Another Day, Another Hack
A 2017 breach note about CEX, stored card data, GDPR pressure, and why reactive security is never the cheaper option.
Original LinkedIn versionI had just written my first article in a few months yesterday about a 711 million record breach being reported. Today, there’s another breach that’s been made public. Not quite as big as yesterday’s, but still notable by the new agencies.
Complete Entertainment Exchange (or CEX) announced a data breach including usernames, emails, passwords and most terrifyingly Credit Card Details.
It should be noted that the credit card details in question have aged, as CEX stopped storing Credit Card Details in 2009. So most, if not all, details should be too old to be useful to anyone.
My favourite part of this story came in the final lines of the BBC Article.
Great news. Fantastic news! Awareness! But the issue that I have with this is that the approach most companies are taking to breaches like this. They’re not being proactive and shoring up their defences BEFORE an event of this type affects them. It’s only after their first or sometimes second breach that it’s considered.
This can be linked to an argument for preparing for the General Data Protection Regulations and highlighting the fact that if a company was to be breached and have secure data shared which was covered under the GDPR then the company in question may not be able to afford a “Cyber-Security Specialist” to prevent the next one. With potential fines of up to 4% turnover or €20million, a preventative Cyber-Security specialist is a much less bitter pill to swallow.