Last year’s Capital One data breach ranks as one of the largest confirmed breaches ever, exposing the personal data of more than 100 million Capital One customer accounts stored in the cloud.
Almost a year later, the story hasn’t gone away. Last month, a U.S. magistrate judge ruled that Capital One must provide forensic details about the hack to attorneys representing a group of customers suing the bank.
As fallout from the breach continues, here are key lessons security and business leaders can learn to protect their organizations from a similar fate.
Implement a robust third-party risk management program
The court decision in the Capital One case sets a new precedent that could require organizations to disclose incident response reports detailing the circumstances around a breach. This requirement could expose companies to greater public scrutiny of their security programs, and open them up to financial and reputational damage.
A key takeaway from the ruling is that the onus is very much on security teams to demonstrate an unparalleled standard of care as they conduct business with vendors. To do this, they must provide evidence that they have a robust third-party risk management program in place — one that continuously monitors for cyber risk within their supply chain.
With such a program, security teams can identify potential vulnerabilities within their third-party networks, and accelerate vendor onboarding processes without sacrificing their security postures. They can also work alongside their vendors to help them understand where risk exists in easily understood terms so that informed decisions can be made about where to prioritize remediation efforts — before those vulnerabilities are exploited.
Reduce liability by understanding the shared responsibility model
The Capital One breach allegedly occurred when a former Amazon Web Services (AWS) employee exploited a misconfigured web application firewall to gain unauthorized access to a cloud-based server.
This had significant liability ramifications for Capital One. Under the AWS shared responsibility model, Capital One was responsible for implementing security on that server and was therefore held accountable for the breach.