Target and Neiman Marcus execs defend security practices
Some US lawmakers call for new data security regulations, but others question how to keep the law current with criminal attacks
IDG News Service - Recent data breaches at Target and Neiman Marcus were sophisticated attacks not detected by robust cybersecurity measures, executives with the two companies told U.S. lawmakers.
The attacks on the two stores seemed to be targeted at defeating specific cybersecurity measures deployed by the two companies, witnesses told the U.S. House of Representatives Energy and Commerce Committee's commerce subcommittee Wednesday. The attacks likely came from "highly technical, sophisticated criminal organizations," said William Noonan, deputy special agent in charge of the Criminal Investigations Division for Cyber Operations at the U.S. Secret Service.
Executives with the two companies, testifying for the second straight day before Congress, defended their security practices. Target has invested "hundreds of millions" of dollars in cybersecurity, said John Mulligan, CFO at Target. Neiman Marcus has spent "tens of millions of dollars," added Michael Kingston, the company's CIO.
No antivirus software would have stopped the malware that attacked Neiman Marcus' card-processing network, because it was rewritten to target the company, Kingston said. "It was very specifically designed for an attack on our systems," he said.
While several lawmakers and witnesses called for a federal data security standard and breach notification rule, Mulligan and Kingston seemed to suggest those regulations wouldn't have stopped the breaches at their companies. Both men said their companies deploy a wide range of security measures, and both companies notified affected customers within days of discovering the breaches.
In both cases, the malware stole customer information right after they swiped their credit or debit cards and before the companies could encrypt that information, the two executives said. The U.S. retail system needs to move away from old magnetic-strip credit cards to newer chip-based cards that are deployed across Europe, Mulligan said.
Some lawmakers questioned, however, whether Congress could require chip-based cards because attackers are constantly changing their methods. Chip-based credit cards would add an "additional layer of security," but the technology would not prevent all data breaches, added Phillip Smith, senior vice president at cybersecurity vendor Trustwave Holdings.
Cybercriminals are looking to new targets, including mobile commerce, making it difficult to manage specific defenses, he said. "The technology's changing so quickly, and the attack vectors are going to change," he added.
Still, many of the previous data breaches in the U.S. happened because the companies were not following basic security practices, such as regularly patching software and encrypting personal data, said Edith Ramirez, chairwoman of the U.S. Federal Trade Commission. Ramirez called on Congress to pass a law mandating basic security practices and requiring companies to notify consumers of data breaches.
"I think it's time for Congress to act," she said. "Companies continue to make very basic mistakes when it comes to data security."
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
- HP HAVEn: See the big picture in Big Data HP HAVEn is the industry's first comprehensive, scalable, open, and secure platform for Big Data. Enterprises are drowning in a sea of data...
- What Datapipe customers need to know about the new PCI DSS 3.0 compliance standard This handy quick reference outlines what PCI DSS 3.0 is, who needs to be compliant and how Alert Logic solutions address the new...
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well...
- The New Way to Work Knowledge Vault This Knowledge Vault focuses on how, in today's increasingly virtual world, it's more important than ever to engage deeply with employees, suppliers, partners,... All Cybercrime and Hacking White Papers | Webcasts