0% found this document useful (0 votes)
14 views32 pages

CIA Triad & Target Breach Analysis

The document outlines a series of activities focused on information assurance and security, including case studies on significant data breaches such as Target and Equifax. Each activity aims to enhance students' understanding of the CIA triad, cybersecurity concepts, and the implications of security breaches, with specific instructions and expected outputs. Additionally, it emphasizes the importance of cybersecurity awareness, policy enforcement, and the need for robust security measures in various contexts.

Uploaded by

lester.ladera
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views32 pages

CIA Triad & Target Breach Analysis

The document outlines a series of activities focused on information assurance and security, including case studies on significant data breaches such as Target and Equifax. Each activity aims to enhance students' understanding of the CIA triad, cybersecurity concepts, and the implications of security breaches, with specific instructions and expected outputs. Additionally, it emphasizes the importance of cybersecurity awareness, policy enforcement, and the need for robust security measures in various contexts.

Uploaded by

lester.ladera
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

ACTIVITY NOTE

FOR
INFORMATION ASSURANCE AND SECURITY 2

Prepared by:

Lester R. Ladera
Instructor

ACTIVITY 1:
A. Activity Title:
"The CIA Triad in Real Life: Analyzing Information Security Cases"

B. Activity Overview:
This activity introduces students to the foundational concepts of information security by
analyzing real-life cases of data breaches. Students will examine how breaches affect the
confidentiality, integrity, and availability (CIA) of data, and relate these to security concepts
such as authentication, authorization, non-repudiation, and encryption.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:

1. Research one real-world information security breach (e.g., Yahoo 2013, Equifax
2017, or any local case).
2. Create a one-page report that includes the following:
o Brief summary of the incident (what happened, when, who was affected)
o Which parts of the CIA triad were violated and how
o Potential causes of the breach (technical or human factors)
o Recommendations on how it could have been prevented using authentication,
encryption, or access control
3. Reflect briefly on how this case shows the importance of security to society.
4. Submit your report with a clear, organized layout.

E. Expected Output:

 A one-page written analysis of the security breach, correctly identifying CIA elements
 Clear application of at least two information security concepts
 Proper formatting, reflection, and integration of institutional values

F. Quiz
A 20 items multiple choice quiz had given after the activity.

ACTIVITY 2:
A. Activity Title:
Case Study: A ‘Kill Chain’ Analysis of the 2013 Target Data Breach

B. Activity Overview:
This activity guides students in analyzing the 2013 Target data breach using the Cyber Kill
Chain framework. Through this case study, learners will examine how the attack progressed
through different stages and identify weaknesses in Target’s security posture. The goal is to
deepen understanding of information security concepts such as confidentiality,
authentication, and breach consequences.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:

1. Research the 2013 Target data breach and summarize key facts (timeline, attackers’
method, impact).
2. Using the Cyber Kill Chain model, analyze the attack by outlining how each of the 7
stages (Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command & Control, Actions on Objectives) occurred.
3. For each stage, describe how Target could have responded or prevented the attack.
4. Reflect on which parts of the CIA triad were compromised and how.
5. Present your case study in a 1–2 page report or visual slide (PowerPoint or Canva
accepted).

E. Expected Output:

 A written or visual case study report showing:


o Accurate Kill Chain stage analysis
o Correct application of CIA triad principles
o Clear security recommendations
o Proper formatting, grammar, and organization

Case Study 1: A 'Kill Chain' Analysis of the 2013 Target Data


Breach
The 2013 Target data breach was one of the most significant cybersecurity
incidents in history, compromising the personal and financial data of over
70 million customers. This breach was made possible due to
vulnerabilities in Target’s third-party vendor, Fazio Mechanical Services, an
HVAC company with remote access to Target’s network for billing
purposes. Attackers exploited these weaknesses to infiltrate Target’s
systems, install malware, and extract sensitive customer information. The
breach serves as a critical lesson on the importance of robust
cybersecurity measures, particularly concerning third-party vendors and
network segmentation.

The attack followed the "kill chain" framework, a structured methodology


that outlines the different stages of a cyberattack. It began with
reconnaissance, where attackers identified Fazio Mechanical Services as a
weak link and sent phishing emails to employees, tricking them into
downloading malware. Once inside Fazio’s systems, attackers installed
credential-stealing malware, allowing them to obtain valid login
credentials for Target’s vendor portal. With these credentials, they gained
unauthorized access to Target’s internal network and moved laterally,
focusing on the point-of-sale (POS) systems. Next, they installed RAM-
scraping malware, known as BlackPOS, on Target’s POS systems to extract
unencrypted credit card data during customer transactions. The stolen
data was collected and sent to external staging servers controlled by the
attackers. To avoid detection, the data was exfiltrated in batches and sent
to multiple servers in different countries. Ultimately, the attackers
successfully stole 40 million payment card records and over 70 million
personal records, which were then sold on underground black market
forums.

Several key security failures contributed to the success of this attack.


First, Fazio Mechanical Services lacked adequate security measures,
making it an easy target for attackers. Second, Target’s network was not
properly segmented, allowing attackers to move from vendor access
points to critical systems without restriction. Third, despite having security
tools that detected unusual activity, Target failed to act promptly on the
alerts, allowing the breach to continue undetected for an extended period.
These weaknesses underscore the importance of comprehensive
cybersecurity protocols and proactive threat management.
The impact of the breach was severe. Financially, Target incurred over
$200 million in legal fees, settlements, and fines. The company also
suffered reputational damage, as customers lost trust in its ability to
protect their personal information. Additionally, the breach attracted
heightened regulatory scrutiny, leading to increased focus on supply chain
security and vendor risk management.

To prevent similar incidents, organizations must adopt strict cybersecurity


measures. Vendor risk management is essential, ensuring that third-party
partners adhere to stringent security standards. Network segmentation
should be implemented to isolate critical systems and prevent lateral
movement by attackers. Proactive monitoring and real-time threat
detection are crucial in mitigating breaches before they escalate.
Additionally, employee awareness training can reduce the risk of phishing
and social engineering attacks. Finally, having a well-prepared incident
response plan can minimize damage and recovery time in the event of a
breach.

The 2013 Target data breach serves as a crucial reminder of the ever-
present threats in cybersecurity. By analyzing the breach through the kill
chain framework, organizations can gain valuable insights into how
attacks unfold and develop strategies to safeguard their systems.
Strengthening security measures, particularly regarding third-party
vendors and network segmentation, is vital in preventing future cyber
incidents and protecting sensitive customer data.

Questions:

1. How did the attackers exploit vulnerabilities in Target’s third-party


vendor to gain access to its network?
2. Explain the steps of the attack using the "kill chain" framework. How
did each phase2 contribute to the breach?
3. What were the key security failures that allowed the breach to
occur, and how could they have been prevented?
4. Discuss the financial, reputational, and regulatory impacts of the
breach on Target Corporation.
5. What lessons can organizations learn from the Target data breach,
and what security measures should be implemented to prevent
similar incidents?
Rubrics
ACTIVITY 3:

A. Activity Title:
Case Study: Analyzing the Equifax Data Breach

B. Activity Overview:
This case study aims to enhance students’ understanding of real-world data breaches through
a detailed examination of the 2017 Equifax incident. Students will assess the breach in terms
of security vulnerabilities, the CIA triad, and applicable information security concepts such as
authentication and encryption.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:
Answer the following questions based on your research of the Equifax Data Breach (2017):

1. What caused the Equifax data breach?


Include a summary of the vulnerability exploited, the timeline, and how attackers
gained access.
2. Which components of the CIA triad were compromised, and what were the
impacts on each?
3. What critical security measures were missing or mismanaged by Equifax that
contributed to the breach?
4. What are the long-term consequences of the breach for affected individuals and
for Equifax as an organization?
5. Suggest two specific technical or organizational solutions that could have
prevented this breach or minimized its impact.

E. Expected Output:

 A written response addressing all five questions


 Demonstrated understanding of information security principles and CIA triad
 Proper structure, clarity, and relevance of content in 1–2 pages or a visual summary
(e.g., infographic or slide)
ACTIVITY 4

A. Activity Title:
Case Study: Cybersecurity Breach in Law Enforcement

B. Activity Overview:
This activity explores a case involving a cybersecurity breach within a law enforcement
agency. Students will analyze the causes, impacts, and possible mitigations of the incident,
focusing on security awareness, policy enforcement, and ethical responsibility. This will help
deepen their understanding of practical information security challenges in critical sectors.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:
Read the case scenario about a Cybersecurity Breach at ISU-PD, then answer the following
questions:

1. What mistakes led to the cybersecurity breach at ISU-PD?


2. How could the attack have been prevented?
3. What immediate actions should the IT Department take to mitigate the damage?
4. What legal and ethical concerns arise from this case?
5. How can law enforcement agencies balance cybersecurity with operational
efficiency?

E. Expected Output:

 A written response addressing all five questions clearly and thoughtfully


 Application of key information security concepts (CIA triad, authentication, policy)
 1–2 pages, or a summarized presentation in infographic or slide format (optional)
Case Study 4: Cybersecurity Breach in Law Enforcement

Situation:
The Ifugao State University Police Department (ISU-PD) recently implemented a new cyber
incident response system to protect sensitive case files from cyber threats. The system,
managed by the IT Department, aimed to detect and mitigate attacks such as phishing, malware,
and unauthorized access attempts. However, last week, the department fell victim to a phishing
attack that compromised critical case files, including evidence in an ongoing criminal
investigation.

A police officer, unaware of cybersecurity risks, received an email from what appeared to be the
"ISU-PD IT Support Team." The email urged the officer to reset their password via a provided
link. Without verifying its authenticity, the officer complied. Unbeknownst to them, the link
directed them to a fake website controlled by cybercriminals, who then gained access to the
police network.

