Free Agentic AI Workshop Map your footprint, identify your highest-risk gaps, and leave with a leadership-ready summary. Book a Workshop→
Start assessment

Zero Trust and the T-Mobile Breach Settlement

October 8, 2024 · Numberline Marketing

Recently, Numberline Security CEO Jason Garbis provided some thoughts on the recent T-Mobile data breach settlement. On September 30, T-Mobile announced a $30M settlement with the FCC related to recent data breaches. As part of this settlement, T-Mobile agreed to spend over $15M to improve their information security program, including the adoption of Zero Trust. What does this mean, and what should we learn from it? 

Interesting details include that the settlement was almost equal parts a fine and a required significant investment in improving their security best practices. With between 80 and 100 million consumers affected by this and two previous breaches, the FCC took what many consider a reasoned approach with both punitive damages and a requirement to fix things moving forward. 

Improvements required in the settlement include:

  • Improved corporate governance: T-Mobile’s CISO must report progress regularly to the board
  • Implementation of modern Zero Trust architecture: Among requirements spelled out are required network segmentation to reduce the blast radius
  • Improved Identity and Access Management (IAM) program: MFA and phishing resistant MFA is now a requirement
  • Data Security program
  • Critical Asset inventory: Identify and track assets on the network
  • Independent third-party assessments

While $15 million is a required expenditure, estimates range up to $160 million to address long-overdue improvements to their security infrastructure. As a T-Mobile customer I hope their new security program is more effective.

The requirement of a Zero Trust architecture attests to the fact that Zero Trust has become mainstream. And organizations of any size should, at a basic level, heed the following advice:

  • Make sure you’re following the tenets of Zero Trust
  • Build a foundation for improved practices
  • Understand what’s running on your network
  • Start with coarse-grained segmentation
  • Enforce MFA and phishing-resistant MFA, especially if you’re a likely target for bad actors

Final thoughts 

Organizations, whether in healthcare, telecommunications or other critical infrastructure sectors, have a responsibility to steward their customers’ personal data. In fact, the FCC in this settlement notes that through this series of breaches, the cost was externalized to everyday Americans. While capitalism should include healthy profits and innovation, unrestrained it can cause damage to the general population if proper security measures aren’t in place. In the age of digitized personal data, consumers should expect a reasonable level of security. Indeed, if your company holds any amount of customer data, a balance of profit and responsibility to secure consumer personal data should be a driving force. 

For Jason’s full commentary, please view his video here

If you’re interested in learning how to best approach your Zero Trust program, sign up for our free, 30-minute Zero Trust Strategy Kickstart. We’ll work with you to make sure your Zero Trust program is set up for success. Complete information is available here.

Discover more from Numberline Security

Subscribe now to keep reading and get access to the full archive.

Continue reading