When there is a breach of date the concern is three fold.
1.
Was the information enough to supply me with the
data I need to create new accounts?
2.
Was there enough information to allow me to
sucker you into giving up more information?
3.
Was it enough for me to take over the account
and drain it, max it out or use it to scam others?
When a company has a data breach and does not clearly
indicate what was exposed it leaves the recipients to try and guess what to do.
It also leaves the company somewhat exposed to legal reprisals. The time frame
in a breach should be discovery, investigation, informed notice, and then
proceed with your business. The investigation should involve law enforcement
and they should be called before any repair or system fixes are started. The
notice needs to be clear and concise and complete. The better these steps are
done the better for all involved.
The very fact that confidential information was compromised is alarming. Most members of the site LinkedIn are professionals who work in companies. When employers who are well aware that their employees are active members of such a site, hear about this, it causes some concern on the employer’s part. There is nothing coincidental about LinkedIn being hacked. There was a good reason why hackers chose to steal information from a pool of people who are directly affiliated to potential sources of money.
ReplyDeleteRuby Badcoe