25 April 2021

Someday Companies Will Take Security Seriously

But today is not that day. Geico data breach exposed customers' driver's license numbers

Driver's license numbers can be used in a lot of ways. In this case Geico thinks the bad guys will apply for unemployment benefits in the names of people who had their data stolen. That is something like 17 million people, or more. They insure 28 million vehicles.

So why do I say they were not taking security seriously?

Once they learned of the abuse, Geico says they secured the website and added additional safeguards to prevent further fraud or illegal activities.

Why were those "additional safeguards" not in place to begin with? Because you IT folks always want to spend money on something, and besides, what's the worst that could happen?

No comments:

Post a Comment

Comment Moderation is in place. Your comment will be visible as soon as I can get to it. Unless it is SPAM, and then it will never see the light of day.

Be Nice. Personal Attacks WILL be deleted. And I reserve the right to delete stuff that annoys me.