This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
Insights Insights
| 1 minute read

Marriott Paying $52M to Settle Federal and State Data Breach Investigations

In connection with several data breaches affecting hundreds of millions of hotel guests, Marriott will settle outstanding investigations with federal and state regulators for $52M and must also greatly beef up its security practices in Marriott's portfolio of hotels.  The company also faces class action claims relating to the breaches, which took place over several years and involved such information as the numbers on guest passports and credit cards.  

WHY IT MATTERS

The size of the financial penalties here would cripple most organizations, but it is the new security commitments that probably matter most.  They signal what regulators view as current best practices for handling consumer data.  Regulators will require that the highest levels of Marriott management be involved in privacy and security matters; that consumers be given easy tools for managing their data; that the company practice good security hygiene including by patching and upgrading systems promptly; and that the company institute a new security program that includes enhanced employee training as well as incorporate concepts of data minimization, vendor management, and security assessments, among other principles and practices.  The requirements also include a commitment to address security gaps in any target company that Marriott acquires hereafter.  These are significant commitments and are likely to feature in regulatory mandates for other companies in the future.  

Under the terms of the deal, each state and Washington, D.C., will receive a portion of the $52 million payout, and Marriott will also be required to strengthen its data security practices "using a dynamic risk-based approach," according to Tong. This includes implementing a comprehensive information security program with new overarching security program mandates such as incorporating zero-trust principles, regular security reporting to the CEO and others within the highest levels of the company and enhanced employee training on data handling and security.

Tags

data security and privacy, hill_mitzi, current events, cybersecurity, data privacy, insights