Richard Smith21:19
Thank you. Thank you, Chairman Walden, Ranking Member Pallone, Chairman Latta, Ranking Member Schakowsky, and the honorable members of the subcommittee. It's an honor to be here before you today. My name is Rick Smith, and for the last 12 years I have had the honor of being the CEO and the chairman of Equifax. Earlier this week I submitted a written testimony, which at this time I don't plan on going through in any detail. Rather, I'm here today to explain to you and the American people how criminal hackers were able to steal personal information on over 145 million Americans from our servers, and as importantly, to discuss with you today what the company's response was to that criminal hack. The criminal hack happened on my watch, and as CEO, I'm ultimately responsible, and I take full responsibility. I'm here today to say to each and every person affected by this breach, I'm truly and deeply sorry for what happened. I've talked to many consumers, I've read your letters, and Equifax is committed to make it whole for you. Americans have a right to know how this happened. I'm prepared to testify today about what I've learned and what I did about this incident and my role as CEO and chairman of the board, and also what I know about the incident as a result of being briefed by the company's investigation, which is ongoing. We know now that this criminal attack was made possible because of a combination of human error and technological error. Human error involved a failure to apply a software patch to our dispute portal in March of 2017. Technological error involved a scanner which failed to detect that vulnerability on that particular portal. Both errors have since been addressed. On July 29th and July 30th, suspicious activity was detected, and the team followed our security incident protocol. The team immediately shut down the portal and began our internal security investigation. On August 2nd, we hired top cybersecurity forensic and legal experts. At that time, we notified the FBI. To be clear, we did not know the nature or the scope of the incident. It was not until late August that we concluded that we had experienced a major breach. Over the weeks leading up to September 7th, our team continued working around the clock to prepare. We took four steps to protect consumers. Step number one: determining when and how to notify the public, relying on the advice of our experts that we needed to have a plan in place as soon as we announced. Step two: helping consumers by developing a website, staffing up massive call centers, and offering services free to every American. Step three: preparing for increased cyber attacks, which we were advised by the cybersecurity experts that we should expect. And finally, continue to coordinate with the FBI and their criminal investigation of the hackers, and also to notify other federal and state agencies. In the rollout of our remediation program, mistakes were made, which again I deeply apologize. I regret the frustration that many Americans felt when our websites and call centers were overwhelmed in the early days. It's no excuse, but it certainly did not help that Hurricane Irma took down two of our larger call centers in the first few days after the breach. Since then, however, the company has dramatically increased its capacity, and I can report to you today we've handled over 420 million consumer visits to our website in just over three weeks, and the wait times at the call centers have been substantially reduced. At my direction, the company offered a broad package of services to all Americans. In addition, we developed a new service available on January 31st, 2018, that will give all consumers the power to control access to their credit data by allowing them to lock and unlock their credit files when they want. They can do that for free for life. Putting the power to control access to credit data in the hands of the American consumer is a step forward. I look forward to discussing this new tool with you during my testimony. As we've all painfully learned, data security is a national security problem. Putting the consumer in control of their credit data is a first step towards a long-term solution to the industry problem of identity theft. No single company can solve a larger problem on its own. I believe we need a public-private partnership to evaluate how to best protect Americans' personal data going forward. I look forward to being a part of that dialogue. Chairman Walden, Ranking Member Pallone, Chairman Latta, Ranking Member Schakowsky, and the honorable members of the subcommittee, thank you again for inviting me here today to speak to you. I will close by saying again how sorry I am for this breach. On a personal note, I want to thank the many hard-working and dedicated employees who worked with me so tirelessly over the past 12 years at Equifax. Equifax is a very good company with thousands of great people waking up every day trying to do what is right. I know they'll continue to work tirelessly as we have over the past two months to right the wrong. I'm looking forward to answering your questions. Thank you.