Homepage / Technology / Three big lessons we all need to learn from the Equifax data breach
Mostbet İncelemesi 2024 » Spor Bahisleri, Giriş & Oyunla Başkanın ilk icraatı işçi kıyımı olmuştur! 719 7slots kumarhane 90 Business Online Solutions What Is a Board Analysis? The Importance of Planning and Programs Development How Board Governance Software Improves Meetings and Governance How to Craft a Successful Board Meeting Reminder Benefits of a Virtual Data Room for Bankruptcy VDR Example for Business Hong Kong ユースカジノの登録方法を初心者にも分かりやすく図解入りで解説 チェリカジ 5 Как быстро пополнить счет в Казино Х в любой валюте Официальный сайт Up X казино и мгновенные игры Paşa Casino Mobil Uygulama 2025 Giriş Üyelik Bonusu Freespin No Deposit Bonus Casino Free Spins In New Zealand What Are The Best Online Casinos For Real Money Pokies And Bonuses In Australia Дэдди Казино официальный сайт Джойказино: информация про официальный сайт Glory Casino giriş için buraya tıkla ve Türkiyede en popüler casino kullanıcısı ol Les Gambling establishments en Ligne en France 2024 200% Reward + 300 Free Rotates LevelUp Internet casino Melbourne En İyi ve Güvenilir Casino Siteleri Canlı Casino Siteleri 2023 Listesi En İyi ve Güvenilir Casino Siteleri Canlı Casino Siteleri 2023 Listesi Le meilleur casino en ligne franзais Extra Casino avec le dйpфt minimal le in addition bas Yeni Casino Siteleri ᐈ Çevrimiçi Kumarhaneler Mart 2024 Les gambling establishments en ligne proposent une grande variйtй de jeux de internet casino gratuits. Türkiye’deki Resmi Web Sitesi Google Play, Türkiye’de kumar oyunlarına izin verecek Her Gün Tatil Olsa ORDU’DA PAZARTESİ GÜNÜ FINDIK FİYATI NASIL? كازينو اون لاين الكازينوهات الممتازة على الإنترنت ألعاب الكازينو المباشرة مينا كازينو العر Google Play, Türkiye’de kumar oyunlarına izin verecek Domain Sorgulama & Domain Fýrsatlarý Canlı Casino Siteleri: 2024 Güvenilir Siteler Seçilmiştir Golden Easter Slot İncelemesi 2024, Demoyu Ücretsiz Oynayın Golden Easter Slot İncelemesi 2024, Demoyu Ücretsiz Oynayın 1xbet Türkiye Giriş Empieza Kayıt 202 Kumar Ve Kumarhaneler Hakkında Pek İlginç 21 Bilgi Kumarhane Doğru Yazımı Nedir? Tdk Ile Kumarhane Kelimesinin Doğru Yazılışı! Mobilbahiste En İyi Kumar Bonusları Ve Kazançlar Mobilbahis Giriş Sayfası On Line Casino Siteleri En Iyi Casino Siteleri 2024 Mostbet: Türkiye’de Internet Casino Mostbet Online Slotlar Ve Canlı-casin Pin Up Casino Oyna Türkiye, Pinup’un Sah Web Sites Ifade Haberleri Son Dakika Ifade Hakkında Güncel Haber Ve Bilgiler “önceliğimiz Transferin Önünü Açmak, Görüştüğümüz Yerler Var” On Line Casino Nuh’un Gemisi Deluxe Resort & Spa, Kıbrıs The Benefits of Document Management Bonus Veren Siteler 3 000 Den Fazla Online Oyunu Ücretsiz Oyna En Tehlikeli Kumar Oyunu Ekşi Sözlük Deneme Bonusu Veren Siteler Deneme Bonusu 2024 Explore the Magic of WildCardCity Güvenilir Bahis Siteleri En İyi Kumar Siteleri Balıkesir Triatlonuna Avrupadan Ödül Tricks of the Aviator gambling establishment game by Spribe Çevrim Içi Kumar Siteleri “bonus” Yalanıyla Kandırıyor En Güvenilir Canlı On Line Casino Siteleri Xbetting-tips Com Uncovering the Abundant Tapestry of Ozwin Gambling establishment Evaluating Board Portal Providers Uncovering the Wealthy Tapestry of Ozwin On line casino Electronic Data Area Providers Evaluation Cobra Internet casino: Raising the Australian On the internet Video gaming Practical experience 4 Things to Search for in Safeguarded Cloud Safe-keeping Fastpay On line casino Australia – Simple and No-Taxation Wagering Web page officielle franзaise de Joka Gambling establishment The Software Development Universe Game Woo Internet casino – Enjoy Slot machine games around australia Ostdeutsche Biersorten What Are Virtual Data Rooms? Vitamin D Receptor Polymorphisms Revue du Casino BlackLabel Faktory, kterй ovlivnujн hodnocenн ceskэch online kasin How to Make the Most of Your Web Development Organization and Advertising Efforts L’essor des casinos en ligne en France Boost Meeting Efficiency With Boardroom Technology Developments WildJoker Casino WildCardCity On line casino – Guaranteed Australian Gambling Portal New Post WildCardCity Casino – The Ideal On the internet Gambling establishment within australia Modern Technologies Produce Sharing Documents Online Faster and More Protect Free Virtual Info Room pertaining to Speedy Due Diligence A Review of Data Area Software For people who do buiness Five Board Bedroom Features Which will help You Acquire a More Productive Boardroom Electronic Systems To your Business Understanding Legal Terms and Laws in Today’s World The Laws and Contracts of Hollywood: A Sunset Blvd. Tale Legal Discussion Between Johnny Cash and Antonin Scalia Legal Insights: What Teens Should Know Legal Issues and Exceptions: What You Need to Know Legal Insights and Expert Analysis Celebrity Dialogue: Legal Matters in the 21st Century Famous Personalities Discuss Legal Issues The Boys in the Boat: Legal Advisors and The Quest for Legal Knowledge Understanding Legal Matters: Q&A on Criminal Law, Joint Ventures, and More Enticing Title The Departed: Understanding Basic Work Requirements and Legal Rights Youth Slang Blog Article Legal Insights: A Journey into the World of Law The Ins and Outs of Legal Matters: Everything You Need to Know

