Case Analysis on CSR

Introduction
Ron Lieber’s article, “Why the Equifax Breach Stings So Bad,” describes the
helplessness and fear experienced by consumers after Equifax failed to protect their personal and
financial information. Equifax and other credit-reporting agencies collect data that consumers
cannot realistically leave, then use algorithms and credit scores to influence access to mortgages,
automobiles, employment, and other important opportunities. Consumers may also struggle to
correct inaccurate information contained in their credit reports. After the breach, many people
feared identity theft, financial losses, damaged credit, and harm to their reputations. Equifax
intensified these concerns through poor communication, its failure to notify affected individuals
directly, and its continued collection of fees from some consumers who attempted to freeze their
credit files.
The breach, therefore, harmed more than people whose information might eventually be
used by criminals; it also harmed consumers who were forced to spend time, money, and energy
protecting themselves from a failure they did not cause due to the lack of the corporation’s social
responsibility (CSR). Remember, you can always change your credit card number, but you can
never change your Social Security Number. In this Case Analysis, with research provided
through Friedman and Anshen’s works, I will argue that Confucianism shows that the Equifax
breach harmed consumers by exposing their personal information, threatening their financial
security, and undermining their trust in the credit-reporting system. This harm was morally
wrong because Equifax failed to fulfill its responsibility as a powerful steward of information
upon which most of the public was forced to depend.

Friedman’s Analysis of CSR
Milton Friedman’s central argument is that the primary social responsibility of a business
is to increase its profits. According to Friedman, corporate executives are employees and agents
of the company’s owners. Their responsibility is therefore to operate the business according to
the owners’ wishes, which typically means maximizing profit while complying with the law and
ethical norms. Friedman was pretty skeptical of executives who use company resources to pursue
broad social causes because they are spending money that belongs to shareholders, customers, or
employees. In his view, political institutions should determine public policy, while businesses
should focus on operating successfully within the established rules of the market (Friedman,
1970).
At first, Friedman’s argument may appear to excuse Equifax from any responsibility
beyond earning money and meeting minimum legal requirements. However, Equifax’s conduct
fails even under Friedman’s profit-centered standard. The company’s business depended on
collecting, analyzing, and distributing sensitive consumer information. Protecting that
information was therefore not an unrelated charitable activity; it was part of Equifax’s basic
business function. A company cannot successfully profit from personal data while treating the
protection of that data as an optional social expense. By failing to safeguard its systems and
respond effectively after the breach, Equifax damaged the trust and stability upon which its
business depended.
Lieber explains that consumers were trapped within the credit-reporting system and
generally had no practical ability to opt out. Equifax and similar agencies used personal
information to create credit scores that influenced mortgages, car loans, employment, and other
major opportunities. After the breach, consumers faced fears of identity theft, financial loss,
damaged credit, and ruined reputations. Many struggled to receive useful information from
Equifax, while some were initially charged fees to freeze credit files that Equifax itself had failed
to protect. This response harmed consumers while also exposing Equifax to reputational damage,
regulatory attention, legal costs, and long-term losses of public trust. Strong security and honest
communication would therefore have served both consumers and the company’s financial
interests.
Friedman also warns that businesses sometimes use the language of social responsibility
as public-relations “window-dressing” while their actions are actually motivated by self-interest.
Equifax’s response demonstrates the opposite problem: it failed to recognize that responsible
treatment of consumers was also necessary for its own long-term success. Instead of immediately
notifying affected individuals, providing reliable support, and offering free protection without
unnecessary obstacles, the company shifted much of the burden onto consumers. Even from a
profit-maximizing perspective, this was shortsighted. A company that depends on public
information and trust cannot treat security failures as someone else’s problem.
Confucianism reveals why Friedman’s framework is still incomplete. Friedman primarily
defines the executive’s responsibility through the relationship between managers and
shareholders. Confucian ethics, however, emphasizes that people and institutions occupy several
relationships and roles at once. Equifax was not only an agent of its shareholders; it was also a
powerful steward of information belonging to millions of consumers. Because consumers could
not realistically leave the credit-reporting system, Equifax held far more power and knowledge
within this relationship. That unequal position created a greater responsibility to act with care,
honesty, competence, and respect.
The morally appropriate action would therefore have been to treat cybersecurity as a central duty rather than merely another operating expense. Equifax should have maintained stronger security systems, responded quickly and transparently, directly notified affected consumers, provided free and simple credit freezes, and offered meaningful assistance to anyone facing identity theft or inaccurate credit information. These actions would not have required Equifax to abandon profitability. They would have protected the relationships and trust necessary for the company to function legitimately. Friedman helps demonstrate that responsible security could serve long-term business interests, while Confucianism explains why Equifax owed protection to consumers even when doing so imposed additional costs.

