Equifax Executives Resign Without Charge

After an estimated 143 million Americans' personal information was accessed by hackers targeting Equifax Inc., its chief information officer and chief security officer are stepping down.

Equifax said recently that Chief Information Officer David Webb and Chief Security Officer Susan Mauldin had departed. They've been replaced by current international IT chief Mark Rohrwasser as interim chief information officer and Russ Ayres, a vice president in Equifax's IT operation, as interim chief security officer.

Background

Picture a factory gushing pollution into a nearby waterway. Now, imagine the factory’s executives knew a giant leak was likely but did nothing to prevent it. Finally, think of those same executives waiting weeks to warn anyone of the spill, and then bungling the clean-up efforts, after first trying to profit from them.

If all this happened, the company responsible would face criminal fines and its executives would likely end up in prison.

That's why Equifax and its leadership team can count themselves lucky they’re in the data business. Even though their incompetence and foot-dragging compromised the security of over 140 million Americans, they're beyond the reach of criminal law.

Equifax may face class action suits and a FTC investigation, but the worst that can happen to individual executives is they will have to resign (two already have), probably with a tidy payout on their way out.

Executives should Catch-Up

It doesn’t have to be this way. According to Jesse Eisinger, author of a recent book about white collar crime, there’s ample precedent for corporate executives going to jail for negligence. In an interview with Fortune, Eisinger pointed to a rule called the “responsible corporate officer” doctrine, which prosecutors can use to charge executives whose lack of oversight endangers the public welfare.

The catch, though, is the “responsible officer” rule has only been deployed in cases involving food, drugs or the environment. Examples include executives who received criminal penalties over mislabeled oxycontin shipments, and whose negligence led to salmonella-tainted eggs.

According to David Frulla, a regulatory lawyer at Kelley Drye, prosecutors can only bring responsible officer charges in respect to a specific law, such as the FDCA, that provides criminal penalties for violators. They can't simply charge Equifax executives for general incompetence.

Right now, there's no such federal law when it comes to personal data. But there probably should be given the clear public harm that occurs after major data breaches, including the Equifax hack, which has been widely described as the worst in history.

In the case of Equifax, hackers plundered not only the name and Social Security numbers of more than 100 million people but, in many cases, their phone numbers and home addresses (past and present) as well. Those who paid for Equifax’s credit monitoring service also had their credit card information stolen.

All of that data is already for sale in dark corners of the Internet, and is going to lead to a spate of scams and identity thefts that will haunt people for years. Meanwhile, the website Equifax set up to help consumers find out if they had been breached has also been found vulnerable to hackers, and critics are accusing the company of using the breach to tout paid ID Theft products. Some sort of punishment is clearly in order.

Many people in cyber-security circles caution that shaming corporate hacking victims is not a good idea because companies will be less forthcoming about data breaches. This reasoning is not convincing in the case of Equifax, however. The company’s whole business revolves around personal data, their failure to protect it should mean public disgrace.

Equifax executives behaved with brazen carelessness, storing the data in a way that made it easy for hackers to try and steal it. Eventually, the hackers broke in because Equifax failed to update a critical piece of software, even though a patch had been available for months.

It’s poor practice, these days, for consumers not to update the software on their home devices. For a giant corporation to ignore software updates is simply reckless, and even more so when that corporation’s core business involves consumer data.

Equifax executives will nonetheless face no legal consequences for this debacle (other than three officers who could face charges for selling stock before the breach was disclosed). The US right now just doesn’t have the laws to hold them accountable. Meanwhile, CEO Richard Smith will probably keep the $68.9 million he's made from selling the company's shares since 2016.

This could change, however, if US Senators Orrin Hatch and Ron Wyden are serious about getting to the bottom of the Equinox breach. Their proposed investigation should seek to identify who at Equifax was responsible for the breach, and also propose ways for this not to happen again.

According to Sam Buell, who teaches corporate criminal law at Duke University School of Law, scandals like the Equifax affair often trigger public conversations that lead to new regulatory oversight.

"There's a good argument this is one of those industries where there’s a need for a higher standard or the pain of criminal punishment. When you’re in a business that has the potential to do this scale of harm, you have a duty of care for your product that could be covered by criminal law."

Consumers would no doubt agree. The time is rapidly coming when executives should be held to the same standard for protecting personal data as they do for the environment or the food supply.

Fortune:      The Street:

You MIght Also Read:

Disastrous Equifax Breach Exposes 44% Of The US Population:

Threat Lessons from Sony and Anthem:

 

« Transforming Your Database
Preventing The Hacked AI Apocalypse »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Hack Miami

Hack Miami

HackMiami is the premier resource in South Florida for highly skilled hackers that specialize in vulnerability analysis, penetration testing, digital forensics, and all manner of IT security.

Duane Morris LLP

Duane Morris LLP

Duane Morris is a global law firm with offices in the USA, UK and Asia. Practice areas include Cybersecurity.

Security Network Munich

Security Network Munich

Security Network Munich brings together leading players in the field of information and cyber security through joint research and innovation projects.

ICS Cyber Security Conference

ICS Cyber Security Conference

SecurityWeek’s Industrial Control Systems (ICS) Cyber Security Conference is the largest and longest-running event series focused on industrial cybersecurity.

FutureCon Events

FutureCon Events

FutureCon produces cutting edge events aimed for Senior Level Professionals working in the security community, bringing together the best minds in the industry for a unique cybersecurity event.

Blockchain Research Institute (BRI)

Blockchain Research Institute (BRI)

Blockchain Research Institute (BRI) is an independent, global think-tank. We bring together the world’s top global researchers to undertake ground-breaking research on blockchain technology.

24By7Security

24By7Security

24By7Security are Cybersecurity & Compliance Specialists with extensive hands on experience helping businesses build a defensive IT Infrastructure against all cyber security threats.

Thrive

Thrive

Thrive delivers the experience, resources, and expertise needed to create a comprehensive cyber security plan that covers your vital data, SaaS applications, end users, and critical infrastructure.

InterGuard

InterGuard

As the pioneer for Unified Insider Threat Prevention and productivity monitoring tools, InterGuard offers on premise and SaaS-based services that are easily available and affordable.

PizzlySoft

PizzlySoft

PizzlySoft is a global company that is seeking convergence of network and security / software and hardware. We put our value on creating the best security.

Privasee

Privasee

Make GDPR compliance simple with Privasee. Our software makes it easy to protect your data and ensure you’re compliant with the new regulations.

Lodestone

Lodestone

Lodestone partners with clients to help them mitigate business and reputational risk, through our human-based, approach to cyber security, digital forensics and incident response.

Allure Security

Allure Security

Allure Security AI-driven brand protection scans more of the online world for faster, more accurate detection & removal of spoof websites, social media & mobile apps -- before customers fall victim.

Boldend

Boldend

Boldend offers leading-edge offensive and defensive cybersecurity solutions that empower government and commercial organizations to stay resilient in an evolving threat landscape.

New Relic

New Relic

After inventing application performance monitoring (APM), New Relic stands at the forefront of observability with the most advanced platform for eliminating digital interruptions.

ITConnexion

ITConnexion

ITConnexion is an Australian-based Managed IT Service with over 20 years of experience. We offer a complete IT management service for non-profits, SMEs, and enterprises.