Article

Cybersecurity lessons from the largest data breaches

The largest data breaches rarely begin with exotic attacks. They usually start with too much data kept too long, an exposed system or stolen password, and an intrusion nobody noticed in time.

The short answer

Large breaches make headlines because of their scale, but the causes are usually ordinary: databases left open to the internet, reused or stolen passwords without multi-factor authentication, unpatched systems, over-privileged accounts, weak oversight of suppliers and slow detection. The lessons apply to organisations of every size. Four stand out.

  1. Data you do not keep cannot be stolen.
  2. Exposed systems and weak identities are the usual way in.
  3. Detection speed decides how bad it gets.
  4. Your response, including legal reporting, is part of your security.

This article discusses patterns seen across many public breaches rather than any single incident, and does not repeat figures that cannot be verified.

Why this matters in Nigeria

Ransomware and data theft are among the most common threats to organisations worldwide, and Nigerian organisations, from banks and hospitals to schools and distributors, are not exempt. Attackers tend to be opportunistic: they look for whatever is exposed, not for a particular name. Modern ransomware groups typically steal data before encrypting it, so a ransomware incident is often also a data breach. With the Nigeria Data Protection Act 2023 (NDPA) now actively enforced by the Nigeria Data Protection Commission (NDPC), a breach is a regulatory matter as well as a technical one (NDPC).

Lesson 1: data you do not keep cannot be stolen

Many of the largest breaches exposed records the organisation no longer needed: former customers, old applicants, duplicate exports, test copies of production databases. Large, centralised datasets are attractive targets, and every copy is another place to protect. The NDPA's principles of data minimisation and storage limitation point the same way: keep only what you need, for as long as you need it.

What to do:

  • Keep an inventory of where personal and sensitive data lives, including spreadsheets, file shares, backups and SaaS applications.
  • Set retention periods and delete data when they expire, subject to legal retention requirements.
  • Never use real personal data in test or development environments without masking it.
  • Encrypt sensitive data at rest and in transit.

Lesson 2: exposed systems and weak identities are the usual way in

Common entry points include cloud storage or databases configured for public access, remote access portals without multi-factor authentication, unpatched internet-facing software and credentials harvested by phishing or reused from earlier breaches.

Widely used baseline controls, such as those in the NIST Cybersecurity Framework and CISA's ransomware guidance, cover most of these directly: automatic patching, secure configuration, strong authentication, perimeter defences, secure cloud use and least-privilege access control (NIST, CISA).

What to do:

  • Turn on multi-factor authentication everywhere, starting with email, remote access, cloud consoles and administrator accounts.
  • Patch internet-facing systems first and fastest, and retire software that no longer receives security updates.
  • Review cloud storage and database permissions regularly; public access should be deliberate and rare.
  • Give each person only the access their role needs, and use separate accounts for administration.
  • Include suppliers: require security commitments in contracts and remove vendor access when it is no longer needed.

Lesson 3: detection speed decides how bad it gets

In many large breaches, attackers were inside for weeks or months before anyone noticed. The longer they stay, the more data they find and copy.

What to do:

  • Deploy endpoint detection and response (EDR) on computers and servers, with someone monitoring the alerts. See EDR vs antivirus.
  • Centralise logs from key systems (identity, email, firewalls, cloud) and keep them long enough to investigate.
  • Alert on unusual activity such as mass downloads, new administrator accounts or logins from unexpected locations.
  • Ransomware guidance from CISA recommends logging and alerting, network segmentation, least privilege and multiple offline backups as core preventive measures (CISA).

Lesson 4: your response is part of your security

The organisations that suffer most after a breach are often those that respond slowly, communicate poorly or do not meet their legal obligations.

Under the NDPA, a data controller must notify the NDPC within 72 hours of becoming aware of a breach that is likely to risk individuals' rights and freedoms, and must tell affected people without undue delay where the risk is high. Keep a record of every breach, whether or not it was reportable. Banks, insurers, pension operators, capital-market firms and other regulated businesses may have further reporting duties to their sector regulators, and operators of critical national information infrastructure have incident-reporting duties under the Cybercrimes Act (as amended) and to ngCERT (NDPC, ngCERT). This is general information, not legal advice. For the details, read responding to a data breach in Nigeria.

What to do:

  • Write a short incident response plan: who decides, who investigates, who communicates, who contacts legal counsel and insurers.
  • Keep contact details for your IT provider, legal counsel and cyber insurer somewhere that does not depend on your own systems.
  • Practise with a tabletop exercise at least once a year.
  • Make sure backups are offline or immutable and that restores have been tested. See backup vs recovery plan.

Breach-readiness checklist

  • We know where our sensitive and personal data is stored.
  • We delete data we no longer need, on a schedule.
  • Multi-factor authentication is on for email, remote access, cloud and admin accounts.
  • Internet-facing systems are patched promptly and unsupported software is retired.
  • Cloud storage and database permissions have been reviewed this quarter.
  • EDR is deployed and alerts are monitored.
  • Key logs are collected and retained.
  • Supplier access is documented and reviewed.
  • We have a tested incident response plan and breach record log.
  • Backups include an offline or immutable copy, and restores are tested.

Limitations

No set of controls prevents every breach. The aim is to make attacks harder, detect them sooner and limit what can be taken. Priorities depend on your data, systems and risk tolerance, which is why a risk assessment is a sensible first step.

Next step

Our cybersecurity services help organisations put these controls in place and monitor them, with 24/7 monitoring and support for managed-service clients. If you are unsure where you stand, start with a security assessment.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Nigeria Data Protection Commission (NDPA, GAID 2025 and breach reporting), Nigeria Data Protection Commission
  2. ngCERT, Nigeria's computer emergency response team, Federal Government of Nigeria
  3. Cybersecurity Framework, NIST
  4. #StopRansomware, CISA

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts