Importance of Due diligence
If you are a CISO, then you must ensure your company has a corporate security policy. Ideally, you should have a full set of security policies, as listed earlier in the chapter. If your company is hacked, whether you have a security policy or not, it can be used as evidence that your company has or has not done its due diligence to ensure the company’s network is secure. After the notorious Equifax hack, in subsequent legal filings, Equifax was cited as having a poor security policy and not doing its due diligence in protecting its network. More specifically, the 2019 class action lawsuit states deficiencies such as using a username and password of “admin” on an externally facing portal that stored PII data. The lawsuit goes on to state Equifax was not using known good cybersecurity hygiene practices, such as multi-factor authentication, nor adequately monitoring its own networks9. It’s bad enough getting hacked, but then to have...