Back
Richard Smith
Former Chairman & Chief Executive Officer, Equifax

Ex-Equifax CEO Richard Smith: Protecting Personal Information Is Number-One Responsibility | CNBC

🎥 Oct 03, 2017 📺 CNBC ⏱ 5m 👁 2823 views
In front of the House Digital Commerce and Consumer Protection Subcommittee, former Equifax CEO Richard Smith answers questions from Subcommittee Vice Chair Rep. Gregg Harper (R-Miss.). » Subscribe to CNBC: http://cnb.cx/SubscribeCNBC About CNBC: From 'Wall Street' to 'Main Street' to award winning original documentaries and Reality TV series, CNBC has you covered. Experience special sneak peeks of your favorite shows, exclusive video and more. Connect with CNBC News Online Get the latest news: http://www.cnbc.com/ Find CNBC News on Facebook: http://cnb.cx/LikeCNBC Follow CNBC News on Twitte...
Watch on YouTube

About Richard Smith

Former Equifax CEO Richard Smith testified before Congress in 2017 and 2018 regarding a data breach that compromised personal information of over 145 million Americans. Smith stated that the criminal hack "happened on my watch" and said he took "full responsibility" for the incident. He apologized to affected consumers and attributed the breach to a combination of human error, including a failure to apply a software patch, and technological error involving a scanner that failed to detect the vulnerability. During questioning, Smith said that Equifax's general counsel and other executives who sold stock in early August 2017 did not know it was a breach at the time, describing the incident as "suspicious activity" with no indication that personally identifiable information had been compromised. Smith stated that upon his retirement he agreed to step down with no further compensation, no bonus, and no severance. In a separate hearing, Senator Elizabeth Warren questioned Smith about Equifax's profits, which Smith confirmed had increased by more than 80 percent since 2013 despite multiple data breaches. Smith also acknowledged that Equifax receives revenue from LifeLock, a credit monitoring service that saw increased enrollment after the breach.

Source: AI-verified profile updated from Richard Smith's recent appearances. Browse all interviews →

Transcript (28 segments)
C
Congressman0:00
In your written testimony in response to some of the Chairman's questions, you stated that you were informed of suspicious activity on July the 31st by your chief information officer and went on to discuss that, and you said, 'I certainly did not know that personally.' Personal identifying information, PII, had been stolen or having the indication of the scope of the attack. Did you ask him if there had been any personal identifying information that had been obtained?
R
Richard Smith0:30
Congressman, at that time I was informed it was a dispute portal document. Dispute portal document is something that typically houses, if the consumer is disputing with us, they've paid off a utility bill, he or she may take a picture of utility bills. So that was the conversation. Not to interrupt—
C
Congressman0:51
But my question was, did you ask if any PII had been accessed?
R
Richard Smith0:56
No, I did not.
C
Congressman0:58
Were you made aware at that point of the Apache Struts patch?
R
Richard Smith1:03
No, sir, I was not.
C
Congressman1:05
Had you had any meetings with your chief information officer or your security department about any of this issue prior to July 31st?
R
Richard Smith1:15
No, congressman, I did not.
C
Congressman1:17
Had you had any meetings with them about any other security information during that time, from March until July 31st?
R
Richard Smith1:25
Oh yes, we would have routine meetings, security reviews, IT reviews.
C
Congressman1:29
How often do you have those?
R
Richard Smith1:31
Common due process will be at least quarterly.
C
Congressman1:34
And why did you not have this discussion come up? And did you have— obviously that's more than a quarter, so how many meetings did you have between that time of March the 8th until July the 31st with your security team?
R
Richard Smith1:46
Make sure I understand your question. Why didn't— how many meetings did you have during that time from March the 8th until July the 31st? I don't have that information with me. If that's important, we can get that.
C
Congressman1:58
Well, how many do you remember? Do you remember any of those?
R
Richard Smith2:03
So it normally would have IT reviews at least quarterly and security reviews at least quarterly, and then you'd augment that on an as-needed basis.
C
Congressman2:12
Well, with those meetings in those timelines of March 8th until July 31st, we are covering two, three quarters— not a total of nine months, but you touch into three quarters of that year. And at any point in any of that, did you have any information about this going on?
R
Richard Smith2:29
No, sir, I did not.
C
Congressman2:30
All right. In your testimony, you indicate that the security department ran scans in March for the vulnerability but failed to identify it. Can you explain how this is possible? And why was there never any confirmation of anybody coming back and checking to see, okay, we have this identified information? There was a failure of someone on the team to identify this, that it was being used, that the software was even being used. Was there no one coming in to verify that? Do you have any outside person prior to the ones that you hired to look at this?
R
Richard Smith3:04
All right, congressman. We get notifications routinely. The IT team and security team do to apply applications. This individual, as I mentioned earlier, did not communicate to the right level to apply the patch. Follow-up was it? As you mentioned, you said this individual, so you had one person responsible for this. There's an owner of the patch process. There's a communication that comes out from security. It's a broad-based communication. Once they receive notification from a software company or in this case DHS, they notify appropriate people. Then an individual who owns the patch process cascades that communication for everyone that's owned. Your Equifax team.
C
Congressman3:45
Is there anything more important than protecting the PII of your consumers?
R
Richard Smith3:48
No, sir.
C
Congressman3:52
With that, would we identify that as the number one responsibility of the company and everybody in your company?
R
Richard Smith3:58
We have four years, sir. Yes.
C
Congressman4:02
So it just appears, obviously, I mean the job wasn't done. And so we know that, and we're trying to look at this. And I know, too, there was an Equifax spokeswoman who said, 'We've taken short-term remediation steps and continued to implement and accelerate long-term security improvements as part of ongoing actions to help prevent this type of incident from happening again.' So we have 145.5 million people whose PII has been compromised. How many files do you have in the system?
R
Richard Smith4:34
All right. Worldwide, yes, sir. I think someone mentioned earlier it's a public number out there: over 800 million consumers and 100 million companies roughly. And we know this reach includes some from Canada, some from the UK. Would that be fair to say even at this point? Congressman, point of clarification: there was some data that we had on 7,000 Canadians in the US, so the data was in the US same environment. We had some data on UK citizens also in the US. That piece is still under investigation.
C
Congressman5:11
You know, my home state of Mississippi has 3 million people. 3 million people. Almost 1.4 million files have been breached in my state. That if you take away people that are minors who don't have a file yet, almost my entire state is going to be impacted. So this is a travesty, something that was preventable, we know. And so saying that we want to protect what goes forward doesn't bring us a lot of comfort today. Thank you. I yield back.
N
Narrator5:40
Hey there, thanks for checking out CNBC on YouTube. Be sure to subscribe to stay up-to-date on all of the day's biggest stories. You can also click on any of the videos around me to watch the latest from CNBC. Thanks for watching.