Equifax Security 2017 Continuous Loop 2018

Chang. Liebel. Sanghi. Wang

Equifax Inc, a controversial incumbent in the credit risk assessment industry, realized success quickly after its foundation as Retail Credit Company (RCC) in Atlanta, Georgia in 1899. Soon after the turn of the century, RCC became one of the largest credit bureaus in the nation attracting considerable criticism for their willingness to sell extensive consumer information on millions of American and Canadian citizens to insurance companies.1 As technology developed and RCC transitioned its records into a computer-based system, the availability of personal information to the public made individuals vulnerable to the negligent inclusion of inaccurate information on their credit reports. This led to the enactment of the Fair Credit Reporting Act in 1970 and RCC's name change to Equifax to enhance and reform its image.

In recent times, Equifax has expanded from strictly a business to business (B2B) model to include a business to consumer (B2C) model; the company not only aggregates demographic and credit related data for over 88 million businesses and 800 million consumers worldwide, but also sells credit monitoring and fraud-prevention services to consumers.2 The sheer volume of data the company is responsible for protecting made the September 2017 cyber-security breach one of the top five largest data breaches in history. The hackers behind the cyber-security breach were able to access data on an estimated 145.5 million Americans, exposing everything from their addresses and birth dates to their social security numbers and drivers licenses.3 The leak of this sensitive information to criminals arguably makes this data breach more severe than larger reported attacks such as the breach on Yahoo! in 2013.

The Equifax breach, therefore, illuminated two outstanding issues that need be addressed in an effort to thwart future cyberattacks. First, that there is a current lack of cybersecurity protocols and standardization from state to state legislature and second, the role of the government in security breaches is ambiguous. 4 5 For these reasons, this paper will discuss the impact from the breach to argue that the government should issue unifying national legislature surrounding cybersecurity and share the responsibility of cyber defense to create realistic expectations for the private sector. 6

The Equifax breach immediately caused an increase in simple crimes such as credit card fraud and identity theft, but there were also larger resounding impacts.7 A company such as Equifax is not abnormal in today's society, many companies store millions of data lines on the personal information of their customers. A sense of trust must be maintained such that consumers know that their lives are essentially protected. Suddenly with this breach, millions of consumers had everything about their identities exposed to the internet. Customers started to doubt what companies and services they can trust to keep them safe and in essence, the U.S. economy could now be compromised. Analysts have described that a breach this influential can cause permanent damage to the credit reporting system, banking system, and even detrimentally impact the global economies in general.8

Unfortunately, beyond just the impact that customers felt from this breach, similar online companies that handle consumer data have also been affected. Equifax itself lost around $4 billion dollars not only from lost business and regulations, but actual crisis management costs as well.9 Some of its competitors, like TransUnion and Experian, faced similar losses though their companies experienced no breach. The Equifax breach did not only cause consumers to lose trust in them, but in other data handling companies as well; as a result, investors panicked in the face of the breach, leaving the public apprehensive. Overall, power associated with big data is a tangible concept and trust is the foundation on which these companies function. With personal data, it is critically important to know what companies are keeping data safe and, since the Equifax breach, consumers are skeptical with how they protect their private information.

Currently, security breach notification laws and cybersecurity legislation vary from state to state and, in some cases, are non-existent (i.e. Alabama and South Dakota).10 These notification laws specify what constitutes as personal information, how and when the public need to be notified, and exact definitions for what is a breach as well as exceptions.11 For instance, Under AS 45.48.010, Alaska's notification law allows information collectors to delay the disclosure of the breach if "disclosing the breach will interfere with a criminal investigation."12 On the other hand, under the 2003 Notice of Security Breach Act, the State of California requires any company that maintains personal information such as name, social security number, driver's license details or financial information to immediately notify the public when a cybersecurity breach has taken place. The inconsistency in cybersecurity legislation and notification laws among states not only blur the role of the government amid security breaches, but also increases the prospect of future data breaches.

The Equifax cyberattack has shone a spotlight on the need for strict and effective policies on data management that are standardized across industries and states. Three key lessons can be learned from the Equifax breach that could help prevent and mitigate the impact of future data breaches. First, the importance of patch management. In the Equifax case, "an externally facing web application system was not fully patched" and have allowed hackers to access sensitive data.13 The vulnerability in the system could have been detected sooner if Equifax had a designated system in place to track when updates from Apache Software Foundation were released. Similarly, Equifax could implement techniques, such as "Hot Patching," to update their application without temporarily shutting down their system. With such organized and timely systems in place, Equifax will be able to continuously track loopholes in their system and, thus, secure its data warehouse from hackers.

