The other day I was cleaning out a drawer in my office when I came across something that made me stop and think. It wasn’t old tax documents or forgotten receipts. It was a stack of breach notification letters. Not one or two, but enough that I had to laugh at how ridiculous it has become.
Every one of those letters followed the same script. They all started with some variation of, “We recently identified unauthorized access to our systems.” They assured me that protecting my information is their highest priority, apologized for the inconvenience, explained that they had brought in cybersecurity experts to investigate, and, of course, offered me twelve or twenty-four months of complimentary credit monitoring.
I’ve been in cybersecurity for almost twenty-five years, and it’s gotten to the point where these letters barely surprise me anymore. In fact, I would argue that we’ve become conditioned to accept them as just another part of modern life. We read them, maybe sign up for the free credit monitoring, throw the letter in a drawer, and move on until the next company loses our information. Then the process repeats itself all over again.
That got me thinking: when did this become acceptable when did this become the norm?
Every day we are asked to hand over some of the most personal information imaginable. Our Social Security numbers, driver’s license numbers, dates of birth, financial information, medical records, tax documents, employment history, home addresses, and phone numbers are all stored in databases that we have little or no control over. In many cases, we don’t even have a choice. If you want healthcare, insurance, a mortgage, a job, or even many online services, you’re required to provide this information and trust that the organization collecting it will protect it.
Unfortunately, too often they don’t.
When a company suffers a breach, they certainly experience embarrassment and negative press. Their executives make public statements, lawyers become involved, and public relations teams work overtime to reassure customers that lessons have been learned. After a few news cycles, however, business largely returns to normal.
The customers, people like you and myself, don’t have that luxury.
We the people, the victims, are the ones who spend years wondering whether someone is going to open a credit card in their name, file fraudulent tax returns, or use their identity in ways they may not discover until much later. Some pieces of information simply cannot be changed. You can replace a credit card, but you can’t replace your date of birth. Replacing a Social Security number is extremely difficult and only granted under very limited circumstances. Once that information is exposed, there is a good chance it will continue circulating among cybercriminals for years, if not decades.
What frustrates me even more is that we’ve somehow accepted free credit monitoring as an appropriate remedy. Let’s be honest about what credit monitoring actually does. It doesn’t prevent criminals from stealing your identity. It doesn’t remove your information from the dark web. It doesn’t stop fraudulent accounts from being opened. It simply tells you that something bad may have already happened. That’s not protection, it’s notification after the damage has begun.
So why does this continue to happen?
In my experience, the answer is surprisingly simple. Too many organizations still view cybersecurity as an expense instead of a business necessity. I’ve heard every excuse imaginable over the years. “We’re too small to be targeted.” “Our IT department handles security.” “We already have antivirus.” “We’ve never been hacked before.” Why would anyone want to attack us?” Unfortunately, many of those same organizations eventually become clients because they’ve just experienced a ransomware attack or data breach.
The reality is that cybersecurity is rarely ignored because leaders don’t care about their customers. It’s ignored because the financial consequences of inadequate security often aren’t severe enough to justify significant investment, at least not until after the breach occurs. Companies perform risk calculations every day. They compare the cost of implementing stronger security against the potential cost of a breach. If the financial impact of a breach is manageable, security improvements often get postponed in favor of other priorities.
That equation has to change.
If an organization chooses to collect and profit from storing sensitive customer information, protecting that information should be treated as one of its most important responsibilities. Security shouldn’t be viewed as a compliance exercise or a box to check during an annual audit. It should be considered part of the organization’s obligation to every customer who trusted them with their personal information.
This is also why I continually remind people that cybersecurity isn’t an IT problem. It’s a leadership problem. Budgets are approved by executives. Risk decisions are made in boardrooms. Priorities are established by leadership teams. When security projects are delayed, when aging infrastructure isn’t replaced, or when cybersecurity recommendations are pushed aside because they’re considered too expensive, those aren’t technical decisions. They’re business decisions.
And business decisions should carry business consequences.
Imagine if a construction company repeatedly built bridges that collapsed due to negligence. Or if an airline routinely failed to maintain its aircraft. We wouldn’t simply accept an apology, a promise to do better, and a coupon for future service. Yet when organizations expose millions of people’s personal information, we’ve somehow normalized the idea that a carefully worded apology and a year of credit monitoring is an adequate response.
I don’t believe it is.
As I looked at that stack of breach notification letters sitting on my desk, I realized that every envelope represented another company that promised to protect someone’s information and failed. Every letter represented thousands, or millions of people whose personal information is now permanently in the hands of criminals. Every one of them offered essentially the same solution, and every one of them left me asking the same question.
When are the consequences for organizations that fail to protect customer data going to become painful enough that preventing breaches becomes more important than managing them afterward?
Until that happens, I suspect that stack of breach notification letters on my desk is only going to keep getting taller.