The breach led to the deletion of key evidence and the leak of sensitive witness information,
causing delays in legal proceedings. The IT Department detected the intrusion after noticing
unusual activity but was unable to fully recover the lost data. As a result, an internal
investigation was launched, and new cybersecurity protocols were mandated.

Discussion Questions:
1. What mistakes led to the cybersecurity breach at ISU-PD?
The primary mistake was the officer's failure to verify the legitimacy of the email. Additionally,
the IT Department lacked strong multi-factor authentication (MFA) and cybersecurity
awareness training for officers.

2. How could the attack have been prevented?


The department should have implemented mandatory cybersecurity training, enforced MFA for
logins, and regularly tested staff with simulated phishing attempts.

3. What immediate actions should the IT Department take to mitigate the damage?
Conduct a forensic analysis, reset all credentials, strengthen firewall rules, and notify affected
individuals. Implement an incident response plan to handle future breaches effectively.

4. What legal and ethical concerns arise from this case?


The breach raises issues regarding data privacy, law enforcement integrity, and potential legal
consequences for mishandling sensitive case files.

5. How can law enforcement agencies balance cybersecurity with operational efficiency?
By integrating automated cybersecurity systems that require minimal manual intervention,
conducting routine security audits, and ensuring that officers can quickly adapt to new security
measures without hindering their work.
ACTIVITY 5

A. Activity Title:
Case Analysis: Online Privacy and Protection of Children’s Information

B. Activity Overview:
This activity encourages students to explore real-world implications of laws and practices
designed to protect the privacy and security of children’s information online. Students will
analyze scenarios involving educational records, online platforms, and age-verification
challenges while applying their knowledge of legal frameworks and security principles.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

1. Describe the types of information considered sensitive and protected under laws
relating to children and educational records.
2. Recognize common threats and risks faced by children online.
3. Explore the methods used to verify age and ensure privacy in online environments.

D. Activity Instructions:
Answer the following questions based on your research and understanding of information
security laws protecting children:

1. What types of personal information are protected under laws like COPPA and FERPA
in relation to children and educational records?
2. Identify three common online threats that target children today.
3. Describe one real-life case or news story involving a breach of children's data privacy.
What went wrong?
4. What age-verification methods do websites or apps commonly use, and what are their
limitations?
5. Suggest two best practices for educational institutions or platforms to better protect
children’s data online.

E. Expected Output:

 A written response to all five questions


 Proper use of terms and legal references (e.g., COPPA, FERPA)
 Clear and concise answers, totaling 1–2 pages, or presented visually via a slide or
infographic
ACTIVITY 6

A. Activity Title:
Digital Privacy Case Reflection: Living in the Surveillance Era

B. Activity Overview:
In this activity, students will critically examine how personal data is collected, shared, and
potentially misused in today's interconnected world. Emphasis is placed on understanding
threats to privacy, particularly through wireless technologies and people-based platforms like
social media. Students will reflect on real-life scenarios and propose strategies to protect their
digital footprint.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

1. Identify and describe various threats to personal data privacy in the digital era, such as
cyberattacks, data breaches, and identity theft.
2. Understand how these technologies can both enhance and compromise data security.
3. Explore the impact of social media, online tracking, and data collection practices on
personal privacy.
4. Develop strategies for individuals to protect their privacy and manage their digital
footprint.

D. Activity Instructions:
Answer the following questions based on your knowledge and research:

1. Describe three common threats to personal data privacy in today’s digital world.
2. How do wireless technologies (e.g., public Wi-Fi, Bluetooth) expose users to privacy
risks?
3. What role does social media play in the erosion of personal privacy? Provide an
example.
4. Discuss a real-world data breach involving personal data. What were the
consequences?
5. Propose three actionable strategies individuals can use to protect their personal data
and limit online tracking.

E. Expected Output:

 A well-written reflection answering all five questions (1–2 pages)


 Use of real examples and references where applicable
 Optional: Visual summary via infographic or short slide deck (PowerPoint or Canva)
ACTIVITY 7

A. Activity Title:
Case Study Analysis: Data Breach at SecureMed Health Services

B. Activity Overview:
This case study examines a data breach incident at SecureMed Health Services, a fictional
healthcare provider. Students will analyze the key cybersecurity lapses that led to the breach,
evaluate how these risks could have been identified earlier, and propose strategies to prevent
similar incidents. Emphasis will be placed on organizational responsibility, legal
implications, and risk management.

C. Target Learning Outcomes:


By the end of this activity, students will be able to:

1. Identify potential consequences of security breaches for individuals and organizations.


2. Describe fundamental information security concepts and risk management practices.
3. Recognize the legal and compliance obligations of organizations handling sensitive
data.

