If it cost them as much to clean up each spill as it cost BP, you better believe they would take better care not to let it happen again.
If it cost them as much to clean up each spill as it cost BP, you better believe they would take better care not to let it happen again.
It's so sad that this is even remotely controversial. Equifax should have gotten the same treatment as Arthur Andersen.
From my rational, informed side, I would argue no. Here's my rationale.
The data stolen from Equifax has not shown up on the black market and hasn't been actively used, which suggests this was a nation-state using the data for something other than profiting from fraud. This also suggests that the hack could easily be considered an "act of war", so given enough time+effort+resources, no company would likely be able to resist that breach (although I know Equifax could have done FAR better than they did).
Technically I don't "own" the data that Equifax has about me. Equifax owns the collection of it, their reporters (ex retailers, landlords, bank/mortgage companies) each own a shard, and other data aggregators who contract with any one of these actors can own part/all of it.
I am not Equifax's customer. They are required to deal with me based on a few rules defined in the Fair Credit Reporting Act, but the FCRA also provides some protections for credit reporting agencies who don't violate those rules. I'm sure they minimize the effort/resources they devote to helping credit consumers because that is the profit motive of every company.
I'm sure Equifax has a ridiculous EULA/ToS that I probably implicitly agreed to when I used the AnnualCreditReport website, and probably additionally when I deal with any retailer that pulled credit reports from Equifax (including the IRS after the breach was revealed). It likely involved me signing away my rights to a class action litigation or my rights to a trial by jury, because that is par for large contemporary corporations.
The standard for "protecting consumer data" is remarkably low except in a few sectors (ex. healthcare, retailers storing credit card data), and even in those it's still disheartening. The problem here is that companies can easily argue to {regulators, judges/juries, their BoD, cybersecurity vendors} that they can't be expected to spend more than the industry average because that hurts them more than the competitors. This just becomes a Prisoner's Dilemma where our data's security becomes the victim to corporate (in this case credit reporting bureau) self-interested decision making.
Yet - and also the absence of evidence doesn't mean the evidence of absence. Not all criminals are stupid, a smart one would wait till vigilance dies down.
> Technically I don't "own" the data that Equifax has about me.
This itself is a big part of the problem. It should absolutely be illegal for companies to hold sensitive info like my SS# without my permission.