Equifax to shell out $700m in fines over 2017 breach
Equifax will pay up to $700 million to victims, regulators and US authorities following its catastrophic 2017 data breach, US federal trade commission officials have announced.
The settlement is split between the US government and the approximately 145 million US residents who were victims of the breach. However, there are some conditions attached to the payout for victims.
The settlement obliges Equifax to contribute $300 million to a fund which will pay for credit monitoring services for affected US residents, and will also be used to reimburse victims for any identity theft protection they purchased, or other expenses incurred, as a result of the hack.
Equifax will supplement this fund with up to $125 million, depending on the amount of compensation required, and will also provide six free annual credit reports for the next seven years. It will also pay $100 million in civil penalties to the US Consumer Financial Protection Bureau, as well as $175 million to Puerto Rico, the District of Columbia and 48 US states.
The breach cost the company $1.4 billion, as of the company's latest financial results, a figure which, when combined with this latest round of penalties, rises to $2.1 billion. The Information Commissioner's Office has also previously hit Equifax with its maximum £500,000 fine over the 15 million UK residents who were affected by the breach.
This collection of financial reprimands, which represents the largest collection of fines and penalties in US data breach history, also comes with a scathing rebuke of Equifax's security practices. According to the FTC's complaint, "hackers were able to access a staggering amount of data because Equifax failed to implement basic security measures".
Its failure to segment its network, protect legacy databases or patch vulnerabilities in a timely manner (all while claiming to put reasonable safeguards in place) put Equifax in breach of the FTC Act and the Gramm-Leach-Bliley Act, the regulator said. Jun Ying, an ex-Equifax executive and the company's CIO at the time of the breach, was also sentenced to four months imprisonment for insider trading last month, after using his knowledge of the breach to dump his company shares before it was publicly announced.
On top of the requirements around penalties and compensation, the terms of Equifax's settlement also compel the company to institute sweeping changes of its security procedures. These include conducting annual security risk assessments, rolling out intrusion monitoring and patch management software, appointing a designated head of information security and making sure that any partners who access Equifax's stores of personal information also abide by similar security requirements. Its security program must also be assessed by an FTC-approved third party every two years.
"Companies that profit from personal information have an extra responsibility to protect and secure that data," FTC Chairman Joe Simons said as part of a statement. "Equifax failed to take basic steps that may have prevented the breach that affected approximately 147 million consumers."
"The incident at Equifax underscores the evolving cybersecurity threats confronting both private and government computer systems and actions they must take to shield the personal information of consumers," added Consumer Financial Protection Bureau Director Kathleen L. Kraninger. "Too much is at stake for the financial security of the American people to make these protections anything less than a top priority."
Industry: Cyber Security
- SPLUNK SOC Analyst level 3, London.
SPLUNK SOC Analyst level 3, Must be able to commute to the City of London. Onsite role. Security clearance needed. The SPLUNK SOC Analyst level 3 must have current experience working within a SOC environment with specific experience using a range of tools and techniques to investigate security incidents. Current experience with Splunk is essential. any additional experience Individuals with Elastic Security SIEM are highly desirable. Any of the following certifications are desirable Splunk Phantom certified admin, Splunk Core Certified Power User / Advanced, Splunk Certified Enterprise Security Admin, etc The role will include, but not be limited to working with sophisticated information security tools, investigating security incidents, incident management, technical escalation, process improvement, research into the latest threats, reporting etc The individual MUST currently be living in the UK and be able to achieve UK security clearance. (SC) This is a permanent role To arrange a call with Chris Holt https://calendly.com/chris-holt/arranged-call-with-chris-holt-elastic-siem-engineer-soc Chris.Holt@dclsearch.com
- ISO 27001 & Business Continuity Security Specialist, End User
- United Kingdom
CH7828 ISO 27001 & Business Continuity Security Specialist, End User, £70,000 United Kingdom ISO 27001 & Business Continuity Security Specialist needed to join a Cyber team within an end user. The ISO 27001 & Business Continuity Security Specialist will have end to end responsibility for the information security and Business Continuity management system. ISMS/BCMS. Both from an information security and technical security perspective working alongside the CISO. Experience must include, but not be limited to; a mix of Information Security standards, frameworks, audit principles, controls / policies and the management and use of the technical tooling to achieve compliance. ISO 22301, ISO 27001, NIST Cybersecurity Framework etc An ideal candidate will be working within an end user environment with a cyber consultancy background. Experience taking a company through accreditation is highly desirable Experience managing internal stakeholders, technical teams and external third parties essential Flexible working, very occasional travel to London office This is an exclusive role to DCL Search & Selection. Looking to interview immediately. https://calendly.com/chris-holt/iso-27001-business-continuity-security-specialis
- PCI- DSS Security Consultant, End User
PCI- DSS Security Consultant needed to join a Cyber team within an end user. The PCI- DSS Security Consultant will have end to end responsibility for PCI - DSS and its continuing certification. Both from an information security and technical security perspective working alongside the CISO. Experience must include, but not be limited to; a mix of Information Security standards, frameworks, audit principles, controls / policies and the management and use of the technical tooling to achieve compliance. PCI objectives / 12 key requirements, OWASP top 10, ISO 27001, NIST Cybersecurity Framework etc An ideal candidate will be working within an end user environment with a cyber consultancy background. PCI Cloud compliance, specifically someone with experience taking PCI-DSS from on premise into the cloud is HIGHLY desired. However, someone with Solid PCI experience with a strong technical background which include Cyber / Secure by design etc would be considered. Experience managing internal stakeholders and external third parties essential. Flexible working, but with the ability to get into London. This is an exclusive role to DCL Search & Selection. 1st stage interviews to happen the week of the 14th September Arrange a call with Chris on https://calendly.com/chris-holt/arrange-a-call-chris-dcl-pci-compliance
- IAM Contractor CyberArk
Identity & Access Management Architect Contractor Flexible • Extensive PAM / IAM experience required, • MUST have CyberArk and or Beyondtrust. Privileged access management • Technical review, recommendation, design and hands on technical delivery. • 6 month contract Arrange a call with Chris Holt https://calendly.com/chris-holt/arranged-call-with-chris-holt?month=2020-09