D. Activity Instructions:
Answer the following five questions based on your analysis of the SecureMed case:

1. What were the key risks that led to the breach?


(e.g., unpatched software, lack of employee awareness, no real-time monitoring)
2. How could the hospital have identified these risks earlier?
(e.g., risk assessments, penetration testing, network monitoring)
3. What strategies should SecureMed implement to mitigate future risks?
(e.g., MFA, patch management, cybersecurity training, IDS)
4. What legal and compliance risks does SecureMed face?
(e.g., penalties under data protection laws, lawsuits, loss of accreditation)
5. What steps should be taken to monitor and prevent future cybersecurity risks?
(e.g., SIEM implementation, audits, phishing simulations, access control)

E. Expected Output:

 A 1–2 page written report with clear, concise answers to all five questions.
 Answers should demonstrate understanding of real-world cybersecurity practices and
legal implications.
 Optional: Students may include a simple infographic or risk mitigation chart to
enhance their analysis.
Case Study 6: Data Breach at SecureMed Health Services

Situation: SecureMed Health Services, a mid-sized hospital, recently


suffered a cybersecurity breach that compromised patient medical
records. The breach occurred when an administrative staff member
received an email disguised as an urgent system update from the
hospital’s IT department. Without verifying its authenticity, the employee
clicked on a malicious attachment, unknowingly granting hackers access
to the hospital’s network.

The attackers exploited an unpatched software vulnerability in the


hospital’s patient management system, allowing them to infiltrate
SecureMed’s database. Over the next 48 hours, the attackers extracted
sensitive data, including patient names, medical histories, and
billing information, before launching a ransomware attack that
encrypted critical files and demanded payment for decryption.

SecureMed’s IT team detected the breach only after multiple users


reported being locked out of their accounts. By the time the attack was
contained, thousands of patient records were leaked, violating the
Confidentiality, Integrity, and Availability (CIA) principles of
information security. This breach led to financial losses, reputational
damage, and legal consequences due to non-compliance with health
data protection laws.

A forensic investigation revealed that the hospital had outdated security


protocols, no employee cybersecurity training, and lacked real-
time threat monitoring. The absence of a robust risk management
framework left vulnerabilities unaddressed, making SecureMed an easy
target for cybercriminals.

As a result, SecureMed faced legal actions from affected patients,


heavy fines from regulatory bodies, and a loss of trust from the public. The
hospital’s board demanded immediate corrective measures to prevent
future incidents and ensure compliance with cybersecurity standards.

Discussion Questions:

1. What were the key risks that led to the breach?

o The key risks included lack of employee cybersecurity


awareness, unpatched software vulnerabilities, and
absence of real-time threat monitoring.

2. How could the hospital have identified these risks earlier?


o Through regular risk assessments, penetration testing,
and continuous monitoring of network activities.

3. What strategies should SecureMed implement to mitigate


future risks?

o Implementing multi-factor authentication (MFA), regular


security training, patch management, and intrusion
detection systems (IDS).

4. What legal and compliance risks does SecureMed face?

o SecureMed may face fines for violating data protection


laws, lawsuits from affected patients, and loss of
accreditation due to non-compliance.

5. What steps should be taken to monitor and prevent future


cybersecurity risks?

o Establishing a Security Information and Event


Management (SIEM) system, routine audits, employee
phishing simulations, and strict access controls.
ACTIVITY 8

A. Activity Title:
Case Study: Risk Assessment of a New Online Learning Platform

B. Activity Overview:
This activity explores the security considerations of implementing a new online learning
platform in a school setting. Students will analyze potential threats, identify vulnerabilities,
and evaluate appropriate risk management strategies to protect student data and maintain
system integrity.

C. Target Learning Outcomes:


By the end of this activity, students will be able to:

1. Identify threats and vulnerabilities in digital education platforms.


2. Propose risk mitigation strategies to enhance data security.
3. Evaluate different approaches to managing risk in real-world scenarios.

D. Activity Instructions:
Read the case study scenario: A school recently adopted a new online learning platform to
support remote and blended learning. The platform collects student data and provides access
to course materials, communication tools, and assessment modules.

Answer the following questions:

1. What are at least two threats the school might face in using the platform? Why are
these considered threats?
2. Identify one vulnerability in the case that could lead to a breach of student data. How
could it be exploited?
3. Recommend one risk mitigation strategy and explain how it would improve the
school’s security posture.
4. Do you think transferring risk (e.g., to a third-party security provider) is a good
option in this case? Why or why not?
5. If the school chooses to accept a risk, what kind of risk would be reasonable to
accept, and why?

E. Expected Output:

 A 1–2 page written report answering all five questions.