Technology

Three big lessons we all need to learn from the Equifax data breach

We’ve all seen the news reports, again and again:

A massive breach has occurred. Many millions of customer records have been obtained by hackers. The company in question has flubbed the response to the incident. Wall Street is punishing the company, and the stock has plummeted since the breach was reported.

That opening to articles on almost-daily cyber crises has become all too familiar. The recent incident involving Equifax, the U.S. credit-reporting company, is particularly egregious and may make it seem as if every attempt to secure our data and personal information is doomed to failure.

However, our failures do not come solely from technology and its misuse, but rather from a mindset that, unless we change it, will force us into the same mistakes time and again. These breaches are a failure of leadership and culture as much as they are failures of network security.

In order to secure our personal information and networks, we need to recognize that privacy and security are not opposites, but rather they support each other and our economy and society. We need to understand that notifying customers about breaches is a vital part of ensuring security and privacy. And, finally, we must recognize the role that government representatives, and the policy choices they make, should play in this entire system.

First, security is often incorrectly framed as a choice between security and privacy. In recent years, whether it is the debate on government’s collection of metadata or law enforcement’s increasing insistence on access to encrypted data, we are asked to choose sides between privacy versus security.

The Equifax incident unambiguously refutes that way of looking at things: privacy depends on security, and vice versa. In the Equifax case, the privacy of 143 million customers was clearly violated — and that breach of privacy introduced the potential for further, cascading breaches, where security is based on those exposed details, such as social security numbers and other sensitive personal information.

Better security undoubtedly leads to greater privacy protection for consumers whose data is aggregated by companies. And a greater emphasis on privacy helps create a culture that values security and is willing to put forth the effort to ensure it. We should learn that security isn’t an end in itself, but rather a mechanism to protect important values, one of which is privacy.

Second, timing is key when notifying stakeholders after a breach. To the consternation of many observers, Equifax discovered that its systems had been breached on July 29 and reported it more than a month later, on September 7. By way of comparison, proposed European regulations mandate breach notification within 72 hours, while allowing explanation by the notifying party in case of any delays.

Notification shouldn’t be arbitrary or an afterthought. The key question that should determine the length of time a company has to report a breach is the following: Would cyber incident damages be reduced more by allowing a company time to provide an organized response, or by allowing affected individuals to act earlier in a decentralized fashion? In the Equifax case, the extended period of time seems to have been unwarranted. After all, the company website established to ostensibly assist affected individuals has been plagued by accusations of inaccuracy and insecurity.

It’s important to note that this is not just a problem between companies and customers or citizens. Notification is no better within many enterprises generally. A recent survey found that nearly 40 percent of U.S.-based, in-house attorneys and general counsel fail to disclose security issues to their board. In such cases, failure of clear governance makes companies — and everyone who connects to them through a network — far less secure.

Regardless of timing, pre-set processes by which companies notify customers of a breach should be part of their post-breach responsibilities. If companies are expected to provide guidance on how to deal with the aftermath, then they should prepare guidance beforehand or within a reasonable period post-breach (and held to account for their inability to provide guidance). At the same time, in order for an enterprise to ensure that its cyber-resilience strategy is effective, there need to be clear rules and timelines for managers to share information with company leaders.

Third, the government’s role in the wake of a breach needs to be more clearly defined. The immediate aftermath of a breach usually centers (generally unhelpfully) on assigning culpability rather than focusing on the victims or on creating policies that would prevent breaches.

The U.S. (like other governments) made a policy choice to give organizations principal responsibility for responding to cyber attacks. Governments, as in other national security matters, could assume principal responsibility themselves or could develop a policy to share responsibility among key stakeholders.

But even as organizations are held responsible, the government’s duty to assist these organizations remains ambiguous. Governments have technical expertise as well as emergency response capabilities that do not have a clear trigger in the current policy environment. At the very least, clear rules and lines of responsibility would help to create reasonable expectations around cyber defense for the private sector.

As cyberattacks continue to increase, the Equifax breach will soon be seen as unexceptional. What will remain exceptional is a culture and policy posture that labors under a dangerous black-and-white assumption where privacy is pitted against security.

Over the past 20 years, there have been ever greater “calls to arms” to tackle cyber security. And yet billions of dollars of market value have evaporated owing to cyber incidents in the last year, not to mention the consumer impact.

That status quo is not sustainable.

Commentary by Daniel Dobrygowski and Walter Bohmayr.

Daniel Dobrygowski, lead for Trust and Resilience, World Economic Forum, is an attorney based in the U.S. whose practice and research includes privacy, security, intellectual property, and regulatory and competition law. He leads the World Economic Forum’s efforts on trust and resilience, focusing on cyber resilience and digital identity, in its system initiative on Shaping the Future of the Digital Economy and Society.

Dr. Walter Bohmayr is a senior partner in the Vienna office of The Boston Consulting Group. He is the global leader for cybersecurity and IT risk, and a member of BCG’s internal Risk and Audit Committee.

Source: Tech CNBC
Three big lessons we all need to learn from the Equifax data breach

Comments are closed.