As a regular shopper at Target, I’ve been closely following the data breach ordeal. This week, I learned that the company did, in fact, have security intelligence in place, but the company’s Security Operations Center (SOC) didn’t react in time to prevent the damage. Astonishing!
It’s my hope that the following questions will eventually be answered, too:
While Target had good intentions with regards to protecting consumers’ personal information, it was a costly oversight to not strictly enforce a security “code of conduct” for SOC employees. This was a key contributor to the successful execution of the breach. Security technology alone cannot detect and stop attackers from stealing valuable data. Rather, only the successful synchronization of technology, people, and processes can.
What do you think? Would love to hear!
Can't agree with you more Seema. PCI DSS is no more than a framework of specifications and guidelines thats it. If there is no leadership in place to drive collaboration across organizational silos then those attempting to implement PCI or any other compliance mandate initiative can end up with a Target like breach.