April 15, 2018
Problem: According to a new internal investigation. The internet pioneer, which reported a massive data breach involving 500 million user accounts in September, actually knew an intrusion had occurred back in 2014, but allegedly botched its response.The findings were made in a Yahoo securities exchange filing on Wednesday that offered more details about the 2014 breach, which the company has blamed on a state-sponsored hacker.That breach, which only became public last year, involved the theft of user account details such as email addresses, telephone numbers, and hashed passwords. After Yahoo went public with it, the company established an independent committee to investigate the matter.
Solution:
1)Employees must pay attention to the emails they open in their Inbox, and they must avoid opening suspicious emails that contain links in particular. Training in the areas of compliance, authorization, employee identity, and the like should also be given.
2)Data must always be backed up to mitigate the risk of breaches. One full backup should be done locally, within the company premises. The second backup must be to a remote location, using online backup solutions.Whether locally or to a remote location, the backups must continue.
3)company software should be updated regularly: ERP systems, MS Office, anti-virus programs, and any other company-specific software must always be updated. IT must allocate enough budget, resources, and time for patches and updates.