In October, the South Carolina Department of Revenue discovered that it had been breached and contacted Mandiant to assist in the investigation and response. All told, millions of social security numbers and hundreds of thousands of bank/credit card numbers had been stolen.
In November, Mandiant published their findings. This is exciting. All we usually get is a news article lacking in technical detail. This we can actually learn from.
My goal in this blog post is to explore what, in hindsight, the S.C. Department of Revenue could or should have done better. Please read the Mandiant report before you move on.
Showing posts with label Case Study. Show all posts
Showing posts with label Case Study. Show all posts
Tuesday, December 4, 2012
Wednesday, November 28, 2012
Lessons from the CCSF debacle
In January 2012, some fairly sensational news stories were published about a major data breach at City College of San Francisco. According to the early reports, tens of thousands of student records may have been compromised. Even more interesting, the reports said that some systems may have been infected for over a decade and that there were connections to China and Russia. While the reports were interesting, they were short on details and I hoped to eventually read more after the school had some time to sort things out.
In May, the CTO of CCSF was suspended at least in part for his reaction to the breach. The Guardsman, CCSF's newspaper, published a series of articles that described controversy within CCSF over the handling of the breach, the CTO's management and accusations that the breach was a false alarm.
The CTO's tenure sounds like it was a disaster. It's also full of lessons for IT and security managers.
In May, the CTO of CCSF was suspended at least in part for his reaction to the breach. The Guardsman, CCSF's newspaper, published a series of articles that described controversy within CCSF over the handling of the breach, the CTO's management and accusations that the breach was a false alarm.
The CTO's tenure sounds like it was a disaster. It's also full of lessons for IT and security managers.
Subscribe to:
Posts (Atom)
Adversaries keep getting faster
According to CrowdStrike’s 2025 Global Threat Report, the average breakout time, the window between an adversary gaining initial access and ...
-
Last week, I was asked to acquire the text messages from an iPhone and to pull out only the messages that were to/from a particular party in...
-
Most cryptographic algorithms deal with numbers that are 128 bits or larger. A 128-bit number has 2 128 possible values, but how big ...