Lessons learned from the equifax data breach

Assignment Help Business Management
Reference no: EM132990408

In March 2017, personally identifying data of hundreds of millions of people was stolen from Equifax, one of the credit reporting agencies that assess the financial health of nearly everyone in the United States. As we'll see, the breach spawned a number of scandals and controversies: Equifax was criticized for everything ranging from their lax security posture to their bumbling response to the breach, and top executives were accused of corruption in the aftermath.

The Equifax data breach was one of the largest in history. The company announced the data breach in September 2017, eventually reporting that 147 million consumers were affected. Hackers were able to get access to a multitude of consumer private information, including names, Social Security numbers, dates of birth, credit card numbers and even driver's license numbers.

During the investigation into the breach, Equifax admitted the company was informed in March that hackers could exploit a vulnerability in its system, but failed to install the necessary patches.

A top-level picture of how the Equifax data breach happened looks like this:

The company was initially hacked via a consumer complaint web portal, with the attackers using a widely known vulnerability that should have been patched but, due to failures in Equifax's internal processes, wasn't.

The attackers were able to move from the web portal to other servers because the systems weren't adequately segmented from one another, and they were able to find usernames and passwords stored in plain text that then allowed them to access still further systems.

The attackers pulled data out of the network in encrypted form undetected for months because Equifax had crucially failed to renew an encryption certificate on one of their internal security tools.

Equifax did not publicize the breach until more than a month after they discovered it had happened; stock sales by top executives around this time gave rise to accusations of insider trading.

Equifax's IT department ran a series of scans that were supposed to identify unpatched systems on March 15; there were in fact multiple vulnerable systems, including the aforementioned web portal, but the scans seemed to have not worked, and none of the vulnerable systems were flagged or patched.

While it isn't clear why the patching process broke down at this point, it's worth noting what was happening at Equifax that same month, according to Bloomberg Businessweek: Unnerved by a series of incidents in which criminals had used Social Security numbers stolen from elsewhere to log into Equifax sites, the credit agency had hired the security consulting firm Mandiant to assess their systems. Mandiant warned Equifax about multiple unpatched and misconfigured systems, and the relationship devolved into in acrimony within a few weeks.

What happened to Equifax after the data breach?

As part of the legal settlement agreement, Equifax paid $175 million in civil penalties to states, and a $100 million fine to the Consumer Financial Protection Bureau.

What, ultimately, was the Equifax breach's impact? Well, the upper ranks of Equifax's C-suite rapidly turned over. Legislation sponsored by Elizabeth Warren and others that would've imposed fines on credit-reporting agencies that get hacked went nowhere in the Senate.

That doesn't mean the Equifax breach cost the company nothing, though. Two years after the breach, the company said it had spent $1.4 billion on cleanup costs, including "incremental costs to transform our technology infrastructure and improve application, network, [and] data security." In June 2019, Moody's downgraded the company's financial rating in part because of the massive amounts it would need to spend on Infosec in the years to come. In July 2019 the company reached a record-breaking settlement with the FTC, which wrapped up an ongoing class action lawsuit and will require Equifax to spend at least $1.38 billion to resolve consumer claims.

Instructions

a. What are the top 3 lessons learned from the Equifax data breach?

b. What 3 things should Equifax done immediately after learning about the hack?

c. If you were in Equifax senior management what post-mortem activities and processes would you put in place?

Reference no: EM132990408

Questions Cloud

How much will be worth in seven years : How much $257,000 will be worth in 7 years, when he will reach age sixty, in case he decides to retire early, assuming the funds can be invested
What amount would bristol estimate and record : What amount would Bristol estimate and record for the current period of bad debt expense as a percentage of current period sales
What effect do the gains have on brandon tax liability : Brandon, an individual, began business four years ago and has sold §1231 assets. What effect do the gains and losses have on Brandon's tax liability?
Employee matching contributions : Which of the following is a socially responsible activity that could include corporate/employee matching contributions?
Lessons learned from the equifax data breach : In March 2017, personally identifying data of hundreds of millions of people was stolen from Equifax, one of the credit reporting agencies that assess the finan
What effect do the gains have on brandon tax liability : Brandon, an individual, began business four years ago and has sold §1231 assets. What effect do the gains and losses have on Brandon's tax liability?
Analyzed improve processes : What are some of the critical success factors within the healthcare industry that can be analyzed to improve processes?
Determine their qualified business income deduction : Tom and Anne Marie are married taxpayers who file a joint return. Determine their qualified business income deduction for 2018
Interaction between genes and the environment : The study of genomics is helping clinicians to understand better the interaction between genes and the environment.

Reviews

Write a Review

Business Management Questions & Answers

  Insert a bootstrap component into an html page

1. Make a hw8 folder. This folder should contain all files for this assignment. Make an html file and save it to your folder.

  Describe what types of control systems they had in place

Think of your current or previous employer, and describe what types of control systems they had in place. In your opinion, are they the right ones?

  Target market segment

Who is your target market? Develop a full target market segment for your business plan.

  Write in an essay - mastering change management

Conclude the key points and reasons identified during the critical evaluation - Write in an essay format - Mastering Change Management

  Find five draft copies of our proposed licensing agreement

As per our conversation, enclosed please find five draft copies of our proposed licensing agreement. We believe this agreement fully reflects our mutual understanding. Please return four signed copies of the agreement and keep one for your records..

  Think of some goals and objectives

Think of some goals and objectives that might be created for an organisation you are familiar with (it could be anything from a bank

  Generating random data that follows a distribution

A primary deliverable for this course will be a group-based analytics project proposal in which you will address some business question that can be answered

  Explain the key benefits of creating such policies

Assignment: Keys to Success in Multinational Companies- Explain the key benefits of creating such policies. Provide a rationale for your response.

  How is vision used to confront resistance to change

How is vision used to confront resistance to change, and move through it?

  Internet as a distribution channel

Avatars are virtual characters that can be used as representatives of a company that is using the Internet as a distribution channel.

  Adjoining state overview for comparison

If you were sitting on the President's council for probation and parole reform, what four (4) recommendations would you make to increase the success of probation and parole in the United States? Give your rational for each recommendation.

  Development of emotional intelligence

Evaluate the improvement in the development of emotional intelligence for two of your workers

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd