Skip to main content

Data Breach Preparation

The Home Depot Data Breach is the second largest data breach on record. It has or will affect up to 56 million debit or credit cards. A trusted vendor account, coupled with the use of a previously unknown variant of malware that allowed the establishment of a foothold, was the entry point into the Home Depot network. Once inside the perimeter, privilege escalation provided an avenue to obtain the desired information. Home Depot did, however, learn some lessons from Target. Home Depot certainly communicated better than Target, procured insurance, and instituted as secure an environment as possible. There are specific measures an institution should undertake to prepare for a data breach, and everyone can learn from this breach. Publicly available information about the Home Depot Data Breach provides insight into the attack, an old malware variant with a new twist. While the malware was modified as to be unrecognizable with tools, it probably should have been detected. There are also concerns with Home Depot's insurance and the insurance provider's apparent lack of fully reimbursing Home Depot for their losses. The effect on shareholders and Home Depot's stock price was short lived. This story is still evolving but provides interesting lessons learned concerning how an organization should prepare for it inevitable breach.

35812 (PDF, 2.38MB)

16 Mar 2015
ByDavid Belangia
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

2026 Cybersecurity Workforce Research Report by SANS | GIAC

Research Paper

The cybersecurity workforce is at a turning point. AI is transforming how work gets done, regulators are redefining ‘qualified,’ and organizations are recognizing that the right skills, not headcount, are what drive success. As AI reshapes the cyber workforce, this report helps leaders make informed decisions and shows practitioners where skills and careers are heading.

  • 11 Mar 2026
  • SANS Institute, GIAC Certifications

A Startups Guide to Implementing a Security Program

Research Paper

Startups struggle to balance survival with the practical implementation of a security program. There...

  • 8 Oct 2020
  • Vanessa Pegueros

Putting it all together through Automation

Research Paper

Most problems faced in Information Security are typically time sensitive. For Forensic Engineers and...

  • 22 Apr 2019
  • Kenneth Ray

Information Security Best Practices While Managing Projects

Research Paper

To maximize long-term return on investment (ROI) with a project's delivery, taking information...

  • 25 Mar 2019
  • Dallas Smith

Logon Banners

Research Paper

Logon banners have been a common feature of operating systems and applications for many years....

  • 20 Mar 2019
  • Keelan Stewart

Security Considerations for Team Based Password Managers

Research Paper

Password management applications are a common and practical way to store complex passwords. They use...

  • 23 Jul 2018
  • Matthew Schumacher

Content Security Policy in Practice

Research Paper

The implementation of Content Security Policy to leverage web browser capability in protecting a web...

  • 6 Jul 2018
  • Varghese Palathuruthil

Agile Security Patching

Research Paper

Security Patch Management is one of the biggest security and compliance challenges for organizations...

  • 3 May 2018
  • Michael Hoehl

Speed and Scalability Matter: Review of LogRhythm 7 SIEM and Analytics Platform

Research Paper

Just how scalable, fast and accurate are SIEM tools when under load? To find out, we put the...

  • 13 Apr 2017
  • Dave Shackleford

Bill Gates and Trustworthy Computing: A Case Study in Transformational Leadership

Research Paper

The notion that IT security is a serious issue is non-controversial. The market for cybersecurity...

  • 20 Sep 2016
  • Preston S. Ackerman

Filling the Gaps

Research Paper

There should be an emphasis on the importance of regular internal and external auditing focusing on...

  • 18 Aug 2016
  • Robert Smith

Investing in Information Security: A Case Study in Community Banking

Research Paper

Small businesses, such as community banks, often do not have resources dedicated to information...

  • 12 Aug 2016
  • Wes Earnest

Introduction to Rundeck for Secure Script Executions

Research Paper

Many organizations today support physical, virtual, and cloud-based systems across a wide range of...

  • 11 Aug 2016
  • John Becker

Using Information Security as an Auditing Tool

Research Paper

As cyber-attacks are gaining visibility within mainstream media, what once was knowledge for...

  • 14 Jul 2016
  • Adi Sitnica

Applying Data Analytics on Vulnerability Data

Research Paper

Organizations, by law, should exercise due care and due diligence in securing data at rest, in...

  • 23 Dec 2015
  • Yogesh Dhinwa

Framework for Innovative Security Decisions

Research Paper

Remember the Periodic Table of chemical elements (Dayah, Dynamic Periodic Table, 1997)? It...

  • 3 Nov 2015
  • Ergash Karshiev

Security Data Visualization

Research Paper

The objective of this paper is to provide guidelines on information security data visualization and...

  • 28 Oct 2015
  • Balaji Balakrishnan

Behind the Curve? A Maturity Model for Endpoint Security

Research Paper

Behind the Curve? A Maturity Model for Endpoint Security

  • 22 Oct 2015
  • G. Mark Hardy

The Sliding Scale of Cyber Security

Research Paper

The Sliding Scale of Cyber Security is a model for providing a nuanced discussion to the categories...

  • 1 Sep 2015
  • Robert M. Lee

Protecting Third Party Applications with RASP Infographic

Research Paper

Protecting Third Party Applications with RASP Infographic

  • 27 Aug 2015
  • SANS Institute

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.