It is not unusual to read that companies “care” about the data privacy and protection of individuals. But how much of that is actually true?
It is often reported that users are subjected to data hacks, and increasingly these attacks are done by credential stuffing. There is a trend where larger companies seem to prefer to pay a fine over putting better preventative and security measures in place.
This has been highlighted by OkCupid, a free online dating site, which recently had users complain their accounts were hacked. OkCupid’s response to this was to defend against allegations with statements including: “all websites constantly experience account takeover attempts”, “there’s no story here,” and “no further comment”.
Target, a large US retailer, paid $18.5 million for a data breach that released details on 41 million customer credit cards. Anthem, the largest US health insurance company, paid $115 million in fines a data breach put 79 million insurance holders’ data at risk. Both companies had revenues of over $70 billion in these years. In addition, Equifax, a global consumer credit reporting agency, which had the biggest breach of the year in 2017, led to a lot of talk but no real action no real action.
Other companies have improved their response to such attacks by, for example, rolling out two-factor authentication and have taken the time to improve account security. There are still further measures that companies could put in place. This can range from something as simple as informing users of contacts details in cases of security flaws to employing people or systems to tighten security and find vulnerabilities.
For security consultancy and support, please contact us. We are also an ESET Partner – this award winning internet security solution is the only protection we recommend and is trusted by over 100 million users worldwide – contact us for current offers.
