HOME     MENU     SEARCH     NEWSLETTER    
NEWS & INFORMATION FOR TECHNOLOGY PURCHASERS. UPDATED ABOUT A MINUTE AGO.
You are here: Home / Network Security / Sony Fined $395,000 for Data Breaches
Neustar, Inc.
Protect your website & network using real-time information & analysis
www.neustar.biz
Sony Fined $395,000 for Poor Security in Data Breaches
Sony Fined $395,000 for Poor Security in Data Breaches
By Jennifer LeClaire / NewsFactor Network Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
JANUARY
24
2013


Sony has been slapped with a 250,000 pounds ($395,000) fine for poor security that exposed subscriber data in violation of Europe's Data Protection Act. The breaches, which date to April 2011, put the personal information of millions of customers -- including names, addresses, e-mail addresses, dates of birth, credit card details, and account passwords -- at risk.

Just weeks after hackers penetrated the Sony PlayStation Network, the hacking group LulzSec took responsibility for another attack on Sony Online Entertainment. During that attack, information from some 100 million user account profiles was exposed. Then, in October 2011, hackers attacked the PlayStation Network again. The company locked down 93,000 accounts.

Europe's Information Commissioner's Office (ICO) launched an investigation. The conclusion: Sony could have prevented the attack if it had kept its security software up to date.

No Apologies

"If you are responsible for so many payment card details and login details then keeping that personal data secure has to be your priority. In this case that just didn't happen, and when the database was targeted -- albeit in a determined criminal attack -- the security measures in place were simply not good enough," said David Smith, deputy commissioner and director of data protection for the ICO.

As Smith sees it, this is a business that should have known better. "It is a company that trades on its technical expertise, and there's no doubt in my mind that they had access to both the technical knowledge and the resources to keep this information safe," Smith said.

Smith called the penalty "substantial" and made no apologies for it because the case was one of the most serious ever reported to his agency. The Sony breach directly affected a huge number of consumers, he said, and at the very least put them at risk of identity theft.

"If there's any bright side to this it's that a PR Week poll shortly after the breach found the case had left 77 percent of consumers more cautious about giving their personal details to other Web sites," Smith said. "Companies certainly need to get their act together but we all need to be careful about who we disclose our personal information to."

Fine Not Big Enough?

Richard S. Westmoreland, a team lead at Perimeter E-Security, said the fine was weak, considering how many people's information was stolen. He also was concerned it did nothing to prevent this type of negligence in the future, because it was reactive, not proactive.

"If it weren't for Sony's size and reputation, this may have gone unnoticed, or worse, covered up," Westmoreland told us. "Organizations that must be compliant under [various regulatory standards] and require regular testing of controls are in a much better position within the Internet threatscape.

"In some situations a serious breach may shut down the non-compliant organization rather than simply landing them with a fine that is absorbed as an expense and eventually passed along to the consumer. That is what makes organizations take this seriously."

Alex Horan of CORE Security told us he's excited about the reasoning behind the fines. As he sees it, it sends a message that businesses can no longer avoid security testing because they want to be able to say "we didn't know of any issues, so it is not our fault that they exist."

"The ICO said that if a business has some level of technical expertise, then it cannot claim ignorance to the possibility of IT-related risk," Horan said. "Ignorance is no longer a defendable position."

Evan Robert Keiser, security analyst at Perimeter E-Security, told us the fine was long overdue and should have been much larger. He noted that Sony underwent two fairly large lawsuits after the breach because they violated Payment Card Industry compliance by failing to notify PlayStation Network members of a possible security breach and storing members' credit card information for quite some time before releasing information about the full scope of the breach.

"Not only did Sony fail to use firewalls to protect its networks, it was using outdated versions of the Apache Web server with no patches applied on the PlayStation Network during the time of the breach," he said. "They should have spent more money ensuring their own security was up to date and less protecting copyrights as well as pursuing hackers like Geohot who's publishing of their root keys and his own homebrew PS3 software could potentially allow a user to play copied discs."

Tell Us What You Think
Comment:

Name:

Pat Michaels:
Posted: 2013-01-26 @ 7:19am PT
That's chump change to them. Not even a slap on the wrist.

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
Neustar, Inc. (NYSE: NSR) is a trusted, neutral provider of real-time information and analysis to the Internet, telecommunications, information services, financial services, retail, media and advertising sectors. Neustar applies its advanced, secure technologies in location, identification, and evaluation to help its customers promote and protect their businesses. More information is available at www.neustar.biz.
MORE IN NETWORK SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business

NETWORK SECURITY SPOTLIGHT
The FBI is pointing the finger of blame for the Sony Pictures cyberattack directly at North Korea. The hackers stole confidential data and caused the movie giant to can its new comic film, "The Interview."

ENTERPRISE HARDWARE SPOTLIGHT
Almost half of consumer, industry and life sciences manufacturers are expected to be using 3D printers within three years and now 3D printing services are aiming to help companies experiment.

© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.