Skip to main content

Companies are sorry about security flaws. Just not sorry enough to change

insecure security breach cfpb
Ted Eytan/Flickr
(in)Secure is a weekly column that dives into the rapidly escalating topic of cyber security.

Reuters reported on February 6 that the Consumer Financial Protection Bureau, a key agency responsible for overseeing financial companies, is neglecting its investigation into the Equifax hack that compromised the personal information of millions. The CFPB allegedly has failed to issue any subpoenas or request any testimony — and has backed off cooperation with other agencies like the Federal Reserve.

Sadly, this isn’t a shocking turn of events.

Sadly, this isn’t a shocking turn of events. Various government regulators have levied fines against companies that suffer security breaches in the past, and a handful of past security failures have indeed cost companies dearly. Most, however, survive unscathed.

Two independent studies have confirmed this. One, conducted by the RAND Corporation, found that most computer breaches cost a company around $200,000. That’s a small figure, even for a small business with a few dozen employees. Another study from Columbia University found that the financial cost of a cyber security breach is, on average, less than 0.1 percent of a Fortune 500 company’s annual revenue.

Where’s the stick?

The moral of this is simple – the consequence of a data breach often isn’t high enough to make companies worry about security.

That’s where government agencies like the CFPB need to step in. They can put their fingers on the scales, using fines to make sure companies see real consequences from their failure to protect consumers. In the past, the CFPB has stepped into that role, though it usually hasn’t been a part of enforcement actions that stem from security breaches. The Federal Trade Commission is also involved in many cases but it, too, rarely levies a fine large enough to pose any real consequence for the companies in question.

Giving Equifax a pass? The Administration should get on the side of consumers and focus on making sure hacks like the #EquifaxBreach don't happen again. My bill with @SenWarren would be a good place to start. https://t.co/iJ4neRvjut

— Mark Warner (@MarkWarner) February 5, 2018

Government oversight tends to be lax in the United States, no matter the issue, but cyber security has regulators particularly vexed. It’s usually unclear who is best equipped to handle an investigation, and the damage caused by compromised data isn’t easy to quantify.

In 2013, Yahoo suffered the largest data breach yet recorded, exposing data on all three billion users. What punishment is fair for each exposure? Does the severity of the data loss matter? How can the losses suffered by the victims even be quantified? No one seems to agree and, more importantly, the law doesn’t agree, either. It doesn’t help that the fallout for victims also varies. While some might have their credit ruined or their taxes defrauded, others won’t be harmed at all, and there’s usually no way to link specific breaches with the problems suffered by specific victims.

These complexities allow companies, and other organizations, a chance to dodge responsibility with a meager apology. That’s exactly what Equifax did in the wake of its hack by offering victims free identity theft monitoring. It’s a reasonable and appreciated gesture, but it doesn’t go far enough to protect the victims. Monitoring doesn’t stop identity theft for you and doesn’t reimburse what you’ve lost. It merely helps you pick up the pieces of a bit more quickly than you otherwise might.

Daily data breaches don’t have to be inevitable

There’s only one solution to the problem. We need new, comprehensive laws that hold companies accountable for security breaches.

The Data Breach Protection and Compensation Act of 2018 could be that law. Introduced to congress in January by Senator Elizabeth Warren of Massachusetts and Senator Mark Warner of Virginia, the bill establishes an Office of Cybersecurity, as part of the FTC, which would supervise the data security of large consumer reporting agencies. This new office would have to be notified of any breach within 10 days; currently, companies wait months or even years before disclosing a problem.

Currently, companies wait months or even years before disclosing a problem.

Specific penalties are also noted, starting at $100 if a consumer’s first and last name are compromised, along with at least one item of personally identifying information. An additional $50 is tacked on for each additional bit of info leaked. Although we don’t know exactly what the price of those fines are based on, it’s a penalty scheme that seems to take lessons from mobile data services and ISPs that add steep penalties for data overages. Better yet, half the penalty collected would be given back to the victims.

