Malware sophistication vexes lawmakers, retailers and the financial industry
Members of the Senate Judiciary Committee also point to failure of industry to implement stronger measures
IDG News Service - The failure of U.S. financial institutions and retailers to implement more robust cybersecurity measures, such as the smart-card technology widely used in Europe, was questioned and criticized by members of the Senate Judiciary Committee at a hearing Tuesday.
Senators also questioned notification procedures following recent high-profile breaches and whether federal law enforcement agencies are doing enough to go after cybercriminals. Lawmakers repeatedly noted the vulnerability of U.S. consumers, who make a quarter of all credit-card transactions globally, but half of all data breaches occur in the U.S., with a quarter of all data breaches occurring in the U.S.
Sen. Richard Blumenthal, a Connecticut Democrat asked what seemed to be a rhetorical question given the discussion at the hearing. "Am I right in thinking that the U.S. is behind the rest of the world in its data-security safeguards?"
Executives from Target and Neiman Marcus, which have recently revealed massive breaches of shoppers' data, were among the witnesses called before the committee, with some lawmakers expressing frustration at the laggardly pace in which industry is moving toward technology that provides additional layers of security. For instance, Visa and Mastercard have said they will implement the use of smart cards by October 2015, yet such technology is already widely used in other countries.
Lawmakers and witnesses also spoke of the lack of federal standards and legislation, including the need for stronger notification laws -- businesses currently have up to 60 days to notify customers when a breach has occurred -- at a time when cybercriminals are developing increasingly sophisticated malware capable of evading detection. For instance, the data breach at high-end retailer Neiman Marcus occurred between July and October of last year, with different stores in the retail chain affected at different times, but the intrusion was not detected until Jan. 2, according to testimony from Michael Kingston, senior vice president and CIO of The Neiman Marcus Group.
A Secret Service report regarding that breach concluded that malware "comparable and perhaps even less sophisticated to the one in our case had a zero-percent detection rate" using available security software, he said.
That means, witnesses agreed, that any standards or legislation implemented by the government must be flexible to adapt to the evolving threats. Legislation must be "multilayered," said Fran Rosch, a senior vice president at security-software vendor Symantec. Smart cards, with embedded chips and data that changes per transaction, are just one method of protecting consumers better from data theft, he said. Two-factor authentication and data encryption at all steps of a transaction are other mechanisms.
"We think any legislation should reflect that, [and impose] those layers," he said.
- Why Projects Fail CIOs are expected to deliver more projects that transform business, and do so on time, on budget and with limited resources.
- The New Business Case for Video Conferencing: 7 Real-World Benefits Beyond Cost-Savings This whitepaper provides insight into the value of video conferencing in today's business environment, and how organizations are using visual collaboration to find...
- Gartner Magic Quadrant for Client Management Tools The client management tool market is maturing and evolving to adapt to consumerization, desktop virtualization, and an ongoing need to improve efficiency.
- Audit Ready and Asset Optimized: The Solid Promise of an Intelligent Software Asset Management Solution In this paper Frost & Sullivan examines the benefits of enterprise-grade Software Asset Management solutions, and how these solutions serve as the convergence...
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Cybercrime and Hacking White Papers | Webcasts