The Sony PlayStation Network Crash

Slides:



Advertisements
Similar presentations
Tax Information Network of Income Tax Department (managed by NSDL)
Advertisements

Click to edit Master title style Page - 1 OneSky Teams Step-by-Step Online Corporate Communication Support 2006.
How to protect yourself, your computer, and others on the internet
MOSS ADAMS LLP | 1 W HAT I S S ENSITIVE D ATA ? Whats the Risk and What Do We Do About It? Weston Nelson Steve Fineberg Steven Gin.
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
Northside I.S.D. Acceptable Use Policy
Configuration management
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Discovering Computers Fundamentals, 2012 Edition
Copyright Critical Software S.A All Rights Reserved. COTS based approach for the Multilevel Security Problem Bernardo Patrão.
PlayStation Through The Years. PlayStation Facts The PlayStation was released in Japan on December 3rd, 1994 and in the U.S. On September 9th, 1995.
Andy Daniëls 3 SWMA ICT03. Introduction History Technical Comparison Companies Security Why Blu-ray is On the Rise? Television: HD vs. Standard Conclusion.
Services Course Windows Live SkyDrive Participant Guide.
HITECH ACT Privacy & Security Requirements Cathleen Casagrande Privacy Officer July 23, 2009.
Services Course Windows Live SkyDrive Participant Guide.
Security by Design A Prequel for COMPSCI 702. Perspective “Any fool can know. The point is to understand.” - Albert Einstein “Sometimes it's not enough.
Sedex: Registration and Account Set Up Instructions
A lesson approach © 2011 The McGraw-Hill Companies, Inc. All rights reserved. a lesson approach Microsoft® PowerPoint 2010 © 2011 The McGraw-Hill Companies,
Lesson 30 Computer Safety and Ethics
CYBER & Product Liability & Professional Indemnity
May Except for the statements of historical fact, the information presented herein, as well as comments that management may.
1 DIGITAL INTERACTIVE MEDIA Wednesday, October 28, 2009.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
E-Commerce Security Issues. General E-Business Security Issues Any E-Business needs to be concerned about network security. The Internet is a “ public.

Security, Privacy, and Ethics Online Computer Crimes.
Why Comply with PCI Security Standards?
Presenter Deddie Tjahjono.  Introduction  Website Application Layer  Why Web Application Security  Web Apps Security Scanner  About  Feature  How.
Company LOGO Copyright Carrie Kerskie Data Breach & Identity Theft By Carrie Kerskie Kerskie Group, Inc.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security.
1 Personal Health Information Data Breach. What Happened? March 10, 2012: Computer hackers illegally access a Department of Technology Services (DTS)
Defining Security Issues
MOBILE DEVICE SECURITY. WHAT IS MOBILE DEVICE SECURITY? Mobile Devices  Smartphones  Laptops  Tablets  USB Memory  Portable Media Player  Handheld.
Jolly Phan Cal State University of San Marcos Professor Fang Fang IS News 11/12/2009.
>>. Prepared by: Max Pearson Sukhee Youn (Saleisha) Jennifer Palahniuk Lin Liu (Austin) OCT 2009 Focus on Play Station Dept.
Overview The Video Game Industry Competitive Landscape
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI: As complicated as it sounds? Gerry Lawrence CTO
AUGUST 25, 2015 Cyber Insurance:
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
-Tyler. Social/Ethical Concern Security -Sony’s Playstation Network (PSN) hacked in April Hacker gained access to personal information -May have.
Managing Data Against Insider Threats Dr. John D. Johnson, CISSP.
IP Security IP sec IPsec is short for Internet Protocol Security. It was originally created as a part of IPv6, but has been retrofitted into IPv4. It.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
© Copyright 2010 Hemenway & Barnes LLP H&B
Doyoung Park, Osaka Gakuin University
Insurance of the risk Policy covers & underwriting issues Stephen Ridley, Senior Development Underwriter.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
Alert against Online Shopping Frauds. Online Shopping A form of electronic commerce whereby consumers directly buy goods or services from a seller over.
Chapter 12: How Private are Web Interactions?. Why we care? How much of your personal info was released to the Internet each time you view a Web page?
Have the Time? Steps to Deal with Cybercrime HFTP Annual Conference Bellevue, Washington October 23, 2015 Presented by: John D. Daum, CPA Scott Perry (Just.
Internet Security. 2 Computers on the Internet are almost constantly bombarded with viruses, other malware and other threats.
Data Security & Privacy: Fundamental Risk Mitigation Tactics 360° of IT Compliance Anthony Perkins, Shareholder Business Law Practice Group Data Security.
Protecting Yourself from Fraud including Identity Theft Personal Finance.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
Data Breach ALICAP, the District Insurance Provider, is Now Offering Data Breach Coverage as Part of Our Blanket Coverage Package 1.
Technical Implementation: Security Risks
Payment Card Industry (PCI) Rules and Standards
Payment Card Industry (PCI) Rules and Standards
Performing Risk Analysis and Testing: Outsource or In-house
PCI-DSS Security Awareness
SONY C O R P O R A T I O N.
Internet Payment.
MIS 5121: Real World Control Failure - TJX
Society of Risk Management Consultants Annual Conference
Cyber Issues Facing Medical Practice Managers
Cyber Trends and Market Update
Anatomy of a Common Cyber Attack
Presentation transcript:

The Sony PlayStation Network Crash Stoppage Of Play The Sony PlayStation Network Crash

AGENDA The Crash Company History Gaming PlayStation Network Timeline of Crash Reactions Considerations What’s Next? http://images4.wikia.nocookie.net/__cb20110618021730/crashban/images/b/b1/Crash_bandicoot_wallpaper_by_tyrannosaurus92-d3adlxn.jpg http://www.gadgetizer.com/wp-content/uploads/2011/04/playstation-network-hacked-users-contacted.jpg

NEWS FLASH Pittsburgh Post-Gazette “You probably heard about Sony’s PlayStation Network hack if you glanced at the internet, television or even newspaper in the past week.  It was such big news even news sources like Fox News, ones that usually reserve video game news for exaggerating the indecencies of the latest mature title, discussed the security breach ad nauseam. To say the hackers did damage to Sony would be the understatement of the year.  They crippled the network, knocking it out of commission for a little over a week, and the hackers had access to about 77 million users personal information, including credit card data.” http://communityvoices.sites.post-gazette.com/index.php/arts-entertainment-living/the-game-guy/28611-was-sony-ready-to-welcome-the-psn-back

CRASH BACKGROUND DATES: April 17-19, 2011 SITUATION: Hackers illegally access Sony PlayStation Network & Qriocity Services which has 77 million registered users data with over 12 million accounts containing credit card information. PUBLIC NOTIFICATION(S): Brief (April 22, 2011) Formal (April 26, 2011) FINANCIAL IMPACT: Sony shares fall by more than 5%. Unknown amounts still need to be determined for resolving problem and compensating consumers. FEEDBACK: Public questions company’s security and response, governments discuss regulatory environment, and lawsuits are filed. http://communityvoices.sites.post-gazette.com/index.php/arts-entertainment-living/the-game-guy/28611-was-sony-ready-to-welcome-the-psn-back http://arstechnica.com/gaming/news/2011/04/sonys-black-eye-is-a-pr-problem-not-a-legal-one.ars

COMPANY ORIGINS Sony Sonus Sonny Boy Founded in 1946 by Engineer Masaru Ibuka and physicist Akio Morita Company begins as Tokyo Telecommunications Engineering Corporation named “Totsuko” Initial products: portable radios, tape recorders, electric rice cookers Initial functions: build and repair electrical equipment Enters North American market in 1950s Sonus (Latin word meaning sound or sonic) Sonny Boy (English term denoting youth & excitement) Sony http://www.sony.net/SonyInfo/CorporateInfo/Subsidiaries/index.html http://www.sony-europe.com/article/id/1178278971500 Large recognizable divisions: Sony Pictures, Sony Computer Entertainment, Sony Electronics, Sony Ericsson, Sony Music, Sony USA