Second, regulation of information sharing between organizations. Organizations share large amounts of data with their partners and third parties involved in their operations.14 Often these data are sent over standard communication lines and accessed through shared databases. These practices exposes the security of the data as in many cases the third party's cyber security system are not up to par. Furthermore, both organizations and the government should be more vigilant about sharing data between organizations by limiting access, requiring third parties to have a higher level of cybersecurity standards, and legally regulating the sharing of sensitive data such as personal identification information.15

Third, clear definition of government role amid data breach. The Equifax incident demonstrated that the impact of irresponsible corporate management is no longer confined to the company itself, but has far reaching negative repercussions that affect public security. Therefore, governments should assume principal responsibilities and develop standardized policies which should be clearly defined and strictly reinforced, especially among companies that store sensitive data. These government policies can take the form of patch cycle regulation, data management inspection, and standardization of notification laws.

In an increasingly technologically dependent world, cybersecurity breaches are becoming more prevalent and detrimental to our society than ever (Appendix A., Appendix C.). Although the Equifax data breach incident is one of many, it is unique due to the nature of the information exposed rather than the volume of the data leaked. This incident has challenged people's trust in private companies' ability to secure data, which is inherently the foundation of businesses such as Equifax. Their breach highlighted the importance of extending government regulations on data protection and the adoption of cybersecurity best practices. Private data collection companies should review and update their current systems and protocols that are in place and work to improve decision making processes. Likewise, the government should clearly define their role in the cybersecurity domain. Moving forward, the increasing need for personal data storage systems is inevitable and, as such, consumers should prioritize companies that value their security needs over business strategy.

Appendix A

Appendix B

Appendix C

Appendix D

Works Cited

Bohmayr, Daniel Dobrygowski and Walter. "Three Big Lessons We All Need to Learn from the Equifax Data Breach." CNBC, CNBC, 20 Sept. 2017, www.cnbc.com/amp/2017/09/20/cybersecurity-lessons-from-equifax-data-breach--commentary.html

"Cybersecurity Legislation 2017." National Conference of State Legislature, NCSL, 29 Dec. 2017, http://www.ncsl.org/research/telecommunications-and-information-technology/cybersecurity-legislation-2017.aspx.

CyberWire Staff. "The Equifax Breach: Consequences, Implications, and Sequelae." TheCyberWire, Pratt Street Media, 20 Sept. 2017, www.thecyberwire.com/articles/the-equifax-breach-consequences-implications-and-sequelae.html.

"Equifax 2017 Data Breach: A Meticulous Timeline." Equifax Data Breach Timeline |Csrps.com - CSRPS, CSR Professional Services, 2017, csrps.com/meticulous-timeline-equifax-data-breach.

"Equifax." Wikipedia, 13 Feb. 2018, en.wikipedia.org/wiki/Equifax.

Fickenscher, Lisa. "Credit Card Fraud Spikes after Equifax Cyber-Attack." New York Post, New York Post, 8 Sept. 2017, nypost.com/2017/09/08/credit-card-fraud-spikes-after-equifax-cyber-attack.

Hackett, Robert. "Huge Equifax Hack Is Even Bigger Than First Thought." Fortune, 2 Oct. 2017, fortune.com/2017/10/02/equifax-credit-breach-total/.

Knutson, Chad. "Equifax Lessons Learned." SBS CyberSecurity, 9 Oct. 2017, sbscyber.com/resources/article-equifax-lessons-learned.

Lim, Paul J. "Equifax Hack: The Stock Lost Nearly $4 Billion in the Crisis | Money." Time, Time, 12 Sept. 2017, time.com/money/4936732/equifaxs-massive-data-breach-has-cost-the-company-4-billion-so-far/.

Reuters. "Equifax Warns About Impact of Data Breach on Its Business." Fortune, 10 Nov. 2017, fortune.com/2017/11/10/equifax-warns-data-breach-business/.

Reuters, Thomson. "Biggest Online Data Breaches Worldwide 2017 | Statistic." Statista, Oct.2017, www.statista.com/statistics/290525/cyber-crime-biggest-online-data-breaches-worldwide.

"Security Breach Notification Laws." National Conference of State Legislature, NCSL, 6 Feb. 2018, www.ncsl.org/research/telecommunications-and-information-technology/security-breach-notification-laws.aspx.

"What can Others Learn in the Wake of the Equifax Breach?" Trend Micro, 19 Sept. 2017, www.trendmicro.com/vinfo/us/security/news/cyber-attacks/what-can-others-learn-in-the-wake-of-the-equifax-breach.

romanwhatind.blogspot.com

Source: https://www.linkedin.com/pulse/equifax-data-breach-analysis-teresita-c-liebel

0 Response to "Equifax Security 2017 Continuous Loop 2018"

Post a Comment

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel