Lessons learned from the equifax data breach

Assignment Help Business Management
Reference no: EM132986337

Equifax Data Breach

In March 2017, personally identifying data of hundreds of millions of people was stolen from Equifax, one of the credit reporting agencies that assess the financial health of nearly everyone in the United States. As we'll see, the breach spawned a number of scandals and controversies: Equifax was criticized for everything ranging from their lax security posture to their bumbling response to the breach, and top executives were accused of corruption in the aftermath.

The Equifax data breach was one of the largest in history. The company announced the data breach in September 2017, eventually reporting that 147 million consumers were affected. Hackers were able to get access to a multitude of consumer private information, including names, Social Security numbers, dates of birth, credit card numbers and even driver's license numbers.

During the investigation into the breach, Equifax admitted the company was informed in March that hackers could exploit a vulnerability in its system, but failed to install the necessary patches.

A top-level picture of how the Equifax data breach happened looks like this:

  • The company was initially hacked via a consumer complaint web portal, with the attackers using a widely known vulnerability that should have been patched but, due to failures in Equifax's internal processes, wasn't.
  • The attackers were able to move from the web portal to other servers because the systems weren't adequately segmented from one another, and they were able to find usernames and passwords stored in plain text that then allowed them to access still further systems.
  • The attackers pulled data out of the network in encrypted form undetected for months because Equifax had crucially failed to renew an encryption certificate on one of their internal security tools.
  • Equifax did not publicize the breach until more than a month after they discovered it had happened; stock sales by top executives around this time gave rise to accusations of insider trading.

Equifax's IT department ran a series of scans that were supposed to identify unpatched systems on March 15; there were in fact multiple vulnerable systems, including the aforementioned web portal, but the scans seemed to have not worked, and none of the vulnerable systems were flagged or patched.

While it isn't clear why the patching process broke down at this point, it's worth noting what was happening at Equifax that same month, according to Bloomberg Businessweek: Unnerved by a series of incidents in which criminals had used Social Security numbers stolen from elsewhere to log into Equifax sites, the credit agency had hired the security consulting firm Mandiant to assess their systems. Mandiant warned Equifax about multiple unpatched and misconfigured systems, and the relationship devolved into in acrimony within a few weeks.

What happened to Equifax after the data breach?

As part of the legal settlement agreement, Equifax paid $175 million in civil penalties to states, and a $100 million fine to the Consumer Financial Protection Bureau.

What, ultimately, was the Equifax breach's impact? Well, the upper ranks of Equifax's C-suite rapidly turned over. Legislation sponsored by Elizabeth Warren and others that would've imposed fines on credit-reporting agencies that get hacked went nowhere in the Senate.

That doesn't mean the Equifax breach cost the company nothing, though. Two years after the breach, the company said it had spent $1.4 billion on cleanup costs, including "incremental costs to transform our technology infrastructure and improve application, network, [and] data security." In June 2019, Moody's downgraded the company's financial rating in part because of the massive amounts it would need to spend on Infosec in the years to come. In July 2019 the company reached a record-breaking settlement with the FTC, which wrapped up an ongoing class action lawsuit and will require Equifax to spend at least $1.38 billion to resolve consumer claims.

Instructions 

a. What are the top 3 lessons learned from the Equifax data breach?

b. What 3 things should Equifax done immediately after learning about the hack?

c. If you were in Equifax senior management what post-mortem activities and processes would you put in place?

Reference no: EM132986337

Questions Cloud

Should US taxpayers nationwide share in the risks : Should U.S. taxpayers nationwide share in the risks of those who choose to live and work in areas known to be at risk for hurricanes, earthquakes, flooding, etc
Determine the maximum itemized deduction allowable : They expect to receive an additional reimbursement of $2,000 in February 2021. Determine the maximum itemized deduction allowable
How much does each have before earning the dollar five : Bessy has 9 times as much money as bob, but when each earns $5, bessy will have 4 times as much as bob. How much does each have before and after earning the $5?
What is brady net income from the property : What is Brady's net income from the property and what type and amount of expenses will he carry forward to next year, if any
Lessons learned from the equifax data breach : In March 2017, personally identifying data of hundreds of millions of people was stolen from Equifax, one of the credit reporting agencies that assess the finan
Calculate the opening capital amount at the commencement : D Lee commenced business on 1 September 2011. Calculate the opening capital amount at the commencement of the business to balance the accounting equation.
What is goodfellows gross profit during the second year : Assuming the $1,000,000 worth of 8 percent mortgage loans are still outstanding, what is Goodfellows' gross profit during the second year?
Promote healthy habits in childhood : The rates of obesity are continuing to rise in this country. Discuss how nutrition, sleep, growth rates, and exercise all interact to promote healthy living. Ho
Calculate the pay out ratio indicator : Calculate the Pay out ratio Indicator. (Mandatory use two decimal places (.)) Calculate Earnings per Share. (Mandatory use of 2 decimal places (.))

Reviews

Write a Review

Business Management Questions & Answers

  Caselet on michael porter’s value chain management

The assignment in management is a two part assignment dealing 1.Theory of function of management. 2. Operations and Controlling.

  Mountain man brewing company

Mountain Man Brewing, a family owned business where Chris Prangel, the son of the president joins. Due to increase in the preference for light beer drinkers, Chris Prangel wants to introduce light beer version in Mountain Man. An analysis into the la..

  Mountain man brewing company

Mountain Man Brewing, a family owned business where Chris Prangel, the son of the president joins. An analysis into the launch of Mountain Man Light over the present Mountain Man Lager.

  Analysis of the case using the doing ethics technique

Analysis of the case using the Doing Ethics Technique (DET). Analysis of the ethical issue(s) from the perspective of an ICT professional, using the ACS Code of  Conduct and properly relating clauses from the ACS Code of Conduct to the ethical issue.

  Affiliations and partnerships

Affiliations and partnerships are frequently used to reach a larger local audience? Which options stand to avail for the Hotel manager and what problems do these pose.

  Innovation-friendly regulations

What influence (if any) can organizations exercise to encourage ‘innovation-friendly' regulations?

  Effect of regional and corporate cultural issues

Present your findings as a group powerpoint with an audio file. In addition individually write up your own conclusions as to the effects of regional cultural issues on the corporate organisational culture of this multinational company as it conducts ..

  Structure of business plan

This assignment shows a structure of business plan. The task is to write a business plane about a Diet Shop.

  Identify the purposes of different types of organisations

Identify the purposes of different types of organisations.

  Entrepreneur case study for analysis

Entrepreneur Case Study for Analysis. Analyze Robin Wolaner's suitability to be an entrepreneur

  Forecasting and business analysis

This problem requires you to apply your cross-sectional analysis skills to a real cross-sectional data set with the goal of answering a specific research question.

  Educational instructional leadership

Prepare a major handout on the key principles of instructional leadership

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd