Question: Case Study 1: Customer Data Breach You are the Head of Security for Marriott International. On September 8, 2018, you received an alert from an
Case Study 1: Customer Data Breach You are the Head of Security for Marriott International. On September 8, 2018, you received an alert from an internal security tool regarding an attempt to access the Starwood guest reservation database. You quickly engaged your security experts to help determine what occurred. You eventually learned during the investigation that there had been unauthorized access to the Starwood network since 2014, 4 years ago. You also discovered that an unauthorized party had copied and encrypted information and took steps towards removing it. On November 19, 2018, your team was able to decrypt the information and determine that the contents were from the Starwood guest reservation database. The data copied by the hackers included guests names, mailing addresses, phone numbers, email addresses, passport numbers, Starwood Preferred Guest account information, dates of birth, gender, arrival and departure information, reservation dates, and communication preferences. For some, the information also included payment card numbers and expiration dates, though these were supposed to be encrypted. You decide the best plan of action is to phase out Starwood systems and accelerate security enhancements to the network. You eventually came to realize that the exposure of personal details ended up affecting 500,000 Starwood guests. You have been approved to offer customers an extra 1000 points for their next stay at any Marriot location. Draft an email to be mass distributed to Starwood guests informing them about the data breach and exposure of their personal information.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
