Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Downgrade Of Equifax By Moody’s Due To Cyber Breach
News & Analysis

Downgrade Of Equifax By Moody’s Due To Cyber Breach

ISBuzz TeamBy ISBuzz TeamMay 28, 2019Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In response to this week’s downgrade by Moody’s of Equifax as a result of its 2017 massive breach of consumer data, six cybersecurity and risk experts offer perspective on this ongoing issue.  

Laurence Pitt, Strategic Security Director at Juniper Networks: 

“A stock downgrade following cyber-attack is not a surprise, in fact it cements what we have been saying for a long time: Cybersecurity is a boardroom issue. Think about it – everyone is in business with a single goal which is to make money, this includes the bad-guys except that they want to make their money by preventing someone else from doing the same. When calculating cyber-risk for insurance or investment reasons a modern enterprise needs to consider brand, reputation and fiscal impact as highly as the cost incurred in the mitigation of an attack. Unless they give equal view to all areas, then cyber could finish up under invested which equals risk.”

“For the cybersecurity industry this signals the need for a chance in conversation – many of us, Juniper included, have made this change, but the bottom line is that it’s no longer enough to talk about product, software, function, speeds and feeds. Now that investment conversations are occurring at board-level we need to arm the security team with data that they can use to provide security insight to the board – not data about what something does for them, but information on how it will ensure their business remains protected against unknown future threats.”   

Byron Rashed, VP of Marketing at Centripetal: 

“Cybersecurity is now part of the business process and that includes cybersecurity posture as an asset and/or liability where the BOD/investors will take into account. Securing the network, and therefore securing client/IP/other PII or important data is crucial for the solvency of the company.  

“This will become a growing part of business moving forward like GDPR, CA Privacy Act, etc. that has gained momentum in the recent past. PII is extremely valuable to threat actors and this is no exception as to the liability and lack of reputation from such a breach that affects the business as a whole from the BOD to the sales team.  

“It’s really meant as a wake-up call to organizations, the cybersecurity industry is matured to deliver products, services and training, it’s up to businesses to take full advantage of this.” 

Gary Roboff, Senior Advisor at Shared Assessments:  

“This is a wake up call for the board, and that’s actually a good thing. Actions such as the one Moody has taken are designed to deliver a message, and we know that when boards are engaged in cybersecurity risk issues risk management practices improve, sometimes dramatically.  

“We may see more of these actions because cyber hygiene expectations are rising. GDPR and other recent regulations have upped the stakes for firms that don’t understand the amount of effort it takes to to provide optimal cyber risk mitigation.”  

George Wrenn, Founder and CEO at CyberSaint Security: 

“Especially in recent years, Boards of Directors must understand their riskiest assets and business endeavors from a cybersecurity risk management perspective. The CEO needs to be able to effectively communicate with metrics that those at the Board level can understand, effectively coupling both quantitative and qualitative risk and compliance analysis facilitated by concise, data-driven, and clear reporting structures. Large organizations are beginning to come up the curve on these ideas, and Boards are beginning to hold CEOs responsible for cybersecurity risk levels within their business. This shift means that CISOs and CEOs must work more closely together, and CISOs need a reporting mechanism to the CEO that takes cybersecurity risk and translates it to business terms that both the CEO and the Board can get behind and act upon.   

“This incident has forever changed how CISOs, CEOs, and Boards communicate on cybersecurity risk and compliance, and the means by which organizations will achieve this feedback loop. Organizations of all sizes, large enterprises especially, have to get up the curve today in order to future-proof themselves for the complexity of cybersecurity now and in the future. Not only do organizations need to comply to cybersecurity best practices, but they also need to be able to communicate their posture in risk terms to business leaders, and at a level of abstraction that the Board can understand, calling for a new type of integrated risk management and reporting solution to come support this shift.”

Catherine A. Allen, Chairman and CEO at The Santa-Fe Group: 

“This is a wake up call, along with pending suits, that cyber governance and best practices are key. Boards should have robust discussion on cyber practices, appropriate spending, risk or security committees and appropriate oversight. The patching issue with Equifax is an example of a lack of oversight and discussion.”  

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}