{"id":6300,"date":"2024-11-19T09:00:00","date_gmt":"2024-11-19T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/we-can-do-better-than-free-credit-monitoring-after-breach"},"modified":"2024-11-19T09:00:00","modified_gmt":"2024-11-19T15:00:00","slug":"we-can-do-better-than-free-credit-monitoring-after-a-breach","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/11\/19\/we-can-do-better-than-free-credit-monitoring-after-a-breach\/","title":{"rendered":"We Can Do Better Than Free Credit Monitoring After a Breach"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5e71d7a5bb01a524\/673ca1e63b1c941581463a36\/Breach_%281800%29_Anthony_Brown_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Having a long career in cybersecurity doesn&#8217;t stop me from being included in the same <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fidelity-notifies-77k-customers-data-breach\">data breaches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and mass involuntary <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fidelity-notifies-77k-customers-data-breach\">disclosures of consumer information<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as everyone else. And like everyone else, I probably have now collected enough years of &#8220;free&#8221; credit monitoring that some of it could be passed on to my kids upon my death \u2014 maybe there will be some left for my grandkids, too.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Not that credit monitoring isn&#8217;t helpful \u2014 one big benefit is the detection of data on the Dark Web, which has shed more light on the frequency of breaches. Through my free credit monitoring obtained after one breach, I have been notified about my data showing up on the Dark Web, indicating a new breach has occurred with a different company, long before the company notified me itself.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last year, over a third of Americans experienced fraudulent charges on their debit or credit cards, email or social media account takeovers, or a fraudulent attempt to open a line of credit or take out a loan in their name, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.pewresearch.org\/internet\/2023\/10\/18\/how-americans-view-data-privacy\/\">Pew Research Center<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Breaches don&#8217;t seem to be slowing down. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.idtheftcenter.org\/publication\/2023-data-breach-report\/\">Identity Theft Resource Center<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> reports there were 78% more breaches in 2023 than the previous year. There are hundreds of millions of victims each year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It certainly feels like no one cares. It&#8217;s true that stock prices do recover after a major breach, and they seem to be recovering faster each time. Wall Street must assume that consumers just don&#8217;t care that much, but I don&#8217;t see that continuing for long. Consumers might feel helpless, they might even feel hopeless, but they absolutely do care. If they start to take action, the economy will feel it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Consider what might happen if most American consumers, concerned about the number of data breaches, decided to just take the simple action of freezing their credit. It would probably be healthier for the economy overall if the ability to borrow impulsively was removed, but it&#8217;s not &#8220;good for business&#8221; and could negatively affect several sectors \u2014 retail in particular \u2014 significantly. This is not unrealistic. Just a few years ago, freezing and unfreezing credit was a bit of a hassle. Today it takes only a couple minutes per credit bureau.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So maybe companies ought to treat disclosure victims a little better and do more to not create victims in the first place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Below are some ideas.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Before a Breach\">Before a Breach<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the very minimum, companies that hold personal health information or personally identifiable information on databases that can be accessed from the Internet should have a bug bounty program. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/bug-bounty-programs-hacking-contests-power-chinas-cyber-offense\">Bug-bounty programs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> allow freelance security researchers to earn money by &#8220;hacking&#8221; companies and responsibly disclosing the vulnerabilities they found in the process. Without a clear program, these researchers are not only not guaranteed any reward for doing the right thing, they also are not guaranteed safe harbor against legal action being taken against them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It also makes sense for companies of at least a certain size to obtain and share security certifications. At present, these certifications are voluntary. Eventually, government regulation may change that. For now, however, industry regulation will need to take the reins. Businesses that rely in any way on freely available consumer credit, such as retail stores that offer store credit cards, should be especially on top of their security certifications and wary of working with third parties who aren&#8217;t.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"After a Breach\">After a Breach<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The number of breaches should absolutely be lower than it is, but even with great security, breaches can and will still occur. What&#8217;s important after a breach is protecting the affected consumers and not insulting them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first thing businesses should do is step up their disclosure game and notify customers in a timelier manner that their data has been compromised. It took <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/unitedhealth-reveals-100m-compromised-change-healthcare-breach\">Change Healthcare<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> six months to send me a notification letter informing me that I was included in their breached data, but I was already keenly aware that this had happened months earlier. What was the point of the delay?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Next, companies need to do more than free credit monitoring. Credit monitoring <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">is<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> valuable, but it&#8217;s reactive security on the consumer&#8217;s end. Giving victims access to free password management services as well would provide them with a proactive tool.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But companies giving out another relatively cheap service is likely not going to cause companies enough pain to force them into prioritizing security any more than they are now. Regarding those industry regulations, certification should be contingent on an agreement to pay victims directly in the event of a breach, something like $5 to $50 per person per event.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If the company has good security implemented and proof that proper controls were in place, then they would pay less. If an ostensibly reputable company that has been identified as compliant is found to be grossly negligent, then not only should that company have to pay a higher amount to each consumer, the certification body should also have to pay out to victims. This extra agreement would bolster the overall value that the certifiers provide because it prevents blind certification to any company willing to pay for it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The sun is setting on companies getting away with being opaque, cheap, and slow to react after major breaches of customer data. Individual companies and entire industries alike must take responsibility for protecting customer data and doing the right thing when they fail.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/we-can-do-better-than-free-credit-monitoring-after-breach\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Having a long career in cybersecurity doesn&#8217;t stop me from<\/p>\n","protected":false},"author":12,"featured_media":6301,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6300","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/we-can-do-better-than-free-credit-monitoring-after-a-breach.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6300"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6300\/revisions"}],"predecessor-version":[{"id":6302,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6300\/revisions\/6302"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6301"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}