• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back

2

When SpaceX starts trading, some 'shareholders' will discover they own nothing at all

3

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

1

Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back

2

When SpaceX starts trading, some 'shareholders' will discover they own nothing at all

3

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
sony pictures

The Sony hack should make cyber security a hot boardroom topic

By
Tom Huddleston Jr.
Tom Huddleston Jr.
Down Arrow Button Icon
By
Tom Huddleston Jr.
Tom Huddleston Jr.
Down Arrow Button Icon
December 23, 2014, 1:55 PM ET
Video Poster

Spooked by the Sony Pictures hack and the leak of sensitive documents, companies of all kinds are now scrambling to shore up their cyber defenses.

The movie studio’s breach is just the latest in a series of hacks in recent years, including attacks on Target (TGT), Home Depot (HD) and JPMorgan Chase (JPM) that collectively compromised the personal information of tens of millions of customers. But Sony’s hack stands out as a more frightful example because of hackers’ unfettered access, the huge damage they caused and the ultimate capitulation to their demands, seen by Sony’s controversial — albeit short-lived — decision to shelve the comedy film The Interview.

“I think the scale of this impact on Sony is what’s going to make a lot of C-suites sit up and say ‘Wow, we really do need to take this seriously,'” said Rob Sloan, head of cyber data and content for Dow Jones Risk & Compliance.

Preventing similar hacks is easier said that done. Companies already invest huge amounts of money to keep their computer systems secure, with varying degrees of success. All it takes is one weak spot for a would-be intruder to exploit. Corporate security teams are redoubling their efforts following the Sony hack, fully aware that their businesses could very well become the next Sony-style victim.

The necessary precautions have remained essentially unchanged for years, Sloan said. Companies must make sure their software and security policies are up to date, and teach employees to spot any phishing e-mails, among other standard hacker tactics.

Even before the Sony hack, Forrester Research predicted that 60% of companies will uncover a breach of sensitive data at some point in 2015, while even more could have breaches that go unnoticed. And while Sloan says not to expect something of the magnitude of the Sony hack for at least another year, smaller, more focused cyber attacks should continue to pop up every few months.

Most companies are constantly under siege, but are able to deflect a high percentage of threats, Sloan said. Sophisticated attacks are bound to occasionally sneak through corporate defenses. The bigger the company is, the harder it is to ensure tight computer security.

What is essential, Sloan notes, is that companies assume that they will be hacked and have a strategy in place to detect any breach during its early stages to stop it from spreading throughout their networks. Sloan says spending on security technology is likely to increase in the wake of the Sony hack, but the best bet for nervous corporations is to invest in its security talent, whether that’s an in-house team or consultants. Top executives need to have regular conversations with those responsible for security to develop a strategy that identifies and protects data that is most important to their business.

In Sony’s case, hackers stole a huge trove including personal information, financial data, and trade secrets — or as Sloan put it, “the complete pillaging” of the company. Until Sony promised to cancel the release of The Interview, those responsible — North Koreans, according to the F.B.I. — slowly released the corporate data online, including embarrassing emails. Executives across the country could look at their own e-mails and imagine a horrifying scenario in which their private conversations were publicly exposed.
[fortune-brightcove videoid=3953139282001]

“They can see the damage being done and it’s potentially career-threatening for them and business-ending if they don’t have the funds to support them through their troubles,” Sloan said.

Sloan also suggests companies be less parochial and warm up to the idea of sharing data with rivals. He pointed to the finance industry, in which banks share information about hackings with each other through the Financial Services Information Sharing & Analysis Center, which even added Target and the recently-breached retailer’s financial arm to its membership roll.

“You can no longer work in isolation,” he said. “You have to see that your peers, or your competitors, are having the same sort of issues and that you can learn from each other if you’re willing to share.”

If suffering a catastrophic breach isn’t enough of an incentive for corporations to constantly work to improve their network security, there is also the prospect of lawsuits to consider. For example, Sony has already been hit by a lawsuit brought by former employees who claimed the company failed to do enough safeguard their personal information that ended up being leaked in public during last month’s hacking.

Gerard Stegmaier, a privacy and data security partner at the law firm Goodwin Procter, says it is natural to see a wave of litigation after the dust settles in a high-profile data breach. In addition to employee claims, investors can also sue if a breach destroys the company’s value and shareholders blame executives for falling asleep at the switch.

“If 2014 was the year of the data breach, 2015 is going to be the year of data breach litigation,” Stegmaier said.

What’s more, Stegmaier added that it’s very difficult for companies to prove they installed reasonable security measures, especially if those measures failed. Fearful of legal exposure, executives are increasingly talking with their computer system teams about network security rather than the traditional practice of letting them handle things themselves.

“Cyber security has moved from the data center to the boardroom,” Stegmaier said.

(UPDATE: The original version of this article mistakenly identified the law firm Goodwin Procter as Goodwin & Procter. The article has been corrected.)

About the Author
By Tom Huddleston Jr.
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

‘Buy a ticket for 60 bucks and resell it for $6,000’: NYC Mayor Mamdani criticized FIFA’s resale market, but his jersey drop created the same thing
North AmericaNew York City
‘Buy a ticket for 60 bucks and resell it for $6,000’: NYC Mayor Mamdani criticized FIFA’s resale market, but his jersey drop created the same thing
By Catherina GioinoJune 12, 2026
1 hour ago
Elon Musk stands behind the Nasdaq opening bell and in front of a "SpaceX" background.
Startups & VentureSpaceX
Founders Fund, Andreessen Horowitz, Valor, and the biggest VC winners from SpaceX’s IPO
By Allie GarfinkleJune 12, 2026
3 hours ago
Liability Car Insurance Explained: What It Covers and How Much You Need
Personal FinanceInsurance
Liability Car Insurance Explained: What It Covers and How Much You Need
By Joseph HostetlerJune 12, 2026
3 hours ago
Sven Gerjets, chief technology officer at Gap, speaks on stage on a panel at Fortune Brainstorm Tech 2026.
Future of WorkBrainstorm Tech
Why companies are treating AI as a strategic partner rather than a passive technology, and how to avoid an ‘AI hangover’
By Sebastian HerreraJune 12, 2026
3 hours ago
Secured debt vs. unsecured debt: What’s the difference?
Personal Financedebt relief
Secured debt vs. unsecured debt: What’s the difference?
By Joseph HostetlerJune 12, 2026
3 hours ago
U.S. energy secretary says 7 million barrels of oil exiting Persian Gulf daily, but Chevron CEO rebuts the claim
Energycrude oil
U.S. energy secretary says 7 million barrels of oil exiting Persian Gulf daily, but Chevron CEO rebuts the claim
By Jordan BlumJune 12, 2026
4 hours ago

Most Popular

Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
Environment
Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
By Catherina GioinoJune 9, 2026
3 days ago
When SpaceX starts trading, some 'shareholders' will discover they own nothing at all
Investing
When SpaceX starts trading, some 'shareholders' will discover they own nothing at all
By Jim EdwardsJune 12, 2026
13 hours ago
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
Energy
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
2 days ago
Current price of oil as of June 11, 2026
Personal Finance
Current price of oil as of June 11, 2026
By Joseph HostetlerJune 11, 2026
1 day ago
American taxpayers have spent $33 billion on sports stadiums. They got fewer seats—and higher prices
Success
American taxpayers have spent $33 billion on sports stadiums. They got fewer seats—and higher prices
By Catherina GioinoJune 11, 2026
1 day ago
Current price of oil as of June 12, 2026
Personal Finance
Current price of oil as of June 12, 2026
By Joseph HostetlerJune 12, 2026
10 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.