Hacking the AIS
Hacking refers to the process of accessing digital devices, including computers, phones, and tablets, without permission. Hackers often gain access to computer systems by exploiting software flaws and configuration. They can also gain access by using stolen passwords. Once the hackers gain access, they impersonate legitimate users to alter data and its configuration or manipulate the devices that linked to the hacked computer. Hackers break network security for various reasons. Some do it to hone their coding skills, others for the challenge while others do it for monetary gain. Hacking has also being used as a form of corporate espionage where the hackers steal information from an organization to gain a competitive advantage. Nonetheless, hacking causes financial losses of varying proportions. The loss is incurred by paying the hackers ransomware to release stolen data or paying network security experts to fix the security loopholes. Hacking can lead to loss of sensitive data either through the files being altered or deleted. Hacking also leads to compromised privacy when they access social networking accounts and email, which can also lead to identity theft. Identity theft can cause problems with the law if the stolen identity is linked to crime and can reduce credit ratings. Further, hackers damage the reputation of the organization whose security they breach. Companies whose security has been breached multiple times might lose customers since there is a high chance that their personal information will be compromised. Don't use plagiarised sources.Get your custom essay just from $11/page
QUESTION 1
In July 2019, U.S bank, Capital One, announced that hackers had caused a major data breach that affected more than 100 million customers, including six million Canadians and 100 million Americans (Leonhardt, 2019). The bank explained that hackers gained access to the data by misconfiguring the firewall installed for the bank’s web application allowing the hackers a communication channel with the bankers’ server where the information was stored. The company explained that the hackers obtained customer application information dating from 2005 to early 2019. The breached data comprised of personal information, including zip codes, names, addresses, phone numbers, and email addresses. Additionally, social security numbers and bank numbers for about 140, 000 U.S based credit card customers was compromised. The hackers also accessed about 80,000 credit card numbers for customers who had lined their bank account numbers. The hack was unique due to the large scale breach of sensitive personal data, including that of Social Security numbers. The bank explained that the breach could cost about $300 million, including expenses for credit monitoring for the affected customers.
QUESTION 2
The breach of personal data for Capital One capital affected more than 100 million customers of a financial institution was one of the most significant data breaches in history. After the hacking incident, Capital One Bank took responsibility for the security flaws that caused the data breach. It explained that it would contact all Americans whose linked bank account numbers and Social Security numbers were affected by the hack. The bank also said that some data that had been previously encrypted had been decrypted. The breach was discovered by an individual who found the breach in another online forum and submitted a vulnerability report to the bank through the bank vulnerability email. Thus, the bank security system is enhanced by the vulnerability disclosure policy. After the report, the bank responded quickly, and the perpetrator was arrested within two weeks. Further, the bank said it had addressed the exploit that the hackers used to access customer data. Moreover, officials explained that it was working with federal law enforcement for a comprehensive inquiry into the breach. The bank’s chief executive and chairman also said that while he was grateful that the culprits had been caught he apologized for the breach and pointed that the bank he was “committed to making things right” (Barrett, 2019). The bank explained that it would also reach out to all affected customers so that it can offer free identity protection and credit card monitoring. Capital One also advised its customers that they should take of the fraud detection technology within the bank, which includes account alert for suspicious activity. Customers were asked to look out for phishing emails. Security experts at the bank said that they would regularly test their firewalls to deter future attacks. Thus, Capital One took responsibility for the security breach by offering card free card protection services and fixing the exploits that the hackers had used.
QUESTION 3
Progressive software vendors that securing their products us a critical business requirement. Assuming that Capital One uses a third-party accounting system, the software provider assumes the security of both the business and its clients. The vendor is expected to review the security of the software at each software development lifecycle, from requirements definition to testing. The third-party software provider is also expected to use third PARTY security companies to conduct independent and comprehensive assessments on all its products. Software vendors are also expected to have a team of white hat hackers who pose as malicious users. The efforts of internal attackers complement the third party security tests. The software vendors are also expected to use automated tools during code review to assess the security of their products. The automated tools should be sourced from reputable vendors. The vendors should also have a team that is dedicated to evaluating and responding to various security vulnerabilities that are reported by clients. The incident response team should determine the seriousness and extent of reported vulnerabilities and partner with development teams to provide timely responses to their customers. Software vendors should also release thoroughly tested patches for their products regularly. The released patches should use popular configuration systems that user-friendly for the clients. Further, for each vulnerability identified, a threat profile should be provided when releasing a patch. The vendors should also publicly disclose all the vulnerabilities that might affect the software.
QUESTION 4
Since the advent of the internet, criminal defense lawyers have often helped hackers receive relatively less severe sentencing in law courts. Additional regulation can prevent hackers from targeting businesses and disrupting work. The additional regulation should work across national jurisdictions, which would ensure a stable global internet system. A cross border initiative would deter hackers from carrying out their activities as law enforcement would easily catch them from anywhere in the world. Presently, hacking is classified under misdemeanors, and penalties include jail time, retribution, and criminal fines. Using the stolen information results in a felony charge. However, hacking to computers owned by the U.S Government can result in more severe penalties as stipulated in the Computer Fraud and Abuse Act. As a result, it is rare for ordinary citizens to hack into government computers due to the harsh laws. Similarly, the current hacking laws should be amended to carry severe penalties as those for hacking into federal computers. Such regulation would deter hackers from attacking businesses and individuals.
QUESTION 5
Businesses can secure their assets and system from hackers by training their teams about company security protocols that involve computers. The training should entail how to detect security risks, including phishing scams. The business should also secure their software by running only recent versions since such software has the latest security updates. Additionally, companies should upgrade access controls by regularly reviewing the requirements for usernames and passwords. Default passwords should be changed and ensure that every employee has strong passwords. Businesses should also back up their data regularly. They can also partner with IT service providers so that their data is routinely backed up. Businesses should also encrypt sensitive customer data so that in case of a data breach, the impact is minimized. Companies should also review their internet service providers to ensure that their internet package consists of inbuilt security features.
In conclusion, hacking is the unauthorized access to a computer and computer-related devices and often results in a breach of data security. The motivation for hacking includes improving coding skills for the challenge, while others do it for monetary gain. Hacking causes financial losses due to the expenses incurred, paying the hackers’ ransomware to release stolen data or paying network security experts to fix the security loopholes and compensating customers. Major corporations that have been hacked include U.S based bank, Capital One, where hackers caused a major data breach that affected more than 100 million customers, including six million Canadians and 100 million Americans. The company took responsibility for the security breach by offering card free card protection services and fixing the exploits that the hackers had used. Further, the current hacking laws should be amended to carry severe penalties as those for hacking into federal computers. Businesses can improve their security through training their employees, reviewing their software updates, and using reputable internet service providers.
References
Barrett, D. (2019). Retrieved from https://www.washingtonpost.com/national-security/capital-one-data-breach-compromises-tens-of-millions-of-credit-card-applications-fbi-says/2019/07/29/72114cc2-b243-11e9-8f6c-7828e68cb15f_story.html
Leonhardt, M. (2019, December 17). The 5 biggest data hacks of 2019. Retrieved from https://www.cnbc.com/2019/12/17/the-5-biggest-data-hacks-of-2019.html