The new DHS breach illustrates what's wrong with today's cybersecurity practices
But the part that jumped out the most was how explicit DHS was about characterizing this as a “privacy incident.” In its public statement, the department made no mention of the incident as an insider threat issue, despite the records being found in the possession of a former employee.
Rather than question DHS’s designation of this as a “privacy incident,” we should focus on what that designation means. Labeling this a privacy incident suggests that a distinct cyber incident would require an outsider gaining access through the network. It could also indicate that the categorization was made after DHS waited until their forensics demonstrated it was not exposed to malicious activity.
No comments:
Post a Comment