Deloitte formed a team consisting of security analysts and experts from both within and outside the firm to conduct a formal inquiry to the breach. The goals were to understand how this happened, assess the scope of the incident, determine what the attacker targeted, evaluate the potential impact to clients, and determine the appropriate cyber-security response. After six months elapsed time, the team determined that the attacker was no longer in the email system, ascertained that there had been no business disruption to any of its clients, and recommended additional steps to enhance Deloitte’s overall security. The team was unable to determine whether a lone wolf, business rivals, or state-sponsored hackers were responsible.
The attack illustrates that any organization can fall prey to a cyberattack even those whose specialty is to stop them.
Critical Thinking Questions
1.Identify what you believe to be the area of most severe consequences for Deloitte direct impact, business disruption, recovery, legal, or reputation. Justify your response.
2.How would you evaluate Deloitte’s response to this cyberattack? What did they do well? Where could they have done better?
3.Identify the three highest priority changes that need to be made to the Deloitte security program.