Those penalties add up. Equifax’s hack would result in a penalty of about $1.5 billion dollars. In fact, the total fine would be higher, but a provision in the bill limits the maximum to a percentage of a company’s revenue. Equifax would no doubt survive such a fine — its annual revenue is $3.1 billion, after all — but it’s steep enough to make any company think twice before slacking on cyber security.

Companies have protested the bill, of course, and it doesn’t seem likely to pass Congress. Yet this is exactly the action that’s needed, and we should all rally behind a push for greater accountability. The near-daily occurrence of major security breaches provides plenty of ammo for this column. But I’d be happy to spend a little more time brainstorming topics if it meant shaking the spectra of imminent identity theft that currently haunts us all, whether we know it or not.

Matthew S. Smith
Matthew S. Smith is the former Lead Editor, Reviews at Digital Trends. He previously guided the Products Team, which dives…
ChatGPT’s new Pro subscription will cost you $200 per month
glasses and chatgpt

Sam Altman and team kicked off the company's "12 Days of OpenAI" event Thursday with a live stream to debut the fully functional version of its 01 reasoning model, as well as a new subscription tier called ChatGPT Pro. But to gain unlimited access to these new features and capabilities, you're going to need to shell out an exorbitant $200 per month.

The 01 model, originally codenamed Project Strawberry, was first released in September as a preview, alongside a lighter-weight o1-mini model, to ChatGPT-Plus subscribers. o1, as a reasoning model, differs from standard LLMs in that it is capable of fact-checking itself before returning its generated response to the user. This helps such models reduce their propensity to hallucinate answers but comes at the cost of a longer inference period and slower response.

Read more
Surface Pro alternative: This Asus Chromebook is another $70 off today
A man holding the Asus Chromebook CM3001 Laptop.

While fast and powerful CPUs and GPUs go a long way with a desktop or laptop, not every PC needs to be a workhorse. Some folks only need a computer for basic web browsing or watching the occasional HD movie or show. That’s why we’re always on the lookout for great Chromebook deals. These Chrome OS machines are just strong enough to deliver a notch above the basics, and today, we found an excellent discount on an Asus Chromebook. For a limited time, when you purchase the Asus Chromebook CM3001 Laptop at Best Buy, you’ll only pay $230. At full price, this model sells for $300.

Why you should buy the Asus CM3001 Laptop
From its convenient 2-in-1 design (check out our list of the best 2-in-1 deals) to its beautiful 10.5-inch 1920 x 1200 touchscreen (WUXGA), the CM30 is a laptop you’ll have zero issues taking just about anywhere. Its light form factor is a huge plus, and when closed, the CM30 is only 0.67 inches thick! And while we’re not dealing with Intel or AMD for internals, the onboard MediaTek Kompanio 520 CPU runs and smooth and efficient ship. It's also a great Surface Pro alternative, for those tiring of the Windows way.

Read more
Get Copilot+ features for less with this Asus laptop deal
An Asus ProArt P16 laptop on a white background.

One of the best laptop deals right now is perfect for anyone who is seeking a Copilot PC. If you’re looking to enjoy AI features, check out the Asus ProArt P16 laptop which is $200 off at Best Buy. The laptop normally costs $1,900 but right now, you can buy it for $1,700. A high-end productivity-focused laptop which also packs a punch for some gaming too, this is an ideal workhorse of a PC. Here’s all you need to know about it alongside some insight into the wonders of Copilot.

Why you should buy the Asus ProArt P16 laptop
Asus features in our look at the best laptop brands thanks to the company being great at developing all-rounder laptops. The Asus ProArt P16 laptop is one such highlight. It has an AMD Ryzen AI 9 HX 370 CPU, 32GB of memory, 1TB of SSD storage, and an Nvidia GeForce RTX 4060 GPU.

Read more