Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Security Industry Responds to Massive Equifax Breach

    By
    Sean Michael Kerner
    -
    September 8, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      PrevNext

      1Security Industry Responds to Massive Equifax Breach

      1 - Security Industry Responds to Massive Equifax Breach

      On Sept. 7, credit monitoring and reporting agency Equifax admitted that it was the victim of a massive data breach that revealed personally identifiable information on 143 million U.S. consumers. Based on an initial forensic investigation, Equifax has determined that the attackers had access to Equifax’s systems for a two-month period this year, from mid-May through July. Equifax has provided sparse details on the cause of the breach, other than that it was a web application vulnerability. Security vendors, meanwhile, have been quick to comment and speculate on the root causes of the Equifax breach, as well as to offer their perspective on what Equifax and the victims of the breach should do next.

      2Poor Security Design Continues to Be a Problem

      2 - Poor Security Design Continues to Be a Problem

      “With the personal details of up to 143 million Americans compromised, this breach acts as another reminder about the dangers of poor security design. Too often companies focus on features and functions and layer security on as an afterthought that must change. Hackers and cyber-criminals can quickly exploit any flaw in a web application without too much trouble, and this looks to be the case here.” —Andrew Avanessian, chief operations officer, Avecto

      3Secure Coding Development Practices Are Required

      3 - Secure Coding Development Practices Are Required

      “The breach appears to be related to a website application vulnerability, which could be anything. But this all comes back to sound security development coding practices, active application scanning and testing, and integrating security into the engineering and development processes to make web applications more resilient.” —Chris Pierson, chief security officer, Viewpost

      4Cyber-Security Skills Shortage Means Bug Bounties Are a Must

      4 - Cyber-Security Skills Shortage Means Bug Bounties Are a Must

      “No one is perfect, and everyone is being hacked in some way or another. Financial services have always been attractive targets for criminals, and this trend continues as everything goes online. It’s also not news that the cyber-security industry is facing a severe skills shortage. Teams are typically short-staffed, underfunded and doing the best they can. That’s why it’s so important to open up a channel of communication with the ethical hacker community to help surface critical bugs before they are exploited.” —Marten Mickos, CEO, HackerOne

      5Why Everyone Should Request a Credit Check

      5 - Why Everyone Should Request a Credit Check

      “Once a Social Security number is no longer a valid means of identifying oneself, we have to establish a new, as of yet unknown, order. It’s of utter importance that ALL personal data is protected. In the short term, every American adult should request a credit check and monitor their financial records closely.” —Ebba Blitz, CEO, Alertsec

      6Equifax Hack Is the New Normal

      6 - Equifax Hack Is the New Normal

      “The unfortunate Equifax breach is just another embodiment of the threat environment that organizations face every day—this is the new normal. The rise of large-scale data collection and aggregation has placed considerable pressure on organizations to preserve privacy while leveraging data for legitimate business purposes. The more sensitive the data, the greater the liabilities caused by a breach.” —Dr. Richard Ford, chief scientist, Forcepoint

      7It’s Time to Be Paranoid

      7 - It's Time to Be Paranoid

      “While we don’t yet know the full dimensions of the Equifax breach, where the most sensitive information of over one-third of the American population could have been exposed to cyber-criminals, tens of millions of us are now forced to look over our shoulders for the rest of our lives because tons of Social Security numbers, the skeleton key to our lives, are out there for cyber-criminals to steal and exploit.” —Adam Levin, chairman and founder, CyberScout

      8Equifax Was an Obvious Target

      8 - Equifax Was an Obvious Target

      “The credit bureaus have made mountains of money monitoring Americans credit. The cyber-crime community is well aware that the bureaus house a treasure trove for data theft. It is my feeling that the majority of credit bureaus do not practice what they preach and have underinvested in cyber-security.” —Tom Kellermann, CEO, Strategic Cyber Ventures

      9The Answer Is Not More Credit Reporting

      9 - The Answer Is Not More Credit Reporting

      “Consumers must assume their data is out there and available for sale on the dark web. They’re monitoring their credit because they’ve lost trust in companies to protect the personal data, but the answer isn’t more credit reporting—it’s privacy and security by design.” —Brian Vecci, technical evangelist, Varonis

      10Consider the GDPR Impact

      10 - Consider the GDPR Impact

      “The Equifax breach not only affects nearly half of the U.S. population, it also includes personal data of residents in the UK. If this breach had occurred after May 2018, when the EU’s new General Data Protection Regulation (GDPR) goes into effect, Equifax could have had to pay penalties of up to $120 million (4 percent of global revenues).” —Pravin Kothari, founder and CEO, CipherCloud

      11Breach of the Year

      11 - Breach of the Year

      “Just when we think the days of massive breaches are behind us, another company pops up and says, ‘Here, hold my beer and watch this!’
      All joking aside, this is likely going to be the ‘breach of the year,’ if such awards were handed out. Over 140 million Americans have had their info potentially stolen. That’s over 40 percent of the entire population of the United States.” —Richard Henderson, global security strategist, Absolute

      PrevNext

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×