{"id":332,"date":"2026-05-06T03:17:57","date_gmt":"2026-05-06T03:17:57","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/jareda-h\/?p=332"},"modified":"2026-05-06T03:17:57","modified_gmt":"2026-05-06T03:17:57","slug":"case-study","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/jareda-h\/2026\/05\/06\/case-study\/","title":{"rendered":"Case Study"},"content":{"rendered":"\n<p>Case Study: The Equifax Data Breach<\/p>\n\n\n\n<p>Student Name: Jared Amonoo-Harrison<\/p>\n\n\n\n<p>School of Cybersecurity, Old Dominion University<\/p>\n\n\n\n<p>CYSE 201S: Cybersecurity and the Social Sciences<\/p>\n\n\n\n<p>Instructor Name: Diwakar Yalpi<\/p>\n\n\n\n<p>Date: April 23, 2026<\/p>\n\n\n\n<p><strong>Introduction<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>The Equifax data breach of 2017 is said to be one of the biggest incidents within cybersecurity history. The personal information of approximately 147.9 million people residing in the United States were exposed. Certain information includes social security numbers, date of birth, addresses, full names, and even driver\u2019s licenses numbers. The breach was possible due to a vulnerability within the Apache Struts software that was unpatched. Attackers seeing that, took the opportunity to exploit it.<\/p>\n\n\n\n<p><strong>Analysis<\/strong><\/p>\n\n\n\n<p>Due to the negligence of an expired security certificate, the network monitoring system was inactive leading to a delay in detection and the result of a breach. The basic cybersecurity practices were not implemented. Equifax chose not to apply a security update as quickly as possible and they paid the price.<\/p>\n\n\n\n<p>Social science perspectives explain in more detail. Psychology examines the human behavior, showing us the poor decision-making and overconfidence employees and leaders had caused the delay of fixing vulnerabilities. Sociology\u2019s focal point is group behavior and organizational culture. Equifax had poor leadership that didn\u2019t prioritize the safety of the system even when knowing about the risks. This brings poor communication, for had it been made the main priority of employees by their leadership, a breach may have never happened. Lastly, anthropology researches workplace norms and communication. Poor communication and coordination between executives and IT staff may have played a part in the delay. These perspectives are to show that the breach did not occur due to technologic failure only, but because of human errors.<\/p>\n\n\n\n<p><strong>Solutions<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>To prevent breaches of this scale from occurring, the combined use of technical solutions and social science plans must continue to be in rotation. Organizations tend to use multi-factor authentication, threat monitoring, encryption and much more. They could have scheduled penetration tests and hire third-party help to identify any overlooked vulnerabilities. As for social science strategies, training security awareness, stress management, behavioral incentives, peer accountability, improved communication styles, leadership visibility, etc. However, there are barriers in place for these changes. Limitation on organization budgets, employee resistance, complex systems, skill shortages, unclear responsibility, and lack of executive support.<\/p>\n\n\n\n<p><strong>Reflection<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The Equifax data breach gives us insight toward the workings of cybersecurity. It informs us that software and firewalls failing are not caused only by technology but involves the mistakes of humans as well. The choices they make, the priorities of leadership and the culture of the workplace are what cause these risks. Social sciences help to explain why people ignore the signs and warnings, failure to communicate, and delays to action. To know what needs to be improved on and the barriers in place of said improvements, action can be taken to ensure that an incident of this caliber never happens again.<\/p>\n\n\n\n<p><strong>Conclusion<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The case of the Equifax data breach should remain as a reminder and a lesson of poor cybersecurity practices by an organization. The help of social sciences within an organization increases the rate of attack preventions and effective responses to attacks in the future.<\/p>\n\n\n\n<p><strong>Citations<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/www.breachsense.com\/blog\/equifax-data-breach\/\">Equifax Data Breach 2017: Timeline, $1.38B Cost &amp; Lessons<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/archive.epic.org\/privacy\/data-breach\/equifax\/\">EPIC &#8211; Equifax Data Breach<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/oversight.house.gov\/wp-content\/uploads\/2018\/12\/Equifax-Report.pdf\">Equifax-Report.pdf<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.ncsc.gov.uk\/blog-post\/creating-the-right-organisational-culture-for-cyber-security\">Creating the right organisational culture for cyber security | National Cyber Security Centre<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.gao.gov\/products\/gao-18-559\">Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach | U.S. GAO<\/a><\/p>\n\n\n\n<div class=\"wp-block-file\"><a id=\"wp-block-file--media-61096380-7dc6-4453-948f-b5b06d9581d4\" href=\"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-content\/uploads\/sites\/40820\/2026\/05\/Case-Study-Equifax-Data-Breach.docx\">Case-Study-Equifax-Data-Breach<\/a><a href=\"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-content\/uploads\/sites\/40820\/2026\/05\/Case-Study-Equifax-Data-Breach.docx\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-61096380-7dc6-4453-948f-b5b06d9581d4\">Download<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Case Study: The Equifax Data Breach Student Name: Jared Amonoo-Harrison School of Cybersecurity, Old Dominion University CYSE 201S: Cybersecurity and the Social Sciences Instructor Name: Diwakar Yalpi Date: April 23, 2026 Introduction &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The Equifax data breach of 2017 is said to be one of the biggest incidents within cybersecurity history. The personal information of&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/jareda-h\/2026\/05\/06\/case-study\/\">Read More<\/a><\/div>\n","protected":false},"author":32159,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/posts\/332"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/users\/32159"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/comments?post=332"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/posts\/332\/revisions"}],"predecessor-version":[{"id":334,"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/posts\/332\/revisions\/334"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/media?parent=332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/categories?post=332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jareda-h\/wp-json\/wp\/v2\/tags?post=332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}