sb-eu logo
Story image

Equifax data breach: The end of cybersecurity as we know it

15 Sep 2017

Article by Gartner analyst, John A. Wheeler

As most everyone knows by now, one of the single largest data breaches in history was disclosed last week by the credit reporting giant, Equifax. While most people are rightly focused on the immediate impacts of this breach – personal fraud, credit and identity protections, waivers of right to sue, class-action lawsuits, etc. – few have considered the longer term implications of this event. So, here are three predictions of how the cybersecurity world will change in light of this monumental event.

1. Bankruptcy looms ahead for Equifax

In the last 4 business days since the company disclosed the data breach, Equifax has suffered a $5.3 billion loss in market capitalisation which represents almost a third of the company’s total value.

When considering an estimate of the potential costs associated with the data breach (based on the 2017 IBM/Ponemon Institute Cost of Data Breach Study), Equifax faces a potential loss of $20.2 billion which currently exceeds their total market value by $8.3 billion.

Also, the company currently faces more than 23 class-action lawsuits with at least one seeking more than $70 billion in damages. The death spiral will soon take on greater momentum when executives are required to testify before Congress and criminally investigated for potential insider trading related to the delayed disclosure of the data breach.

Equifax will ultimately be acquired out of bankruptcy by one of the remaining two credit reporting companies – TransUnion or Experian.

2. Social Security Number will be replaced by a more secure National ID

The use of Social Security Numbers (SSN) as the primary authentication device for US citizens will be eliminated. What will replace the SSN is anyone’s guess, but it can no longer serve in this capacity since at least half of the nation’s primary method of authentication has been compromised. Perhaps the US will follow Estonia’s lead in creating a true electronic national ID?

3. A federal cybersecurity act will be passed quickly

Attempts at passing federal legislation over cybersecurity have been futile in the past, but all of that will change. Similar to what happened in the aftermath of the Enron and Worldcom accounting frauds, broad reaching legislation will be crafted and passed much like the Sarbanes Oxley Act of 2002.

This will occur because the impact of the Equifax breach is being felt by every single American (as well as some Canadians and Brits). Similar to the Sarbanes-Oxley requirement on the certification of internal control over financial reporting, CEOs and other executives will be required to disclose any material data breach upon discovery and personally certify to the effectiveness of their internal control over data security.

Story image
Radware issues security alert, warning of global rise of DDoS-for-hire
Efforts from corporations, law enforcement and independent researchers around the world have attempted in the last two years to curb this growth – but the industry keeps growing says Radware information security researcher Daniel Smith.More
Story image
Global DDoS attacks: What they are, how they work, and how to defend against them
Do not pay the ransom, and do make sure you've got strong DDoS protection, security firms warn.More
Story image
Research: 61% of companies have suffered an insider attack in last 12 months
It comes as rapid migration to cloud and remote working and BYOD scenarios leave organisations increasingly vulnerable to insider attacks as a result of the upheaval caused by the COVID-19 pandemic.More
Story image
Bitglass receives US patent for SAML technology
Bitglass designed its SAML relay to allow a cloud access security broker (CASB) to be inserted into the traffic flow between users and cloud services during the login process.More
Story image
Misinformation on the rise, organisations consider how best to respond
The increase in misinformation and fake domains have left organisations perceiving the threat level to be ‘very significant’, with a third planning greater emphasis on their ability to respond in coming months.More
Story image
Exabeam and Code42 partner up to launch insider threat solution
The solution will give customers a fuller picture of their environment, and will leverage automated incident response to obstruct insider threat before data loss occurs.More