Five Questions With: Doug White

Doug White is chair of cybersecurity and networking at Roger Williams University.

White, who co-hosts the podcast “Secure Digital Life,” talks with Providence Business News about the recent Equifax data breach, what people can do to protect themselves and whether we should expect to see similar attacks in the future.

The Most Undervalued Asset in Business: The Right Connection

By Emilio DiSpirito IV License Partner | Private Office Advisor Engel & Volkers Oceanside www.DiSpiritoteam.com…

Learn More

PBN: What do we know about how this Equifax information was compromised?

WHITE: They described it as a “web exploit.” Could mean a lot of different things but typically it’s some sort of hole in the website, which allowed a request to the database to be fulfilled and then dumps all the data to the hacker.

- Advertisement -

PBN: How – if at all – is it different from other major cyberattacks in recent years, i.e. Target, Yahoo?

WHITE: It’s different in the sense that financial credit agencies have a great deal of personal information that a department store wouldn’t have. It is similar to the OPM breach, which lost top-secret data.

PBN: How could this type of information be used in a harmful way?

WHITE: Identity theft is a prime vector. A common scam is to file false tax returns claiming refunds using social security numbers. The greater threat, in my opinion, is the use of this data for spear phishing attacks on users. Not to downplay the identity theft. The other threat is that combinations of personal information can be used to guess bank account logins, etc., if you use those.

PBN: What – if anything – should folks be doing to protect themselves? 

WHITE: Don’t panic, be vigilant about this data. When you are approached via phone, email, or mail (or even text messages), be careful what you give up. You can freeze your credit reports, which has a limited effect and subscribe to an identity protection service, but I think the ability of these to protect you is limited and the greatest risk is going to be scams.

PBN: Does anything signal to you that we won’t continue to see these types of massive cyberattacks in the future? Why or why not?

WHITE: These attacks will persist until several things happen:

  • There are significant penalties in place for organizations that allow personal data to be breached.
  • There is a true commitment to security on the part of these organizations (meaning continuous).
  • We need to stop using Social Security as an identification tool and use something more robust as an absolute identifier for our citizens.

Remember, even if they perfect their website, a spear phishing attack on an employee can breach the whole place easily. Security is not just a one-shot fix or an annual review, it requires layers, persistence and continuity if it is going to be effective. The first American bank robbery occurred in 1831, but we still have them today. Cybersecurity is no different.

Eli Sherman is a PBN staff writer. Email him at Sherman@PBN.com, or follow him on Twitter @Eli_Sherman.