833-847-3280
Schedule a Call

OPM Hack: Can it get any worse?

Last night I was asked on Fox News what I thought the impact of the OPM hack would be and I commented on the incredulous amount of information that has been stolen and the potential impact on over 21 million Americans. In my opinion, no more valuable a trove of information can be found outside of actually compromising our national defense systems.

For those of you that don’t have a security clearance, the information that is on these forms is staggering. Due to the fact that an initial security background has to be complete in order to properly “vet” the individual for access to classified data, applicants are required to pretty much place their entire life on this forms: addresses, positions, next of kin, SSN, criminal background, medical issues, drug use etc. I don’t know of one other single source of information that is so complete about an individual.

For this reason, I am astounded that, at a minimum, none of this data was at least considered critical enough to national security for it to be encrypted and possibly be declared classified. These “crown jewels” should not have been left in an antiquated IT architecture with 80 various agencies having access to it, without being protected. Even after the 2 contractors that had the contracts to conduct background checks were hacked, nothing was done to increase the security around this data and to keep it from nefarious hands.

The OPM and the Obama administration needs to move fast to fix this. Right now, there are 21 million Americans, including me, whose lives are now compromised and will be, for decades. This data must be taken off line and encrypted, if not placed behind a closed architecture with limited access. There must be some basic cyber security procedures taken such as these to at least provide this information with the protection it warrants. Making some easy decisions such as these and moving fast will show the American people that this cyber-attack is being taken seriously.

Assigning attribution for this hack and having a plan of attack to counter this threat should be of the highest priority. The American people should know that the data they entrust to the USG is safe and that those people or counties that violate that agreement will be punished. While the #1 culprit, presumably is China (and personally I agree that no other country has more to gain through the theft of this data), it is critical to identify the entity behind this act and resolve the damage through a combination of diplomatic, legal, economic or military action.

Oh, and 3 years of credit monitoring doesn’t even come close to compensating these victims for this hack. The USG should move to provide compensation for each American who has to find the time to fix identify theft associated with this. Additionally, creating a law enforcement capability or augmenting an existing agency such as the FBI to review stolen records and monitor various healthcare, insurance, tax and yes OPM systems for fraud, exploitation and impersonation would help provide the necessary increase in vigilance.

Latest Posts

A transparent image used for creating empty spaces in columns
With the release of PCI DSS 4.0, penetration testing is no longer viewed as just a once-a-year checkbox item. Instead, the standard takes a dynamic, risk-based approach that aligns testing with real-world threats, changes in system environments, and evolving business operations. Rather than applying a…
A transparent image used for creating empty spaces in columns
Penetration testing is one of the most powerful tools in an organization’s cybersecurity arsenal. But a test is only as valuable as the action it inspires. Too often, penetration test reports are treated as one-off exercises or compliance checkboxes. The real value comes when those…
A transparent image used for creating empty spaces in columns
As cyber threats grow more complex and persistent, regulatory frameworks like PCI DSS 4.0 have evolved to demand more rigorous and transparent security practices. One of the key updates in PCI DSS 4.0 is the enhanced requirement for penetration testing reports, pushing organizations to go…
A transparent image used for creating empty spaces in columns
A penetration test, also known as a pen test, is a crucial cybersecurity measure that enables organizations to identify vulnerabilities in their networks, applications, and security controls. However, the real value of a penetration test lies in how well an organization can interpret the findings…
A transparent image used for creating empty spaces in columns
The release of PCI DSS 4.0 introduces significant enhancements to the security landscape, particularly in the area of security controls and penetration testing. While penetration testing has always been a critical component in identifying vulnerabilities within a network or system, the updated PCI DSS standards…
A transparent image used for creating empty spaces in columns
Social engineering attacks remain one of the most effective ways cybercriminals gain access to sensitive information, systems, and financial assets. Phishing, pretexting, baiting, and other manipulative tactics exploit human psychology, making it difficult to defend against using technical measures alone. Organizations often use social engineering…
contact

Our Team

Name(Required)
This field is for validation purposes and should be left unchanged.
On Load
Where? .serviceMM
What? Mega Menu: Services