Live data from Hacker News

Equifax used records it collects from companies to fire employees with 2nd jobs

businessinsider.com

291–300 of 408 posts

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#291
post #267

Earlier quoted context omitted.

Quoted post unavailable.

Oh, please. People in technical leadership roles should have formal training and should have spent some time in the trenches, full stop. We hold most other specialized leadership roles to this standard: Chief Financial Officers, Chief Legal Officers, Chief Medical Officers, etc. Why not CTOs and CISOs? > nasty sexism... male CISO at other company... The article is about Equifax. I am commenting about Equifax. This is…

>People in technical leadership roles should have formal training and should have spent some time in the trenches, full stop. We hold most other specialized leadership roles to this standard: Chief Financial Officers, Chief Legal Officers, Chief Medical Officers, etc. Why not CTOs and CISOs?

The vast majority of qualified candidates will not have relevant formal training. Until very recently it's been borderline impossible to get an infosec degree, and what little opportunities existed were of atrocious quality.

>Oh, please. I'm well aware that this problem is pervasive in American business culture. The article is about Equifax. I am commenting about Equifax.

1) It's not a problem

2) It's not American

This is just how emerging fields are, you can't have formal education when nobody knows what to teach.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#292
post #152

Earlier quoted context omitted.

This is pure evil, and should be 100% illegal.

As an employee you can opt out of it

It should be opt in really though shouldn't it.

The problematic nature of opt out is common sense at this point.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#293

Semi-related, but Equifax runs The Work Number, which is basically your "employment credit report / record"; they hoover up the data by agreements with employers that they will share employment info with them. You can freeze your employment record with them here: https://employees.theworknumber.com/employee-data-freeze/ I highly recommend you do this, as any employer could just decide to look you up using this info a…

Shockingly, this contains your salary information. Which is pretty dangerous for salary negotiation.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#294
post #271

Earlier quoted context omitted.

It's a nasty sexist lie. The person had no relevant degree (as is the case for most people working in security roles, because such degrees didn't exist until very recently). The person did have a literal decades of relevant experience, working in security.

You're going around the threads trying to make this a gender issue. It's a valid criticism of anyone. In this case they happen to be female. That doesn't mean the criticism is motivated by gender. Your gender also doesn't excuse you from criticism.

It's not a valid criticism of anyone. Essentially zero people with that kind of work experience have infosec degrees.

It's hard to get a formal degree on a subject which isn't taught anywhere!

For example: HN loves Mudge, who also happened to just leave a CISO post, and also only holds a music degree from Berkelee.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#295
post #291

Earlier quoted context omitted.

Oh, please. People in technical leadership roles should have formal training and should have spent some time in the trenches, full stop. We hold most other specialized leadership roles to this standard: Chief Financial Officers, Chief Legal Officers, Chief Medical Officers, etc. Why not CTOs and CISOs? > nasty sexism... male CISO at other company... The article is about Equifax. I am commenting about Equifax. This is…

>People in technical leadership roles should have formal training and should have spent some time in the trenches, full stop. We hold most other specialized leadership roles to this standard: Chief Financial Officers, Chief Legal Officers, Chief Medical Officers, etc. Why not CTOs and CISOs? The vast majority of qualified candidates will not have relevant formal training. Until very recently it's been borderline impo…

Seriously? It's not the 1990s.

You will never convince me that Equifax could not have hired a CISO with decades of relevant IC and leadership experience and appropriate educational background. Perhaps Maudin at the time she was hired, I'm not sure the length of her tenure. But there was certainly no excuse for choosing an MBA without IC cybersecurity experience for her replacement. (Who, btw, is a man and also wildly unqualified except for a string of other executive positions that he also should not have been in... happy now?)

>> The article is about Equifax. I am commenting about Equifax.

> 1) It's not a problem

You have got to be kidding me.

1. Equifax majorly shit the bed on cybersecurity, and the buck stops at the CISO.

2. Why is this not the case for CFOs, CMOs, CLOs, and literally every other technical chief officer position except CTOs and CISOs? Again, it's not the 90s.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#296
post #294

Earlier quoted context omitted.

You're going around the threads trying to make this a gender issue. It's a valid criticism of anyone. In this case they happen to be female. That doesn't mean the criticism is motivated by gender. Your gender also doesn't excuse you from criticism.

It's not a valid criticism of anyone. Essentially zero people with that kind of work experience have infosec degrees. It's hard to get a formal degree on a subject which isn't taught anywhere! For example: HN loves Mudge, who also happened to just leave a CISO post, and also only holds a music degree from Berkelee.

Another data point, I was reading just yesterday on a HN post about fake qualifications about many male director level people without proper education.

They were criticised too.

I guess we all see the world as we wish.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#297

Semi-related, but Equifax runs The Work Number, which is basically your "employment credit report / record"; they hoover up the data by agreements with employers that they will share employment info with them. You can freeze your employment record with them here: https://employees.theworknumber.com/employee-data-freeze/ I highly recommend you do this, as any employer could just decide to look you up using this info a…

Are there any other sites like this for the other credit agencies? Are there other services that do something like this that aren't the big three credit agencies?

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#298
post #291

Earlier quoted context omitted.

>People in technical leadership roles should have formal training and should have spent some time in the trenches, full stop. We hold most other specialized leadership roles to this standard: Chief Financial Officers, Chief Legal Officers, Chief Medical Officers, etc. Why not CTOs and CISOs? The vast majority of qualified candidates will not have relevant formal training. Until very recently it's been borderline impo…

Seriously? It's not the 1990s. You will never convince me that Equifax could not have hired a CISO with decades of relevant IC and leadership experience and appropriate educational background. Perhaps Maudin at the time she was hired, I'm not sure the length of her tenure. But there was certainly no excuse for choosing an MBA without IC cybersecurity experience for her replacement. (Who, btw, is a man and also wildly…

>You will never convince me that Equifax could not have hired a CISO without decades of relevant IC and leadership experience and appropriate educational background.

If it's so easy, surely you can name a couple of people with decades of relevant IC and leadership experience and appropriate educational background who they could have hired back when they went with Maudin?

>1. Equifax majorly shit the bed on cybersecurity, and the buck stops at the CISO.

The buck never stops at the CISO, just like it supposedly didn't at Twitter.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#299
post #267

Earlier quoted context omitted.

Quoted post unavailable.

The only person that made this about the CISOs gender is you. OPs point was about the lack of credentials, which would apply to anyone. I think it's a reasonable conclusion to draw, due to the nature of the very sensitive data at risk. Having professional accreditation that you should be overseeing the security of peoples most sensitive information is objectively a good idea. Muddying the conversation with virtual si…

They were stating the facts around the Equifax breach which is on topic. What is a surprise is the conversation being derailed because someone wanted to make their comment about gender. It isn’t.

https://archive.ph/Afnyl

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#300
post #267

Earlier quoted context omitted.

Quoted post unavailable.

The only person that made this about the CISOs gender is you. OPs point was about the lack of credentials, which would apply to anyone. I think it's a reasonable conclusion to draw, due to the nature of the very sensitive data at risk. Having professional accreditation that you should be overseeing the security of peoples most sensitive information is objectively a good idea. Muddying the conversation with virtual si…

>The only person that made this about the CISOs gender is you. OPs point was about the lack of credentials, which would apply to anyone.

Except it seemingly doesn't apply to literally every other CISO. Does the CISO at Meta have a relevant degree? No. Did Mudge have a relevant degree while he was the CISO at Twitter? No, he also had a music degree. Does Coinbase CISO in charge of securing many billions hold a relevant degree? Nope. Does the CISO at Stripe hold a relevant degree? Again nope.

>Having professional accreditation that you should be overseeing the security of peoples most sensitive information is objectively a good idea.

It's a good idea, yes! Did some meaningful professional accreditation exist at the time? Nope!

Post reply on HN