Wegmans’ $400,000 fine for exposed customer data should leave all retailers on high alert
July 1, 2022 – Published on SC Magazine
Retail chains operate on thin margins with very tight IT and security budgets, so news on Thursday that Wegmans agreed to pay the state of New York $400,000 and upgrade its cybersecurity operations for a cloud misconfiguration was hardly a shocker to security industry insiders.
Jonathan Villa, the practice director for cloud security at GuidePoint Security, pointed out that similar data breaches caused by misconfigured resources in the cloud are not as widespread as they once were, a potential reason why the fines were so high. Villa said the cloud service providers have made improvements to their services that bring to light some of the more riskier configurations.
“That doesn’t mean the services are any more secure or were less secure before, it simply means there’s more awareness,” Villa said. “It can be argued that if the information about misconfigured resources was available to the cloud customer, it could be a form of negligence. When cloud was new to the industry the root cause was almost always lack of education. Today, there have been major strides made to educate cloud customers.”
Read More HERE.