damage of a Data Breach<\/title>\n<meta name=\"description\" content=\"Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Calculating the Damage of a Data Breach\" \/>\n<meta property=\"og:description\" content=\"Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-22T17:43:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-22T17:50:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"786\" \/>\n\t<meta property=\"og:image:height\" content=\"393\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Dan Draper\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dan Draper\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/\",\"name\":\"Calculating the Damage of a Data Breach\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg\",\"datePublished\":\"2024-01-22T17:43:41+00:00\",\"dateModified\":\"2024-01-22T17:50:15+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/cf68f195da564ed08f4b212d7a474bd9\"},\"description\":\"Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg\",\"width\":786,\"height\":393,\"caption\":\"Data Breach\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Calculating the Damage of a Data Breach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/cf68f195da564ed08f4b212d7a474bd9\",\"name\":\"Dan Draper\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Dan-Draper-headshot.jpeg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Dan-Draper-headshot.jpeg\",\"caption\":\"Dan Draper\"},\"description\":\"Dan Draper is the Founder and CEO of CipherStash. Dan is a lifelong coder and self-taught cryptographer, passionate about developing cutting-edge technology rooted in academic research. He previously worked as VP of Engineering at Medical Director and Expert360, and is a member of Australia\u2019s Cyber Security Working Group-- an organization that prioritizes changes in data security regulation.\",\"sameAs\":[\"https:\/\/cipherstash.com\/\"],\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/draper\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Calculating the Damage of a Data Breach","description":"Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/","og_locale":"en_US","og_type":"article","og_title":"Calculating the Damage of a Data Breach","og_description":"Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them.","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2024-01-22T17:43:41+00:00","article_modified_time":"2024-01-22T17:50:15+00:00","og_image":[{"width":786,"height":393,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg","type":"image\/jpeg"}],"author":"Dan Draper","twitter_misc":{"Written by":"Dan Draper","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/","name":"Calculating the Damage of a Data Breach","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg","datePublished":"2024-01-22T17:43:41+00:00","dateModified":"2024-01-22T17:50:15+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/cf68f195da564ed08f4b212d7a474bd9"},"description":"Dan Draper of CipherStash puts a number on the real cost of a data breach, and walks us through best practices to prevent them.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Damage-of-a-Data-breach.jpg","width":786,"height":393,"caption":"Data Breach"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/calculating-the-damage-of-a-data-breach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"Calculating the Damage of a Data Breach"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/cf68f195da564ed08f4b212d7a474bd9","name":"Dan Draper","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Dan-Draper-headshot.jpeg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2024\/01\/Dan-Draper-headshot.jpeg","caption":"Dan Draper"},"description":"Dan Draper is the Founder and CEO of CipherStash. Dan is a lifelong coder and self-taught cryptographer, passionate about developing cutting-edge technology rooted in academic research. He previously worked as VP of Engineering at Medical Director and Expert360, and is a member of Australia\u2019s Cyber Security Working Group-- an organization that prioritizes changes in data security regulation.","sameAs":["https:\/\/cipherstash.com\/"],"url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/draper\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/5250"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/1031"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=5250"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/5250\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/5251"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=5250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=5250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=5250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}