{"id":2398,"date":"2018-04-02T13:02:11","date_gmt":"2018-04-02T19:02:11","guid":{"rendered":"https:\/\/www.kraftgrp.com\/under-armours-armor-gets-penetrated\/"},"modified":"2018-04-02T13:02:11","modified_gmt":"2018-04-02T19:02:11","slug":"under-armours-armor-gets-penetrated","status":"publish","type":"post","link":"https:\/\/www.kraftgrp.com\/under-armours-armor-gets-penetrated\/","title":{"rendered":"Under Armour\u2019s \u201cArmor Gets Penetrated\u201d"},"content":{"rendered":"
How Would It Cost Your Business If This Happened To You?<\/strong><\/p>\n Have you read the news? According to Reuters<\/a>, Under Armour Inc.<\/a>, headquartered in Baltimore, Maryland, recently suffered a breach of the private information for their 150 million MyFitnessPal<\/a> app users.<\/p>\n This is the largest breach this year according to experts. It included account usernames, email addresses, and passwords. Lucky for them, Social Security numbers, driver license numbers, and payment card data weren\u2019t stolen like they usually are in data breaches of this kind.<\/p>\n Once again we learn that keeping up to date on cybersecurity, changing passwords often, and using an IT support provider to implement a layered approach to security is essential if you want your business to stay safe in today\u2019s digital world.<\/p>\n Perhaps, if Under Armour had used these services, they could have prevented this breach. Now, their reputation has been ruined.<\/p>\n Would you trust your private data to them?<\/p>\n I wouldn\u2019t.<\/p>\n With so many data breaches today, they should have known better and considered the privacy of their customers. How can they salvage their creditability now?<\/p>\n As a business technology professional, I know that data protection costs much less than what I\u2019d face from a breach \u2013 legal liability, fines, and lost customers.<\/strong><\/p>\n With the rising number of cyber thefts, numerous lawsuits have been filed against businesses like Under Armour. In the last few years, data breaches have become so prevalent that it\u2019s almost commonplace to hear that a company has been breached.<\/p>\n Learning that all their personal information is in the hands of thieves causes a significant change in the behavior of customers. One study<\/a> found that consumers who learned of a data breach at their favorite retail store significantly cut back on their purchases.<\/p>\n With over 1,500 data breaches in 2017, consumers responded in this way:<\/strong><\/p>\n I know that my business has the best cybersecurity and IT management that money can buy. I take full responsibility for this and all my customers\u2019 private data.<\/p>\n After what I\u2019ve learned, this is what I would tell the CEO of Under Armour, and others to do from now on:<\/strong><\/p>\n Protecting your security isn\u2019t only a job for your IT support provider but one for you as a CEO as well. You must understand that any interruption in your information systems can hinder your operations, negatively impact your reputation, and compromise your customers\u2019 private data.<\/p>\n Many CEOs don\u2019t fully understand this. They spend their energy developing new products and services and managing current ones. Security comes in second. Maybe they\u2019re unaware of the risks or feel that it\u2019s solely an IT concern. Some may not be very technical and fear to discuss what could be an intimidating topic, but this isn\u2019t wise.<\/p>\n The Department of Homeland Security recommends five questions that CEOs should ask themselves to lower the risk of cyber attacks:<\/strong><\/p>\n 1) What is the current level and business impact of cyber risks to our company? What is our plan to address identified risks?<\/p>\n 2) How is our executive leadership informed about the current level and business impact of cyber risks to our company?<\/p>\n 3) How does our cybersecurity program apply industry standards and best practices?<\/p>\n 4) How many and what types of cyber incidents do we detect in a normal week? What is the threshold for notifying our executive leadership?<\/p>\n 5) How comprehensive is our cyber-incident response plan? How often is the plan tested?<\/p>\n We also need to train our employees on cybersecurity practices like recognizing phishing attacks and using secure passwords. The folks at OneSource handle this for us. Here are some of the topics they cover:<\/p>\n Lesson 1: Ignore Ransomware-Threat Popups and Don\u2019t Fall for Phishing Attacks.<\/em><\/strong><\/p>\n These threats look like they\u2019re from an official entity like the IRS or FBI. If a screen pops up that says you\u2019ll be fined if you don\u2019t follow their instructions, beware! If you do, the criminal will encrypt all your data and prevent you and your employees from accessing it.<\/p>\n Watch out for messages that:<\/strong><\/p>\n Don\u2019t believe messages that contain an urgent call to action:<\/strong><\/p>\n Be on the lookout for messages that:<\/strong><\/p>\n Watch for flags like:<\/strong><\/p>\n Lesson 2: Always Use Secure Passwords.<\/em><\/strong><\/p>\n Lesson 3: Keep Your Passwords Secure<\/em><\/strong><\/p>\n Lesson 4: Backup Your Data Onsite\/Remotely and Securely<\/em><\/strong><\/p>\n<\/p>\n
\n
\n
\n
\n
\n
\n
\n
\n
\n