Posted in

Sensitive Big Data Exposure and How to Avoid It

A few years back, big data was a tech jargon term understood by few outside the industry “ but not any more. During the last few years, the incredible potential of mining large datasets of increased volume, variety and veracity and at higher velocity has started to dawn on the rest of high-revenue generating economy sectors; nowadays the challenges posed by big data are on everyone’s minds, along with the high rewards involved. Every pertinent actor, from financial and commerce giants to health and education providers, are either developing processes to utilise big data, or are already there. That is good news, but they must also be mindful of the risks involved and take steps to mitigate them.

Big Data Breaches Can Affect Millions of Users

Big data, by nature, is no stranger to sensitive data exposure “ currently listed as A6 on OWASP Top Ten 2017 Release Candidate, an authoritative source for the most critical web application threats out there. Sensitive data falling into the wrong hands is in itself devastating enough, but imagine the multiplying effect of huge datasets of vulnerable information being compromised. Just last November, news surfaced that a hacker was able to access the sensitive data of over 34 million residents of the state of Kerala, India, and release their personal records on Facebook. In what is probably one of the most severe data breaches globally, everything from the residents’ names and addresses to their monthly income, electoral details and utilities consumer identification information was made public.

Infographic: Latest Yahoo Hack Is the Largest Data Breach To Date | Statista You will find more statistics at Statista

In that case, the culprit was a Tokyo-based IT security expert, Indian himself, who decided to take extreme measures when his repeated warnings about the local government’s civil department website’s low levels of protection were ignored. Yet other hackers are not so benign as the Indian hacktivist. Moreover, despite this person‘s motives, the information was still made available publicly to everyone, which includes anyone with a criminal agenda. Large-scale data breaches on prominent service providers routinely affect millions of users worldwide and demonstrate just how high the stakes are. The Yahoo data breach revealed last December saw more than 1 billion accounts compromised while the incident at the same company uncovered in September 2016 affected around 500 million users.

How to Mitigate Big Data Exposure Risks

Promoting security as a first priority and ensuring protection mechanisms should be at the top of the agenda for every company and state entity handling big datasets of sensitive information. Identifying and installing appropriate cyber-security tools is key; for instance, a WAF (web application firewall) will effectively protect against threats and intrusions that can result in data exposure as well as other OWASP Top Ten threats and even zero-day attacks. The firewall acts as an added layer of protection between a website and malicious incoming traffic, weeding out potential threats while allowing undisrupted user experience by essentially eliminating false positives in the blocking process.


Enforcing encryption for accessing sensitive data is a must, but it is not enough: focus must be given on strong encryption and passwords as well as proper key management to ensure real protection. Finally, coupling cyber-security protection and skilled IT personnel should also be combined with comprehensive internal data classification and access rights policies: categorising data as confidential, private and public will enable data controllers to identify suitable protection levels for each type of data, as well as restrict user access as required “ with particular attention to data stored on the cloud and on third-party storage.

With great power comes great responsibility, a wise man once said to his nephew, and big data is perhaps the greatest opportunity the industry has had in a long time to understand that “ and rise to the occasion. As utilising big data becomes more and more commonplace, cyber-attacks will become increasingly elaborate “ and so must our response mechanisms and our focus on security, too.

Thomas is a freelance writer with over 5 years covering the latest and greatest developments in business, finance, technology, and web security.

Having written for a host of websites, magazines, and journals Thomas is narrowing his focus on finance and emerging technologies.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.