• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

2

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

3

Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less

1

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

2

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

3

Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
CommentaryCybersecurity

After the SolarWinds hack, we need contact tracing for our data

By
Doug Merritt
Doug Merritt
Down Arrow Button Icon
By
Doug Merritt
Doug Merritt
Down Arrow Button Icon
February 18, 2021, 12:30 PM ET
For security-conscious companies and organizations, writes Doug Merritt, “data contact tracing can dramatically reduce the time it takes to discover how far into their networks an attacker has penetrated.”
For security-conscious companies and organizations, writes Doug Merritt, “data contact tracing can dramatically reduce the time it takes to discover how far into their networks an attacker has penetrated.”Getty Images
Add Fortune on Google for similar content.

The ramifications of the SolarWinds hack will plague affected organizations for months, if not years. 

Since the December revelation that thousands of organizations may have been compromised by a SolarWinds software update containing Russian malware, security experts have worked overtime to identify and remediate any breach. This has meant everything from updating the infected SolarWinds software (or removing it entirely), to checking data logs to detect any intrusion or lateral movement across a company’s IT environment, to even perhaps executing full third-party software code reviews.

While the attack on SolarWinds software is arguably the most significant state-sponsored hack we’ve seen in years, it’s more than an isolated incident. It is emblematic of a constant reality of the digital era: We’re all likely to get hacked at some point. Our ability to respond determines our ability to operate. Digital security is now a broad governance imperative. 

Organizations of all types must be able to defend against attacks. Yet 2020 research from the Ponemon Institute, conducted in partnership with IBM, found that on average it takes a company 207 days to identify that a breach has occurred, and another 73 days to contain it. 

Whether a cyberattack is motivated toward sabotage or data theft, a victim’s fundamental questions are, “Who has accessed our data? Which data, when, and why?” In other words, the ability to trace all contact with sensitive data is vital. But most companies today cannot do this.

Contact tracing is an epidemiological technique that we’ve all heard a lot about in the past year. Because COVID-19 is spread by human contact, we look at where an infected person has been, and whose paths they’ve crossed, during the infectious period. On the human scale, we’ve seen mixed results worldwide. But applied to digital systems, contact tracing could become a powerful security technique.

This idea is not new. A concept called Sightings has been gaining traction in the security community, largely at the academic level, for the past few years. The idea is for organizations to be able to share details of how they were attacked and what was targeted—the who, what, and when—as quickly as possible with other organizations. 

This concept could help organizations identify breaches sooner and remediate faster and more effectively. Through sharing, attack techniques could be more thoroughly understood, and with the right reporting mechanism, the resulting threat intelligence could be shared to help more organizations avoid a breach in the first place. MITRE, a leading not-for-profit research organization, is working on incorporating Sightings concepts into a security reporting process that would let breach victims share appropriate data in a secure, anonymized way to benefit the wider community.

Beyond this threat intelligence application, organizations could use this sort of contact tracing approach for their own internal investigations. Data contact tracing can dramatically reduce the time it takes to discover how far into their networks an attacker has penetrated, and identify where related systems in their supply chains, customers, and partner networks have also been compromised.

While remediation of compromised systems will vary based on the specific hack, data contact tracing could dramatically shrink the “dwell time”—the period between detection of an attack or compromised system and notification to the world. With the right technologies and techniques, detection could be measured in hours, if not minutes, as opposed to months. Similar to sharing virus data between governments, sharing data between organizations could help stamp out major threats, including ransomware and nation-state attacks.

The world’s scientific community did astonishing work in 2020, compressing what’s typically an eight-year process into just 10 months to develop new COVID-19 vaccines. Now we need a similar marshaling of commitment and resources for data contact tracing, to improve breach response and reporting actionable threat intelligence to the wider IT community. 

While such a vision would require broad cooperation across multiple industries and sectors, the first steps are ones that each company can take for itself immediately and begin with a few simple questions. Those questions include: Within our organizations, can we see how and when every data file is touched? Can we identify the digital trails that data users, authorized or not, leave through our systems? Can we ensure that our software supply chains are sound, and that we are aware of the source and history of every line of code contributed by our developers? When a breach or other anomalous activity is discovered, how quickly can we trace the behavior and identify where access occurred and what data has been compromised?

The technology exists to contact-trace our data and to automate the real-time extraction of insights. It’s used for many things today, from managing IT, software development, and operations to improving customer experience. My own company is involved in helping clients with efforts like these. If we can take smart action on those insights in real time, we should be able to put the same focus and velocity behind protecting our data.

Doug Merritt is the president and CEO of Splunk. Previously, he held senior leadership roles across a wide range of disciplines, including product, sales, marketing, and HR, for companies including Cisco, SAP, and PeopleSoft.

About the Author
By Doug Merritt
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

nido
Commentary250 Years of Innovation
As an immigrant turned entrepreneur and college president, here is why I celebrate our nation as it turns 250
By Nido R. QubeinJune 25, 2026
2 hours ago
Asia’s defense boom is rewiring the global arms supply chain
Commentaryarms, weapons, and defense
Asia’s defense boom is rewiring the global arms supply chain
By Chris OberoiJune 24, 2026
17 hours ago
steve
Commentary250 Years of Innovation
Steve Case: America was built by entrepreneurs. Here’s how we keep that edge for the next 250 years
By Steve CaseJune 24, 2026
1 day ago
t
CommentaryWhite House
Trump mistakes the bully pulpit for bullying leadership — history’s villains were never heroes
By Jeffrey Sonnenfeld and Steven TianJune 24, 2026
1 day ago
mg
CommentaryHealth
The ‘tech neck’ time bomb: why 43 million young Americans could cripple U.S. health care within a generation
By Michael GerlingJune 24, 2026
1 day ago
sb
Commentaryclimate change
The climate policy triangle: why leaders can no longer choose between growth, security and sustainability
By Sebastian BuckupJune 23, 2026
2 days ago

Most Popular

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
1 day ago
The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
Economy
The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
By Jacqueline MunisJune 24, 2026
1 day ago
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
Retail
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
By Nick LichtenbergJune 24, 2026
23 hours ago
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
Asia
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
By Nick LichtenbergJune 24, 2026
1 day ago
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
2 days ago
Trump’s international student crackdown kicked off a domino effect that could shave nearly $500 billion off the economy
Economy
Trump’s international student crackdown kicked off a domino effect that could shave nearly $500 billion off the economy
By Tristan BoveJune 24, 2026
20 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.