Case
study 6
Business Case: Lax Security at
LinkedIn Exposed
Q1: LinkedIn does not collect the credit
card or other financial account information of its members. Why then would
profit-motivated hackers be interested in stealing linkedIn’s stored data? What
data would they be most interested in?
Q2: Companies are often slow to
self-detect data breaches so a cyberattack can occur without a company even
knowing it has a problem. What effect do you think LinkedIn’s failure to
self-detect its massive data breach had o its popularity and credibility?
Q3: Most corporate security incidents are
uncovered by a third party, like a security firm, that picks up on evidence of
malicious activity. Why do you think IT security experts and not LinkedIn
discovered the data breach?
Q4: LinkedIn lax approach to members’
information security and weak passwords was very surprising to members and
information security professionals. Why?
Q6: Why is data encryption an important
security defense?
Q7: Discuss why information security is a
concern of senior managers.
Q8: Explain why someone who used the same
password for several sites would need to change all those passwords. In your
opinion, was LinkedIn negligent in protecting its main asset? Explain.
