Equifax ratchets up security

Feature
Apr 30, 20078 mins

Three-year project aims at global consolidation of security services

As one of the three big credit-reporting agencies in the country, Equifax keeps personal and financial data on 300 million consumers. Here are the steps it took to strengthen its security.

Don’t let compliance drive security


“Historically, security [at Equifax] was very departmental. You’ll have one department that does compliance and has some security people, some [employees] doing access control, some other folks managing firewalls,” says Tony Spinelli, senior vice president of information security.

With 4,600 employees working in 14 countries, each business unit and geography dealt with the rising tide of security concerns and compliance requirements by implementing technology and policies based on that group’s specific needs. “We had a strong security program in pockets, but with the new and emerging risks” the company knew that wasn’t enough, he says.

Tony Spinelli, senior VP, information security

Considering that an interconnected, global organization’s security is only as good as its weakest link, this departmental approach is not recommended by experts. “It’s the kind of thing that should be centralized,” says Rich Mogull, an analyst at Gartner.

Seeking centralized security

Unless the functions of individual units within an enterprise are vastly different, centralized security is more effective and easier to manage, he says. “If someone attacks Equifax, they’re going to come through the main door — their Web site.”

By 2005, with security risks and compliance requirements mounting (see related story), Equifax’s executive team knew it had to take action. In September of that year, the company hired Spinelli and charged him with evaluating the corporation’s security stance and bringing less-secure units and geographies up to par by setting companywide technology and policy standards. Spinelli, who had served as a security officer at First Data and was a founder of Ernst & Young subsidiary eSecurityOnline, knew the importance of standardized IT security.

“We wanted to take a fresh look at how to turn security into a shared service to protect the enterprise,” he says. “We really wanted a strategic approach to security in the global enterprise, not just in business units.”

Spinelli and his corporate security and compliance team’s first step was to hire a consulting firm to perform a security assessment and determine the areas of low, medium and high risk.

Spinelli asked the firm to benchmark Equifax’s security level against the ISO 27001 specification, a standard for governing the security of information systems and networks. He wanted the company to be compared with the standards of “world-class security,” Spinelli says. “Then we could use the 10 tenants of ISO security and compliance” as goals. Spinelli also had the company’s own compliance team evaluate how well security was performed.

Global hot spots

From these assessments, Spinelli and his team created a “heat map” to clearly illustrate which areas of the company were less secure than others and prioritize fixes based on greatest need. Heat map in hand, Spinelli met with Equifax’s board of directors just weeks after he was hired, to present the results of these assessments and pitch a three-year, $15 million plan to reorganize security.

The heat map turned out to be particularly effective, not only in illustrating what areas of the company weren’t as secure as they should be, but also in demonstrating the advantages of making security a shared service.

“That was one slide that the executive team spent a lot of time on,” he says. Because officials could see by the color coding which units or geographies were up to par regarding security and using the limited shared services available — such as network monitoring — the chart painted a picture of effectiveness and efficiency for those areas.

Those departments “were spending the least amount of money to get maximum security, because they were relying on central controls,” Spinelli says. “What this shows is if you make the right investments in shared services, you can avoid duplicate investments.”

The board signed off on Spinelli’s project, and 105 days after being hired, he began implementing his plan. The first step was tearing down the existing security organizations, determining staffers’ core skills — whether they were operations, data-loss prevention, engineering, compliance — and regrouping them. Spinelli’s $15 million project included adding 43 positions over the life of the three-year plan. He became the IT security leader of Equifax’s new Security Council, designed to ensure the goals of the IT security, data security and physical security departments are aligned.

“The organization really has to match your strategy,” Spinelli says, and for Equifax that meant global execution. “I wanted to execute every strategic promise globally . . . the danger is if you do things that are U.S.-centric, you’re forgetting the risk of a system operating in the U.K. that’s attached to one in the U.S.; it’s risky if they’re not protected in the same manner.”

Tech fix focuses on endpoints

With the organization in place, next came the technology. Spinelli had budgeted $12 million in capital expenses, to be acquired over the three-year period. Key technology initiatives in 2006, the first year of the plan, included implementing Sun’s identity-management suite, Vontu’s data-loss prevention suite and hard-drive encryption protection from Pointsec Mobile Technologies, now a division of Check Point.

“One risk that was pointed out by the assessments was the [vulnerability] of our endpoints; that’s of vast concern,” he says. Last May a company laptop was stolen that contained personal information about its employees, though Equifax officials say no signs of identity theft resulting from that breach have surfaced. Pointsec’s encryption technology combined with RSA Security’s key token technology will protect against such risks in the future, he says.

With each technology expense, Spinelli wanted to be able to go back to the board and explain how the new hardware or software would heighten security. “For every initiative we wanted to do, say a firewall refresh, we had to explain how that improves one of those 10 [ISO 27001] tenets,” he says.

This year, the company plans to refresh all perimeter security hardware from ISS. It will also continue down some of the paths forged last year; having gotten Sun’s identity-management system running and connected to all the necessarily sources, this year Spinelli’s team will focus on gaining efficiencies from the suite, such as self-service password reset, simplified logon and role-based authorization.

Identity-management federation is planned for 2008. Additional technology purchases will be made next year, though Spinelli says it’s too soon to specify which ones.

Getting efficiencies out of security technology is a secondary goal, but an important one, Spinelli says. “We wanted to promise that if you really want to get to [the convenience of] single sign-on, first you focus on risk reduction, then you can add efficiencies and lastly cost avoidance,” he says.

Efficiencies and cost savings should be a goal of any security project, Gartner’s Mogull concurs.

“The goal of security isn’t just to protect, but also to do it as efficiently as possible,” he says. “With identity management, for example, you can actually provide some value back to your users.”

Reporting results

Spinelli went back to the board of directors in November to report results for the first year of the plan. He revised his heat map to show where risks were mitigated. “We had gotten rid of all the high-risk areas,” he says. “In ’07 we’ll do the medium ones, and in ’08 the low-risk areas.”

But although Spinelli’s plan hit its targets for the first year, and he’s optimistic about the remaining two, he knows that when it comes to discussing security with corporate executives, he needs to continuously manage expectations.

“I don’t want to give them the sense that every security risk in the future is now covered,” he says.

Step-by-step security

Spinelli offers advice about how to take a strategic approach to forming and implementing a risk-reduction plan.

Make sure the security plan you’re implementing is right for your organization, not simply that you’re implementing your plan well. “The righter we do the wrong things, the wronger we become,” Spinelli says. “The assumption that you’re right and you execute it efficiently doesn’t mean anything unless your basic strategy is right.”

To make sure your strategy is correct, you need to check twice. Perform an internal audit of your organization’s IT security based on your own and your staff’s perception of industry standards, then get an outsider’s opinion. An in-depth security assessment from a third party will open your eyes to risks not visible from within the organization.

The results of the internal and external risk assessment should drive your risk-mitigation plan, including capital investments and staff additions. Get buy-in from the top — be it your company’s board, executive team — by presenting your risk assessment and risk-mitigation plan, and show demonstrable results whenever possible.