Please wait while the transcript is being prepared...
0:04
Now, we're going to
look at a case study,
and this is a
well-documented incident.
There have been several
investigations into it,
more, even still ongoing.
So we're going to look
at a genuine company,
quite a well-known
one, and that is Uber.
0:20
Uber had an incident.
A breach exposed the data
of 57 million users,
which is a significant number.
That was both drivers
and passengers.
0:34
What happened was the breach
occurred in October 2016.
Shortly afterwards, Uber's
leadership authorised
a payment of $100000
through what's called
a bug bounty program.
Now, a bug bounty
program is where
an organisation pays
a bounty for people
to discover weaknesses
and vulnerabilities in
their software and report it,
rather than exploiting it.
In this case, that 57 million
dataset of users had
already been stolen.
That is not a bug bounty;
that is an incident.
However, they
authorised $100000,
called it a security report,
and got the attackers to sign
non-disclosure agreements.
They were already
under investigation
by the FTC for separate
privacy concerns.
So this was an organisation
where there were already
known concerns around
privacy and user data.
The breach wasn't revealed until
there was a change
of leadership.
A new CEO took over in 2017.
So it was actively and
deliberately concealed
from an ongoing investigation
into privacy concerns,
there were multiple,
not just the FTC,
but that's the one
we'll focus on,
until a change of
leadership happened.
The results were
severe, both for
the organisation and
for the company.
The company faced a
multimillion dollar fine
over the concealment.
The CISO, the chief
information security officer,
who was no longer with
the organisation,
faced a personal $50000 fine
and three years' probation,
reputational damage and
obviously severe
regulatory backlash.
Now, this was the
first case of a CISO
being found guilty over
concealing an incident.