Live data from Hacker News

Former Equifax CEO says breach boiled down to one person not doing their job

techcrunch.com

31–39 of 39 posts

Re: Former Equifax CEO says breach boiled down to one person not doing their job

#31
IMO, the board of a public company is responsible for overseeing risk, audit and internal controls, and the CEO is the one person most responsible for ensuring the company acts in accordance with those directives on a day-to-day basis. That an error could be made by a worker is human, though an automated system could also suffer a fault. Audit would have caught a gap, risk management would have caught a vulnerability, and internal controls would have detected incomplete work were these practices properly designed and deployed. Good CEOs look at governance, process, oversight and don't fling muck at employees.

Re: Former Equifax CEO says breach boiled down to one person not doing their job

#32

This is how it always goes down. - F*ck your customers over by gross negligence and sheer greed (or stupidity, or both) - Get caught with your pants down - Dump your stocks and cash out - Apologize when customers and media express outrage - Go to Congressional hearing and repeat the magic words "I do not recall" for every question - Find 1 low-level scapegoat employee - Fire that employee and declare that the company…

As of 2016 you can now add to the list "suspected state actors." How could any private company be responsible for being able to stop this?

Re: Former Equifax CEO says breach boiled down to one person not doing their job

#34

There's a mantra at my company that you can't assign blame for a problem to a particular person. If one person is capable of breaking your system, you have a bad system. The focus isn't on finding the one person or the one mistake that caused it, but fixing the process so one person or one mistake can't wreak that much havoc. I think it's a very good philosophy.

Has this mantra been stress-tested in the real world with a large scale data breach? Edit: to add to his, what I mean to say is: it's great that (some) companies have this culture internally. It remains to be seen whether the mantra would survive a sufficiently large scandal. Maybe that's when the legal team comes in with the damage control plan as outlined in another comment by @justboxing.

I work for AWS. We haven't had a breach, but consider that S3 outage not too long ago, which was due to one engineer fat-fingering a command. Rather than blaming or disciplining that person, AWS changed the process so that people aren't manually typing in those commands.

Re: Former Equifax CEO says breach boiled down to one person not doing their job

#36

This is shamefully terrible leadership. If you're the CEO and a subordinate fucks up, it means you fucked up. At the end of the day the performance of the entire company is your responsibility.

It's not leadership at all.

Re: Former Equifax CEO says breach boiled down to one person not doing their job

#37

There's a mantra at my company that you can't assign blame for a problem to a particular person. If one person is capable of breaking your system, you have a bad system. The focus isn't on finding the one person or the one mistake that caused it, but fixing the process so one person or one mistake can't wreak that much havoc. I think it's a very good philosophy.

"we built a workflow that allowed one person to ruin the company."

that's one heckuva excuse, dude.

Re: Former Equifax CEO says breach boiled down to one person not doing their job

#38
post #22

Earlier quoted context omitted.

Bought a book mentioned in another thread about understanding system failures. If the conclusion blames an individual then 100% of the time the real problem is with the system that gave them that much power.

What's the book? Would like to add to my reading list :)

And here I thought I could avoid grabbing it from my shelf...

"The Field Guide to Understanding 'Human Error'" by Sidney Dekker.

Post reply on HN