What is data exfiltration?
Data exfiltration is the unauthorized transfer of data from an organization’s systems to an external actor. It typically occurs after an attacker has gained access to an organization’s IT environment and identified information of value.
Rather than making their presence immediately visible, an attacker may collect and transfer data over time. Smaller data transfers can be more difficult to distinguish from legitimate traffic, allowing the attacker to remain undetected while information is removed.
Data exfiltration can be part of a ransomware attack, where an attacker first steals data and later encrypts systems or threatens to publish the information. Data can also be stolen without the attacker ever locking or encrypting the organization’s systems.
Sicra and data exfiltration
An attacker may have access to an organization’s systems long before an attack becomes visible. Detecting unusual data flows, suspicious activity, and other indications that information is being removed is therefore important.
Sicra SOC monitors security data and can identify unusual data traffic, transfers of sensitive information, and other indicators of data theft. Sicra can also assess network security and identify weaknesses in traffic flows and security controls that may increase the risk of data exfiltration.
Services
Sicra SOC - Security Operation Center
Network security assessment
Security maturity assessment
Related terms: Data breach, Data security, DLP (Data Loss Prevention), Logging, MDR (Managed Detection and Response), Ransomware, SIEM (Security Information and Event Management), SOC (Security Operations Center), Threat intelligence, XDR (Extended Detection and Response)