Cyber Risk Compendium

Disclosure of sensitive information

BSI ID: G 0.19

Confidential data and information may only be accessed by persons authorised to do so. Alongside integrity and availability, confidentiality is one of the core values of information security. Confidential information (such as passwords, personal data, company or official secrets, development data) is inherently at risk of being disclosed through technical failure, carelessness or even deliberate action. This confidential information can be accessed at various points, for example

  • on storage media within computers (hard drives),

  • on removable storage media (USB sticks, CDs or DVDs),

  • in printed form on paper (printouts, files) and

  • on transmission paths during data transfer.

The manner in which information is disclosed can also vary greatly, for example:

  • unauthorised reading of files,

  • careless disclosure, e.g. in the course of repair orders,

  • insufficient deletion or destruction of data carriers,

  • theft of data carriers and subsequent evaluation,

  • tapping of transmission lines,

  • infection of IT systems with malware,

  • reading on screens or eavesdropping on conversations.

If sensitive information is disclosed, this can have serious consequences for an institution. Among other things, the loss of confidentiality can have the following negative effects on an institution:

  • Violation of laws, e.g. data protection, banking secrecy,

  • Negative internal effects, e.g. demoralisation of employees,

  • Negative external effects, e.g. damage to relationships with business partners, loss of customer trust,

  • Financial consequences, e.g. claims for damages, fines, legal costs,

  • Impairment of the right to informational self-determination.

A breach of confidentiality is not always noticed immediately. It often only becomes apparent later, e.g. through press enquiries, that unauthorised persons have gained access to confidential information.

Example:

  • Buyers of used computers, hard drives, mobile phones or similar devices repeatedly find highly confidential information such as patient data or account numbers on them.