Why ‘blaming the intern’ won’t save startups from cybersecurity liability – TechCrunch

-


SolarWinds is back in hot water after a shareholder lawsuit accused the company of poor security practices, which they say allowed hackers to break into at least nine U.S. government agencies and hundreds of companies.

The lawsuit said SolarWinds used an easily guessable password “solarwinds123” on an update server, which was subsequently breached by hackers “likely Russian in origin.” Former SolarWinds chief executive Sudhakar Ramakrishna, speaking at a congressional hearing in March, blamed the poor password on an intern.

There are countless cases of companies bearing the brunt from breaches caused by vendors and contractors across the supply chain.

Experts are still trying to understand just how the hackers broke into SolarWinds servers. But the weak password does reveal wider issues about the company’s security practices — including how the easily guessable password was allowed to be set to begin with.

Even if the intern is held culpable, SolarWinds still faces what’s known as vicarious liability — and that can lead to hefty penalties.



Source link

Ariel Shapiro
Ariel Shapiro
Uncovering the latest of tech and business.

Latest news

Anduril might build a weapons factory in the UK

Factories are all the rage in defense tech: Anduril announced a billion-dollar ‘megafactory’ in Ohio earlier this year,...

Hungryroot Is Maybe the AI-Guided Meal Plan of the Future. The Present Is Much More Familiar

My colleague Molly Higgins, who is vegan, simultaneously tested out her own very different goals and preferences on...

Startups Weekly: Wiz’s bet paid off in an M&A-rich week

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups....

Wayve CEO shares his key ingredients for scaling autonomous driving tech 

Wayve co-founder and CEO Alex Kendall sees promise in bringing his autonomous vehicle startup’s tech to market. That...

Must read

You might also likeRELATED
Recommended to you