The timeline was reconstructed in full. Export emailed to a personal account at 9:15 PM on 3 July. Last day and access revoked on 11 July. Personal inbox accessed by an unauthorised party on 13 July, using a password reused from an unrelated breach. First client contacted on the private number in early August. The call that surfaced it reaching the account team at 11:20 AM on 6 August. The breach reported at 3:45 PM the same day.
Thirty-four days between the moment the data left and the moment anyone inside knew to start the clock.
This is what the investigation found. Not as background. As verdict.
No one owned the alarm.
A breach has to be raised the moment it happens — not whenever a customer eventually calls in, confused. The data left on 3 July. The company became aware on 6 August. In between, a resignation had been processed as an HR event: notice, handover, goodbye, access off, file closed. No one was assigned to ask whether a data breach had walked out with the leaver.
No one owned the data.
There was no named person responsible for what customer data could leave the building, or in whose hands. Nobody whose job it was to notice that the entire customer master could be turned into a single file and carried out — or to decide that it shouldn’t be. So the question never got asked, and the habit was never governed.
Nothing guarded the door.
The CRM allowed a bulk export of every record with no limit, no approval step, and no log that anyone read. Nothing stopped that file leaving for a personal inbox. Access was revoked when Dana left — but revoking access to the system does nothing about the copy that already left it.
In the UAE, data protection rules now apply, and the consequences for a breach are no longer hypothetical.
The investigators’ conclusion was the same one that appeared in the reports before it: the person who exported the file was not the problem. The absence of any system around that moment was.
Dana did everything a conscientious professional does. She stayed late to leave a better handover than she’d been given. She used a button the system offered her. She never sold a contact, never misused a record, never intended a thing.
That was the problem — because nothing around her was built to make any of it safe, and nobody had ever told her it wasn’t.
The 3-step protocol the investigators recommended:
1. Make offboarding a data event, not just an HR one. The moment someone gives notice, review and log what they’ve exported, downloaded and emailed — before access is switched off — with a named person who owns that check. A goodbye card is not a data control.
2. Put a limit and an approval on export. No one should be able to turn the whole customer master into a CSV in two clicks with nobody the wiser. Cap bulk exports, require approval for large ones, and keep a log someone actually reads — so an export is a decision, not a reflex.
3. Train the people who live in the CRM. Not a policy handout. Training built around what sales, account management and marketing staff actually do every day — exports, handovers, working from home, “my” client relationships — and the one line UAE data protection law turns on: being allowed to see customer data is not being allowed to take it home.
Dana still works in sales. She knows what to do now. Does your team?
If your organisation needs to close this gap — the training exists, built for exactly this.
training.cybernym.io/login/?tab=demo
Cybernym.io — Cyber Instincts. Built, Not Taught.