Target's network security protocols and vendor access controls
Critique of Target Hack
Protocols
The Krebs article describes the Target hack, but does not list company protocols, nor would those typically be made public anyway. In any case, Target either did not have effective protocols or did not follow them. For Target, probably the most important set of protocols would be those concerning how the company would limit access to its network. The hack occurred when the hackers were able to enter Target’s network through one of its vendors, via malware that was clicked in an email. The malware spread into Target’s network, including all of its point-of-sale devices. There were no controls that would limit access so that somebody entering the network from one point was able to freely move around the network.
Thus, Target needs to have protocols that define the freedom of movement that any one vendor might have with respect to accessing the company’s network. A company that operates in a limited regional area, such as Fazio, might only be allowed access to a certain geography under such a regime, but the protocol could also be drawn up in such a way that companies are limited to what devices they can access, with appropriate firewalls in place to ensure that hackers cannot move freely. If Fazio’s technicians needed remote access to certain parts of the network to manage their HVAC stuff, then they should only have access to that HVAC stuff – granular permissioning for network access could be done either by device type or by geography under the protocol, if not both, and that would be vastly superior to the system that Target had in place wherein no such protocol existed.
Furthermore, Target should have had a system whereby it could vet the security practices of its vendors. If there is some security credentialing that demonstrates a vendor has adequate controls, tech stack and training, then such a credential should be mandatory for vendors. This is fairly standard in a lot of industries, particularly health care, defense and others where sensitive data is handled. If Fazio didn’t have such credentials they would not have been a vendor for Target in the first place. Holding vendors to strict protocols on things like cybersecurity is quite common for enterprise clients, and especially when those vendors are going to need access to parts of the client’s networks.
These protocols would have two impacts. First, they would reduce the likelihood of a hack succeeding against Target. The hack was fairly easy to execute, and relied on poor training on the part of Fazio employees. But this means of hacking is entirely predictable, and so steps to prevent common methods of hacking would certainly have reduced the risk of a hack attack succeeding.
Furthermore, the protocols would limit the potential damage. The hackers themselves were probably rather surprised at the access they got from this attack, as it would have been unusual to gain such unfettered access to an entire network, including unsecured point of sale systems. The reality is that Target’s new protocols would at least increase the odds of the company containing the hack. If Target, as happened, did not find out about the hack immediately, then the malicious actors would be able to gather information from wherever they had access. By taking steps to limit access, or make it more difficult for criminals to bypass firewalls and other security precautions, Target could have better contained the damage so that the information of its entire customer base wasn’t stolen. By taking steps to contain the damage, Target reduces its legal liability even in the event of a successful hack. Damages would be less, and the more the potential damage is contained, the less liability the company would face. Imagine if hacking Fazio only gave the hackers access to the HVAC equipment, and how little liability Target would face under that scenario. That scenario was entirely possible, had the company taken adequate preventative measures to defend its networks against hacks. We do not even know to what degree Target monitors its networks, so Target might not have even had sufficient means to detect a hack.
Ethical Implications of Target Hack
There is nothing at all unethical about Target imposing protocols on the internal operations of its vendors. Indeed, that should be mandatory. The decision by a company to do business with a vendor is simply a business deal, and should the vendor not be able to meet the conditions that the two companies negotiated as part of the contract, then Target does have both a legal right and an ethical imperative to impose conditions, up to and including voiding the contract with the vendor. In fact, Target has an ethical imperative to its clients – to the forty million people whom it owes a fiduciary duty of care to handle personal financial information securely – to insist that vendors meet its strict standards.
While this certainly has the outcome of reducing Target’s liability, the action itself has nothing to do with liability, but the duty of care that Target owes those who have entrusted it with their personal financial information. Target reduces its liability by reducing the risk that its clients face when dealing with Target. What Target did – either not have standards or ignore them – is the unethical action, because consumers have a reasonable expectation that a major company with the financial ability to protect their data should have implemented reasonable measures to do so. The ethical violation for Target is what it did, not the imposition of strict protocols to which its vendors must adhere – that’s something that gets negotiated and would be a standard part of any vendor contract that Target would sign.
Fault for Target Hack
Both Target and Fazio are at fault, and there is no “more fault” or “less fault” in this scenario. Both companies failed to secure the customer data, despite both companies having full knowledge that hackers exist, that they like to target enterprises, and that they like to steal financial data like credit card numbers. None of this would have been a mystery to either company. Nor would the concept of malware, malware embedded in emails, or anything else. The reality is that the entire hack was done using means that should have been fully known by both Target and Fazio, and despite this neither company attempted to defend against such attacks.
For Fazio’s part, the company clearly did not train its employees. The hack may have been malware, but an employee clicking on an email without knowing what the link is could just as well have been a phishing attack, ransomware, or something else. Fazio having not trained its employees – or its employees not taking the training seriously – is certainly one of the causes of the breach, and one that cannot be ignored.
However, Target was vulnerable, due to weaknesses in its own security regime. Had the attack not come through Fazio, it could easily have come from another equally sloppy vendor. As such, Target has to accept a substantial amount of responsibility as well. It did not need to grant Fazio unlimited access to its networks in order for Fazio to do its job. By virtue of Target not having the proper systems and protocols in place to defend against this type of hack, Target definitely takes fault.
Furthermore, there really was no excuse for Target to have such a glaring lack of internal defenses against hacks. As a large company that collects and stores personal and financial information on millions of customers, Target should clearly have known that it had a bullseye on its back for hackers. It was negligent and unethical for Target to not have any internal defenses. Furthermore, Target does not seem to have held its vendors to any standard. The only correct thing for Target to do is to ensure that any third party vendor it deals with has sufficient security protocols, and that any third party vendor would also have training that aligns with Target’s needs for cybersecurity.
When two companies both commit egregious errors that lead to a hack like this, there is no “more” or “less” culpable. They are both equally culpable, both having the means to prevent the hack, the reasonable expectation that such an attack could occur, and neither having taken anywhere close to adequate preventative measures to ensure that the hack did not occur, and that if a hack did manage to happen, that damage could be contained.
All told, Target faced maximum liability for this hack, and that was because the company failed to take anything close to adequate preventative measures, either in terms of securing its own networks by compartmentalizing access so that a successful hack would only gain access to a limited amount of data. Had Fazio’s access been limited to the HVAC equipment it was servicing, the liability for Target would have been minimal. Furthermore, vetting of vendors would have either ruled out Fazio, or given Target the ability to insist that Fazio meets Target’s standards. Whether those standards did not exist, or were not enforced, Fazio should not have been a vendor for Target, nor should it have been given access to anything beyond what it needed to perform its role. So while Fazio clearly did not meet the cybersecurity grade, Target basically did nothing to help its own cause. In a situation where the liability could have been minimal, instead Target faces massive liability for the hack that saw financial information for millions of consumers stolen.
References
Krebs, B. (2015) Inside Target Corp, days after 2013 breach. Krebs on Security. Retrieved September 25, 2019 from https://krebsonsecurity.com/2015/09/inside-target-corp-days-after-2013-breach/
Create your account
Always verify citation format against your institution’s current style guide requirements.