Anshen’s Analysis of CSR
Melvin Anshen argues that business and society are connected through an implicit social
contract consisting of reciprocal duties and expectations among corporations, governments, and
citizens. Because society’s needs change over time, this contract is continually renegotiated.
Practices accepted in the past may therefore become unacceptable, requiring managers to
reconsider their responsibilities and adapt their organizations accordingly (Anshen, 1970, pp. 7–
8).
Anshen contrasts this emerging social contract with an older model of corporate
responsibility. Under the old model, businesses were expected to maximize profit, compete
fairly, and obey existing rules. Economic growth was treated as the main source of social
progress, while problems such as pollution, unemployment, discrimination, and damage to
communities were left for individuals, charities, or governments to address. This allowed
corporations to receive the economic benefits of their activities while shifting many of their
social costs onto the public. Anshen argues that the emerging contract requires businesses to
consider economic and social progress together and accept responsibility for costs created by
their operations (Anshen, 1970, pp. 9–11).
The Equifax breach demonstrates the failure of the older corporate model. Equifax
profited by collecting, evaluating, and distributing consumers’ financial information. Consumers
could not realistically opt out because credit reports influenced access to loans, housing,
automobiles, mobile phones, and some employment opportunities. When Equifax failed to
protect that information, consumers were forced to monitor accounts, freeze credit files, dispute
errors, and protect themselves against identity theft. They also experienced fear that their
finances, reputations, and future opportunities could be harmed. Some consumers were even
charged fees to freeze credit files that Equifax had failed to secure.
These consequences represent the externalized social costs Anshen criticizes. Equifax
received the financial benefits of controlling consumer data, while the public carried much of the
risk and recovery burden. Under Anshen’s emerging social contract, cybersecurity should not be
treated merely as an optional internal expense. Because Equifax’s business created the risk, the
company should have incorporated the cost of preventing and responding to breaches into its
operations.
Confucianism further explains why Equifax acted immorally. Confucian ethics
emphasizes reciprocal relationships, proper fulfillment of social roles, and the greater
responsibilities held by those with more authority. Equifax possessed far more knowledge and
control than the consumers whose information it collected. Consumers depended on the
company, but had little ability to leave the relationship or control how their data was handled. As
a powerful information organization, Equifax had a responsibility to act with competence, care,
and honesty. Its failure to protect consumers and assist them afterward violated that role and
weakened trust throughout the credit-reporting system.
Equifax should have invested in stronger security, directly notified affected consumers,
provided free and accessible credit freezes, corrected inaccurate records promptly, and supported
victims of identity theft. Its leaders should also have accepted responsibility instead of shifting
the burden onto people who never chose to place their data in Equifax’s hands. Anshen argues
that businesses should help redesign the social contract rather than waiting for public outrage or
government intervention to force change (Anshen, 1970, pp. 12–14). Equifax failed because it
benefited from its powerful social position without fulfilling the obligations that accompanied it.

Conclusion
Corporations and organizations have grown increasingly careless about the
responsibilities that come with their power. The Equifax breach was immoral because it exposed
consumers to harm caused by circumstances beyond their control. Consumers could not
realistically opt out of the credit-reporting system, yet Equifax failed to protect the information
on which their opportunities depended. Friedman’s argument shows that protecting consumer
data was part of Equifax’s basic business responsibility because its profitability depended on
securely managing that information. Anshen’s social contract goes further, showing that
corporations must accept the social costs created by their operations rather than shifting those
costs onto the public. From a Confucian perspective, Equifax also failed to fulfill its role as a
powerful steward of sensitive information. One objection is that no company can prevent every
cyberattack. However, this does not excuse weak preparation, poor communication, or forcing
victims to pay for protection afterward. No one man should possess unchecked power over
others, and the same principle should apply to corporations.

References
Anshen, M. (1970). Changing the social contract: A role for business. Columbia Journal of
World Business, 5(6), 6–14.
Friedman, M. (n.d.). The social responsibility of business is to increase its profits. Corporate
Ethics and Corporate Governance, 173–178. https://doi.org/10.1007/978-3-540-70818-6_14
Lieber, R. (2017, September 22). Why the Equifax breach stings so bad – The New York Times.
https://www.nytimes.com/2017/09/22/your-money/equifax-breach.html