THE CYBER-SAFETY ZONE: Tip #2 Thoughts on the Equifax Data Breach

Have a question for our cyber-security expert Joseph Koval? Email: editor@rocklandcountytimes.com and weโ€™ll pass the question along.

BY JOSEPH KOVAL

Everyone shouldย know all too well, itโ€™s not a matter of IF but rather a matter of WHEN a network will be compromised. ย Our personal identifying information (PII) is a โ€œhigh valueโ€ target to hackers. The recent Equifax hack where over 145,000,000 people had their PII (Personal Identifying Information)ย stolen is a perfect case study. This cyber-attack shines a spotlight on the mistakes that were made by Equifax.

Time-line reported by USA Today:

Mid-May to July 2017 –ย Criminal hackers carry out an attack and infiltration of Equifax servers. It resulted inย unauthorized access to the personal information of nearly 44 percent of the U.S. population.

Sept. 7ย –ย Breach publicly announced.

Sept. 8ย –ย Equifax shares plunge 13.7 percent in first day of trading after breach announced.

Sept. 12ย –ย Equifax announcesย two senior computer security executivesย at the company are retiring.

Sept. 12ย –ย Equifaxย CEO apologizes in USA TODAYย op-ed.

Sept. 11ย –ย Sen. Orrin Hatch, R-Utah, who chairs the Senate Committee on Finance, and Sen. Ron Wyden, D-Oregon, the panel’s ranking minority member,ย ask the credit-reporting giant for a timeline of the breach, along with details of Equifax’sย efforts to quantify the scope of the intrusion and limit consumer harm.

Sept. 15ย –ย Equifax announcesย its chief information officer, Susan Mauldin, and chief security officer, David Webb are retiring “effective immediately.”

Sept. 21ย –ย Equifax admits it sentย victims of the data breach to a bogus websiteย that shared a similar address to the one it set up to help victims.

Sept. 26ย –ย Equifax announces itsย CEO, Richard Smith, retires.ย Paulino do Rego Barros, Jr., a seven-year veteran of the company, is appointed interim Chief Executive Officer.

MISHANDLING OF INCIDENT

1 โ€“ A known vulnerability in their web software was left unpatched for two months.ย  There were numerous announcements concerning this vulnerability and security patches made available to remediate the software vulnerability but the company took no action.

2 โ€“ The company failed to announce the hack in a timely manner.

3 โ€“ Several high ranking managers made large sales of their company stock just prior to the announcement.ย  The SEC is currently investigating.

4 โ€“ If there were policies in place that governed a responsible and effective response to the hack were they followed?ย  Did policies even exist?

5 โ€“ Were all safeguards in place and updated with the latest threat management software?

6 โ€“ Any entity that has electronic records containing PII, or any other valuable data, needs to have network vulnerability and penetration testing done on a regular basis.ย  If Equifax had run regular penetration and vulnerability tests they would have detected the vulnerability in their web software and patched it immediately.

THE LATEST EQUIFAX NEWS

Equifax told the US Senate Banking Committee that more data may have been exposed:ย ย Hacking News reports:

Equifax spokesperson Meredith Griffanti told Newsย Fridayย that the initial list of vulnerable personal data was never intended to serve the full list of potentiality presented information.

The new documents quickly bring Equifaxโ€™s credibility into even further problem following numerous other damaging announcements, including a malware-infested website, executives who dumped stock after the company noticed the hack, and the news the business was warned months before about security vulnerabilities and did nothing.”

Whether you are a large corporation, a small to medium business, government, or just a home with PCโ€™s, laptops, smartphones, etc. you need to take due diligence and secure your electronic assets.

At a recent North Rockland Chamber event an owner of a local business asked me, โ€œI only have two PCโ€™s and a couple of smartphones that connect to my business network.ย  Do I need a threat assessment?โ€ย  My answer was, โ€œif you turned on your computer one morning and the screen had a message saying all of your business files have been encrypted and a bitcoin ransom was demanded and you couldnโ€™t access your customer data, invoicing, etc. what would you doโ€?ย  His eyes widened and he understood that no business or personal network is too small for cyber security planning.

My future articles will cover many cyber security steps for you to take:ย human, physical, endpoint, network application and data.

Joseph Koval is the owner and president of Syber3 โ€“ Syber Security Solutions located in Rockland County. He has over 27 years of Cyber Security experience and project management. Check out his web site:ย www.syber3.comย and Syber3 Facebookย 

You must be logged in to post a comment Login