 Answers should be clearly explained with examples or reasoning where applicable.
 Optional: A simple risk matrix or visual summary to support your analysis.
ACTIVITY NOTE
FOR
INFORMATION ASSURANCE AND SECURITY 2

Prepared by:

Lester R. Ladera
Instructor
ACTIVITY 1:

A. Activity Title:
"The CIA Triad in Real Life: Analyzing Information Security Cases"

B. Activity Overview:
This activity introduces students to the foundational concepts of information security by
analyzing real-life cases of data breaches. Students will examine how breaches affect the
confidentiality, integrity, and availability (CIA) of data, and relate these to security concepts
such as authentication, authorization, non-repudiation, and encryption.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:

5. Research one real-world information security breach (e.g., Yahoo 2013, Equifax
2017, or any local case).
6. Create a one-page report that includes the following:
o Brief summary of the incident (what happened, when, who was affected)
o Which parts of the CIA triad were violated and how
o Potential causes of the breach (technical or human factors)
o Recommendations on how it could have been prevented using authentication,
encryption, or access control
7. Reflect briefly on how this case shows the importance of security to society.
8. Submit your report with a clear, organized layout.

E. Expected Output:

 A one-page written analysis of the security breach, correctly identifying CIA elements
 Clear application of at least two information security concepts
 Proper formatting, reflection, and integration of institutional values

F. Quiz
A 20 items multiple choice quiz had given after the activity.
ACTIVITY 2:

A. Activity Title:
Case Study: A ‘Kill Chain’ Analysis of the 2013 Target Data Breach

B. Activity Overview:
This activity guides students in analyzing the 2013 Target data breach using the Cyber Kill
Chain framework. Through this case study, learners will examine how the attack progressed
through different stages and identify weaknesses in Target’s security posture. The goal is to
deepen understanding of information security concepts such as confidentiality,
authentication, and breach consequences.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:

6. Research the 2013 Target data breach and summarize key facts (timeline, attackers’
method, impact).
7. Using the Cyber Kill Chain model, analyze the attack by outlining how each of the 7
stages (Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command & Control, Actions on Objectives) occurred.
8. For each stage, describe how Target could have responded or prevented the attack.
9. Reflect on which parts of the CIA triad were compromised and how.
10. Present your case study in a 1–2 page report or visual slide (PowerPoint or Canva
accepted).

E. Expected Output:

 A written or visual case study report showing:


o Accurate Kill Chain stage analysis
o Correct application of CIA triad principles
o Clear security recommendations
o Proper formatting, grammar, and organization
Case Study 1: A 'Kill Chain' Analysis of the 2013 Target Data
Breach

The 2013 Target data breach was one of the most significant cybersecurity
incidents in history, compromising the personal and financial data of over
70 million customers. This breach was made possible due to
vulnerabilities in Target’s third-party vendor, Fazio Mechanical Services, an
HVAC company with remote access to Target’s network for billing
purposes. Attackers exploited these weaknesses to infiltrate Target’s
systems, install malware, and extract sensitive customer information. The
breach serves as a critical lesson on the importance of robust
cybersecurity measures, particularly concerning third-party vendors and
network segmentation.

The attack followed the "kill chain" framework, a structured methodology


that outlines the different stages of a cyberattack. It began with
reconnaissance, where attackers identified Fazio Mechanical Services as a
weak link and sent phishing emails to employees, tricking them into
downloading malware. Once inside Fazio’s systems, attackers installed
credential-stealing malware, allowing them to obtain valid login
credentials for Target’s vendor portal. With these credentials, they gained
unauthorized access to Target’s internal network and moved laterally,
focusing on the point-of-sale (POS) systems. Next, they installed RAM-
scraping malware, known as BlackPOS, on Target’s POS systems to extract
unencrypted credit card data during customer transactions. The stolen
data was collected and sent to external staging servers controlled by the
attackers. To avoid detection, the data was exfiltrated in batches and sent
to multiple servers in different countries. Ultimately, the attackers
successfully stole 40 million payment card records and over 70 million
personal records, which were then sold on underground black market
forums.

Several key security failures contributed to the success of this attack.


First, Fazio Mechanical Services lacked adequate security measures,
making it an easy target for attackers. Second, Target’s network was not
properly segmented, allowing attackers to move from vendor access
points to critical systems without restriction. Third, despite having security
tools that detected unusual activity, Target failed to act promptly on the
alerts, allowing the breach to continue undetected for an extended period.
These weaknesses underscore the importance of comprehensive
cybersecurity protocols and proactive threat management.

The impact of the breach was severe. Financially, Target incurred over
$200 million in legal fees, settlements, and fines. The company also
suffered reputational damage, as customers lost trust in its ability to
protect their personal information. Additionally, the breach attracted
heightened regulatory scrutiny, leading to increased focus on supply chain
security and vendor risk management.

To prevent similar incidents, organizations must adopt strict cybersecurity


measures. Vendor risk management is essential, ensuring that third-party
partners adhere to stringent security standards. Network segmentation
should be implemented to isolate critical systems and prevent lateral
movement by attackers. Proactive monitoring and real-time threat
detection are crucial in mitigating breaches before they escalate.
Additionally, employee awareness training can reduce the risk of phishing
and social engineering attacks. Finally, having a well-prepared incident
response plan can minimize damage and recovery time in the event of a
breach.

The 2013 Target data breach serves as a crucial reminder of the ever-
present threats in cybersecurity. By analyzing the breach through the kill
chain framework, organizations can gain valuable insights into how
attacks unfold and develop strategies to safeguard their systems.
Strengthening security measures, particularly regarding third-party
vendors and network segmentation, is vital in preventing future cyber
incidents and protecting sensitive customer data.

Questions:

6. How did the attackers exploit vulnerabilities in Target’s third-party


vendor to gain access to its network?
7. Explain the steps of the attack using the "kill chain" framework. How
did each phase2 contribute to the breach?
8. What were the key security failures that allowed the breach to
occur, and how could they have been prevented?
9. Discuss the financial, reputational, and regulatory impacts of the
breach on Target Corporation.
10. What lessons can organizations learn from the Target data
breach, and what security measures should be implemented to
prevent similar incidents?

Rubrics
ACTIVITY 3:

A. Activity Title:
Case Study: Analyzing the Equifax Data Breach

B. Activity Overview:
This case study aims to enhance students’ understanding of real-world data breaches through
a detailed examination of the 2017 Equifax incident. Students will assess the breach in terms
of security vulnerabilities, the CIA triad, and applicable information security concepts such as
authentication and encryption.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:
Answer the following questions based on your research of the Equifax Data Breach (2017):

6. What caused the Equifax data breach?


Include a summary of the vulnerability exploited, the timeline, and how attackers
gained access.
7. Which components of the CIA triad were compromised, and what were the
impacts on each?
8. What critical security measures were missing or mismanaged by Equifax that
contributed to the breach?
9. What are the long-term consequences of the breach for affected individuals and
for Equifax as an organization?
10. Suggest two specific technical or organizational solutions that could have
prevented this breach or minimized its impact.

E. Expected Output:

 A written response addressing all five questions


 Demonstrated understanding of information security principles and CIA triad
 Proper structure, clarity, and relevance of content in 1–2 pages or a visual summary
(e.g., infographic or slide)

ACTIVITY 4

A. Activity Title:
Case Study: Cybersecurity Breach in Law Enforcement

B. Activity Overview:
This activity explores a case involving a cybersecurity breach within a law enforcement
agency. Students will analyze the causes, impacts, and possible mitigations of the incident,
focusing on security awareness, policy enforcement, and ethical responsibility. This will help
deepen their understanding of practical information security challenges in critical sectors.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.

D. Activity Instructions:
Read the case scenario about a Cybersecurity Breach at ISU-PD, then answer the following
questions:

6. What mistakes led to the cybersecurity breach at ISU-PD?


7. How could the attack have been prevented?
8. What immediate actions should the IT Department take to mitigate the damage?
9. What legal and ethical concerns arise from this case?
10. How can law enforcement agencies balance cybersecurity with operational
efficiency?

E. Expected Output:

 A written response addressing all five questions clearly and thoughtfully


 Application of key information security concepts (CIA triad, authentication, policy)
 1–2 pages, or a summarized presentation in infographic or slide format (optional)
Case Study 4: Cybersecurity Breach in Law Enforcement

Situation:
The Ifugao State University Police Department (ISU-PD) recently implemented a new cyber
incident response system to protect sensitive case files from cyber threats. The system,
managed by the IT Department, aimed to detect and mitigate attacks such as phishing, malware,
and unauthorized access attempts. However, last week, the department fell victim to a phishing
attack that compromised critical case files, including evidence in an ongoing criminal
investigation.

A police officer, unaware of cybersecurity risks, received an email from what appeared to be the
"ISU-PD IT Support Team." The email urged the officer to reset their password via a provided
link. Without verifying its authenticity, the officer complied. Unbeknownst to them, the link
directed them to a fake website controlled by cybercriminals, who then gained access to the
police network.

The breach led to the deletion of key evidence and the leak of sensitive witness information,
causing delays in legal proceedings. The IT Department detected the intrusion after noticing
unusual activity but was unable to fully recover the lost data. As a result, an internal
investigation was launched, and new cybersecurity protocols were mandated.

Discussion Questions:
1. What mistakes led to the cybersecurity breach at ISU-PD?
The primary mistake was the officer's failure to verify the legitimacy of the email. Additionally,
the IT Department lacked strong multi-factor authentication (MFA) and cybersecurity
awareness training for officers.

2. How could the attack have been prevented?


The department should have implemented mandatory cybersecurity training, enforced MFA for
logins, and regularly tested staff with simulated phishing attempts.

3. What immediate actions should the IT Department take to mitigate the damage?
Conduct a forensic analysis, reset all credentials, strengthen firewall rules, and notify affected
individuals. Implement an incident response plan to handle future breaches effectively.

4. What legal and ethical concerns arise from this case?


The breach raises issues regarding data privacy, law enforcement integrity, and potential legal
consequences for mishandling sensitive case files.
5. How can law enforcement agencies balance cybersecurity with operational efficiency?
By integrating automated cybersecurity systems that require minimal manual intervention,
conducting routine security audits, and ensuring that officers can quickly adapt to new security
measures without hindering their work.

ACTIVITY 5

A. Activity Title:
Case Analysis: Online Privacy and Protection of Children’s Information

B. Activity Overview:
This activity encourages students to explore real-world implications of laws and practices
designed to protect the privacy and security of children’s information online. Students will
analyze scenarios involving educational records, online platforms, and age-verification
challenges while applying their knowledge of legal frameworks and security principles.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

4. Describe the types of information considered sensitive and protected under laws
relating to children and educational records.
5. Recognize common threats and risks faced by children online.
6. Explore the methods used to verify age and ensure privacy in online environments.

D. Activity Instructions:
Answer the following questions based on your research and understanding of information
security laws protecting children:

6. What types of personal information are protected under laws like COPPA and FERPA
in relation to children and educational records?
7. Identify three common online threats that target children today.
8. Describe one real-life case or news story involving a breach of children's data privacy.
What went wrong?
9. What age-verification methods do websites or apps commonly use, and what are their
limitations?
10. Suggest two best practices for educational institutions or platforms to better protect
children’s data online.

E. Expected Output:

 A written response to all five questions


 Proper use of terms and legal references (e.g., COPPA, FERPA)
 Clear and concise answers, totaling 1–2 pages, or presented visually via a slide or
infographic
ACTIVITY 6

A. Activity Title:
Digital Privacy Case Reflection: Living in the Surveillance Era

B. Activity Overview:
In this activity, students will critically examine how personal data is collected, shared, and
potentially misused in today's interconnected world. Emphasis is placed on understanding
threats to privacy, particularly through wireless technologies and people-based platforms like
social media. Students will reflect on real-life scenarios and propose strategies to protect their
digital footprint.

C. Target Learning Outcomes:


By the end of this activity, the student should be able to:

5. Identify and describe various threats to personal data privacy in the digital era, such as
cyberattacks, data breaches, and identity theft.
6. Understand how these technologies can both enhance and compromise data security.
7. Explore the impact of social media, online tracking, and data collection practices on
personal privacy.
8. Develop strategies for individuals to protect their privacy and manage their digital
footprint.

D. Activity Instructions:
Answer the following questions based on your knowledge and research:

6. Describe three common threats to personal data privacy in today’s digital world.
7. How do wireless technologies (e.g., public Wi-Fi, Bluetooth) expose users to privacy
risks?
8. What role does social media play in the erosion of personal privacy? Provide an
example.
9. Discuss a real-world data breach involving personal data. What were the
consequences?
10. Propose three actionable strategies individuals can use to protect their personal data
and limit online tracking.

E. Expected Output:

 A well-written reflection answering all five questions (1–2 pages)


 Use of real examples and references where applicable
 Optional: Visual summary via infographic or short slide deck (PowerPoint or Canva)
ACTIVITY 7

A. Activity Title:
Case Study Analysis: Data Breach at SecureMed Health Services

B. Activity Overview:
This case study examines a data breach incident at SecureMed Health Services, a fictional
healthcare provider. Students will analyze the key cybersecurity lapses that led to the breach,
evaluate how these risks could have been identified earlier, and propose strategies to prevent
similar incidents. Emphasis will be placed on organizational responsibility, legal
implications, and risk management.

C. Target Learning Outcomes:


By the end of this activity, students will be able to:

4. Identify potential consequences of security breaches for individuals and organizations.


5. Describe fundamental information security concepts and risk management practices.
6. Recognize the legal and compliance obligations of organizations handling sensitive
data.

D. Activity Instructions:
Answer the following five questions based on your analysis of the SecureMed case:

6. What were the key risks that led to the breach?


(e.g., unpatched software, lack of employee awareness, no real-time monitoring)
7. How could the hospital have identified these risks earlier?
(e.g., risk assessments, penetration testing, network monitoring)
8. What strategies should SecureMed implement to mitigate future risks?
(e.g., MFA, patch management, cybersecurity training, IDS)
9. What legal and compliance risks does SecureMed face?
(e.g., penalties under data protection laws, lawsuits, loss of accreditation)
10. What steps should be taken to monitor and prevent future cybersecurity risks?
(e.g., SIEM implementation, audits, phishing simulations, access control)

E. Expected Output:

 A 1–2 page written report with clear, concise answers to all five questions.
 Answers should demonstrate understanding of real-world cybersecurity practices and
legal implications.
 Optional: Students may include a simple infographic or risk mitigation chart to
enhance their analysis.
Case Study 6: Data Breach at SecureMed Health Services

Situation: SecureMed Health Services, a mid-sized hospital, recently


suffered a cybersecurity breach that compromised patient medical
records. The breach occurred when an administrative staff member
received an email disguised as an urgent system update from the
hospital’s IT department. Without verifying its authenticity, the employee
clicked on a malicious attachment, unknowingly granting hackers access
to the hospital’s network.

The attackers exploited an unpatched software vulnerability in the


hospital’s patient management system, allowing them to infiltrate
SecureMed’s database. Over the next 48 hours, the attackers extracted
sensitive data, including patient names, medical histories, and
billing information, before launching a ransomware attack that
encrypted critical files and demanded payment for decryption.

SecureMed’s IT team detected the breach only after multiple users


reported being locked out of their accounts. By the time the attack was
contained, thousands of patient records were leaked, violating the
Confidentiality, Integrity, and Availability (CIA) principles of
information security. This breach led to financial losses, reputational
damage, and legal consequences due to non-compliance with health
data protection laws.

A forensic investigation revealed that the hospital had outdated security


protocols, no employee cybersecurity training, and lacked real-
time threat monitoring. The absence of a robust risk management
framework left vulnerabilities unaddressed, making SecureMed an easy
target for cybercriminals.

As a result, SecureMed faced legal actions from affected patients,


heavy fines from regulatory bodies, and a loss of trust from the public. The
hospital’s board demanded immediate corrective measures to prevent
future incidents and ensure compliance with cybersecurity standards.

Discussion Questions:
6. What were the key risks that led to the breach?

o The key risks included lack of employee cybersecurity


awareness, unpatched software vulnerabilities, and
absence of real-time threat monitoring.

7. How could the hospital have identified these risks earlier?

o Through regular risk assessments, penetration testing,


and continuous monitoring of network activities.

8. What strategies should SecureMed implement to mitigate


future risks?

o Implementing multi-factor authentication (MFA), regular


security training, patch management, and intrusion
detection systems (IDS).

9. What legal and compliance risks does SecureMed face?

o SecureMed may face fines for violating data protection


laws, lawsuits from affected patients, and loss of
accreditation due to non-compliance.

10. What steps should be taken to monitor and prevent


future cybersecurity risks?

o Establishing a Security Information and Event


Management (SIEM) system, routine audits, employee
phishing simulations, and strict access controls.
ACTIVITY 8

A. Activity Title:
Case Study: Risk Assessment of a New Online Learning Platform

B. Activity Overview:
This activity explores the security considerations of implementing a new online learning
platform in a school setting. Students will analyze potential threats, identify vulnerabilities,
and evaluate appropriate risk management strategies to protect student data and maintain
system integrity.

C. Target Learning Outcomes:


By the end of this activity, students will be able to:

4. Identify threats and vulnerabilities in digital education platforms.


5. Propose risk mitigation strategies to enhance data security.
6. Evaluate different approaches to managing risk in real-world scenarios.

D. Activity Instructions:
Read the case study scenario: A school recently adopted a new online learning platform to
support remote and blended learning. The platform collects student data and provides access
to course materials, communication tools, and assessment modules.

Answer the following questions:

6. What are at least two threats the school might face in using the platform? Why are
these considered threats?
7. Identify one vulnerability in the case that could lead to a breach of student data. How
could it be exploited?
8. Recommend one risk mitigation strategy and explain how it would improve the
school’s security posture.
9. Do you think transferring risk (e.g., to a third-party security provider) is a good
option in this case? Why or why not?
10. If the school chooses to accept a risk, what kind of risk would be reasonable to
accept, and why?

E. Expected Output:

 A 1–2 page written report answering all five questions.


 Answers should be clearly explained with examples or reasoning where applicable.
 Optional: A simple risk matrix or visual summary to support your analysis.

Case Study 7: School adopts new online learning platform

Scenario:

Saint Gabriel High School has recently adopted a new online learning
platform to enhance digital learning and facilitate hybrid education. This
new system allows students and teachers to access lessons, assignments,
grades, and communication tools online. While the new platform promises
better learning outcomes and improved access to educational resources,
its implementation introduces potential security risks.

During the pilot phase, several issues were reported:

 Some student accounts were accessed without permission.

 Teachers experienced unexpected data loss.

 Parents raised concerns about privacy, especially related to


students' personal information being stored online.

 The IT department realized that the platform had not been updated
with the latest security patches.

As part of the school’s risk management team, your class is asked to


evaluate the situation.

Task:

1. Identify possible threats involved in using the new platform.

2. List potential vulnerabilities that may exist within the current


system.

3. Propose appropriate risk-handling strategies to mitigate or avoid


these risks.

Examples to Guide Your Evaluation:


 Threat Example: Unauthorized access by hackers or misuse by
insiders.

 Vulnerability Example: Weak passwords, lack of data encryption, or


untrained users.

 Risk Handling Strategy Example: Implement two-factor


authentication (Mitigation), outsource security auditing (Transfer), or
limit platform access to verified devices (Avoidance).

Assessment Questions:

1. What are at least two threats that the school might face in using the
new online learning platform? Explain why they are threats.

2. Identify one vulnerability in the case that could lead to a breach of


student data. How can this be exploited?

3. Recommend one risk mitigation strategy and explain how it would


improve the school’s security posture.

4. In your opinion, is transferring risk (e.g., hiring a third-party security


provider) a good option in this case? Why or why not?

5. If the school chooses to “accept” a risk, what kind of risk would be


reasonable to accept and why?

You might also like