1 / 7100%
Running Head: DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c 1
Data Breach Incident Analysis and Report
April 12,2022
DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 2
Introduction/Overview of the problem
In the current times, when risk and uncertainties in the online setting have surged, the
need for cyber insurance has magnified. Cyber insurance involves insurance products that can
safeguard businesses from cyber risks and threats. In the specific context of Padgett-Beale Inc.,
an investigation by its cyber insurance company has revealed that the company lacks the
readiness to respond to data breaches.
In order to evaluate the threats that data breaches can create for businesses a major
security incident involving Marriott Hotels, a well-known business entity in the hospitality
business domain has been examined. It was involved in a major cybersecurity incident in 2014
(Marriott Data Breach FAQ: What really happened? Hotel Tech Report, 2022).
Analysis
Data involve in Marriott International’s security breach
The security breach incident involving Marriott International compromised the credit
card details, birthdates and passport numbers of over 300 million guests that were stored in the
company’s global guest reservation database. The incident specifically involved Starwood
Network which was acquired by Marriott in the year 2016. The hackers who were responsible
for the incident had encrypted the sensitive data and removed it from the system of Starwood
Network. The guest information that had been stolen by the malicious actors included name,
phone numbers, Starwood Preferred Guest (SPG) account information, gender, arrival as well as
departure information, communication preferences and the date of reservation (Marriott Data
Breach FAQ: What really happened? Hotel Tech Report, 2022). It harmed the business as well
as the affected guests. Even though insurance covered a portion of the financial repercussions
DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 3
the business’ image and reputation was severely damaged. The guests were also adversely
affected since their sensitive and confidential details were compromised and were accessed by
hackers.
Findings by government agencies/courts on actions that Marriott International should
have taken
The findings by government agencies/courts revealed that the actions that Starwood
Hotels or Marriott International took were not sufficient to offer protection against
cybercriminals. Even though cybercriminals had access to the sensitive IT ecosystem for a long
time, the business was unaware of the situation because of the existence of a weak, ineffective
and insecure system (Marriott Data Breach FAQ: What really happened? Hotel Tech Report,
2022). The ICO found that the business had failed to introduce in place appropriate technical or
organizational measures to safeguard the personal data that was being processed on its IT
systems, as required by the General Data Protection Regulation (Ico fines Marriott International
Inc £18.4million for failing to keep customers' personal data secure. ICO, 2020).
After the incident occurred, Marriott International should have carried out a
comprehensive and thorough taken due diligence of the IT system of Starwood Network. This
step would have helped to identify the loopholes and vulnerabilities that could have been
exploited by online hackers and cybercriminals. As Starwood was notorious for having an
insecure reservation system, it was a necessity to inspect the IT system of the division and mend
existing gaps. It could have also included additional IT staff to perform due diligence of the
entire system to ensure its security (Marriott Data Breach FAQ: What really happened? Hotel
Tech Report, 2022).
DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 4
Findings by government agencies / courts on liability and penalties
Marriott International faced significant fines and penalties as a result of the data breach
incident involving Starwood Network. Several class a-action lawsuits were filed against the
hospitality business and it agreed to pay for the passport replacements of the customers who
were victims of the incident. The business was also fined $ 23.8 million by the Information
Commissioner’s Office (ICO) which is known as U.K.’s customer rights watchdog (Marriott
Data Breach FAQ: What really happened? Hotel Tech Report, 2022). The original fine that was
charged on the company was $ 123 million because of the infringement of the General Data
Protection Regulation (Whittaker, 2019). It is considered to be a large fine amount that has been
charged to a business for breach of its cybersecurity.
A review of best practices
Several best practices have been identified relating to people, processes, policies and
technologies that Padgett-Beale, Inc. needs to focus upon to strengthen its cybersecurity
framework.
The workforce must be provided training on the cybersecurity aspects and the latest
legislation so that they can play a proactive role to counter cyber threats. The focus on
the people factor is critical because they can sometimes act as the weakest link in the
cyber domain (Chalico, 2022). By training them their technical skills can be enhanced
and they can be empowered to reduce vulnerability of a business in the online setting.
It is critical to introduced effective and robust technologies like intrusion detection and
prevention systems, firewalls, antivirus software, etc. Organizations must leverage such
DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 5
technology-based security tools in order to reduce the scope of cybercriminals to invade
their digital ecosystems.
Stringent policies relating to data encryption, bring your own device (BYOD) and other
aspects must be introduced and strictly adhered to. These policies must be followed in a
consistent manner to ensure that a proper code of conduct from employees can be
expected in the work setting. c
A robust risk management regime or process must be in place to ensure that the
organization can regularly assess the risks that may arise and affect its digital assets or
information resources. Having a well-defined risk management process in place can help
to evaluate risks that may arise online and take suitable response measures to deal with
them (Cyber Risk Management Service. IT Governance, 2021).
The user privileges must be managed in a cautious and strategic manner in order to
ensure that no staff or internal member would be able to abuse the rights that have been
given. The principle of least privilege must be followed within the organization so that
individuals will have restricted rights based on their specific job roles and they would
require permission or approval to require extra rights.
Summary
Organizations face a diverse range of challenges in the virtual setting. The risk that they
encounter from cybercriminals or online attackers have the potential to threaten their very
existence in the market setting. A useful instrument that has come into existence to safeguard
organizations from malicious actors is cyber insurance. However, it is essential for companies to
have in place a robust cybersecurity framework. The cybersecurity incident involving Marriott
Hotels has been analyzed which shows how the lack of due diligence and the establishment of a
DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 6
proper cybersecurity framework can compromise the cybersecurity system. Several best
practices have been identified that companies must focus upon to strengthen their cyber security
framework.
References
Chalico, C. P. (2022, March 11). Your employees are The weakest link in your cybersecurity
chain. Are humans the weakest link in cybersecurity? | EY Canada. Retrieved April 25,
2022, from https://www.ey.com/en_ca/cybersecurity/your-employees-are-the-weakest-
link-in-your-cybersecurity-
chain#:~:text=People%20are%20often%20the%20prime,aware%20of%20the%20associate
d%20risks.&text=of%20Canadian%20respondents%20consider%20careless,top%20vulner
ability%20to%20a%20cyberattack.
Cyber Risk Management Service. IT Governance. (2021). Retrieved April 25, 2022, from
https://www.itgovernance.co.uk/cyber-security-risk-
management#:~:text=The%20cyber%20risk%20management%20process&text=Analyse%
20the%20severity%20of%20each,to%20respond%20to%20each%20risk.
Ico fines Marriott International Inc £18.4million for failing to keep customers' personal data
secure. ICO. (2020). Retrieved April 25, 2022, from https://ico.org.uk/about-the-ico/news-
and-events/news-and-blogs/2020/10/ico-fines-marriott-international-inc-184million-for-
failing-to-keep-customers-personal-data-
secure/#:~:text=The%20ICO%20has%20fined%20Marriott,Hotels%20and%20Resorts%20
Worldwide%20Inc.
DATA BREACH c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 7
Marriott Data Breach FAQ: What really happened? Hotel Tech Report. (2022, January 26).
Retrieved April 25, 2022, from https://hoteltechreport.com/news/marriott-data-breach
Whittaker, Z. (2019, July 10). Marriott to face $123 million fine by UK authorities over Data
Breach. TechCrunch. Retrieved April 25, 2022, from
https://techcrunch.com/2019/07/09/marriott-data-breach-uk-fine/
Students also viewed