GAMING HISTORY 1980s – CD technology developed with Philips 1988 – Partnership built with Nintendo to develop cartridge/cd gaming system called “PlayStation” Early 1990s – Sony & Nintendo disagree on direction and disbands partnership 1994 – Sony releases cd-only gaming system called the “PlayStation X” 1995 – Sony Computer Entertainment division is created and headquartered in Sunnyvale, CA Nintendo PlayStation Image - http://t3.gstatic.com/images?q=tbn:ANd9GcTknjcjM1-JO2M5J1F1kn9sKKeEOiuwyFeEOZON4-wS4nb2e5QLBvSwcKK25Q Sony PlayStation (PSX) Image - http://edu.glogster.com/media/5/35/79/64/35796434.jp Mid 2000s – Latest version of PlayStation called PS3 arrives with “Blu- ray” disc technology, wireless internet access, internal storage, digital video & audio outputs, and general navigation menu

CONSOLE GAMING MARKET NINTENDO: SONY: MICROSOFT: Wii Sales: $754M Portable (DS & 3DS) Sales: $827M SONY: PS3 Sales: $439M PlayStation Portable Sales: $297M MICROSOFT: Xbox 360 Sales - $535M Sales Totals (as of 4/30/11) - http://www.vgchartz.com/weekly.php?date=40804&reg=World&date=40664# Sony PS3 Image - https://s3.amazonaws.com/luuux-original-files/bookmarklet_uploaded/1276904134_98872156_1-Fotos-de--Playstation-3-Slim-120GB-SONY-PS3-1276904134.jpg Nintendo Image - http://www.mogulite.com/wp-content/uploads/2011/06/Nintendo.jpg Xbox Image - *Please note that sales numbers only represent combined hardware and software numbers without additional subscription revenue, etc.

THE PLAYSTATION NETWORK Business Briefing Meeting 2006 in Tokyo Brought on as part of PS3 news Release Multi-player gaming, internet, & chat System updates; downloads and streaming of multimedia Specifications Free user registration Access via PlayStation 3, PlayStation Portable, or PC Registration & Access Paid for using electronic funds Originally done through tickets but now pre-paid & credit cards are okay Transactions 77 million registered online worldwide as of 4/30/11 Users Sony PSP Image - http://www.newgadget.info/wp-content/plugins/wp-o-matic/cache/f1bfd_sony-psn-minis-press.jpg

TWO LONG WEEKS 4/19: Illegal activity is detected in network. 4/20: Engineers discover intrusion evidence and shut down PSN. 4/21: Sony retains services of external security firm. 4/22: Sony provides FBI info and comments on blog without discussing data loss. 4/23: Forensic teams confirm advanced attack and notifies public. BREACH

TWO LONG WEEKS 4/24: Sony continues work with forensics on server problems. 4/25: Account details (name, address, email, password, etc.) are confirmed stolen. 4/25: Global credit card info loss cannot be confirmed. 4/26: Kaz Hirai, head of Sony gaming, appears at news conference for tablet pc’s without taking PSN questions. DIAGNOSIS

TWO LONG WEEKS 4/26: Sony emails consumers with detailed hack info. 4/26-4/27: Sony begins notifying regulatory entities of breach. 4/27: Shares fall 2% on news of potential data loss and first lawsuit filed against company. 4/28: Shares drop 4.5% in Tokyo. 4/29: Sony refutes claims of 2.2 million credit card accounts stolen. FALLOUT

REACTION – CONSUMERS CNN reported that “Gamers (are) fuming” +sid4peeps: “This update is 6 days LATE. I think it is time to move to the other network, no regard for customers here” +Korbei83: “If you have compromised my credit information, you will never receive it again. The fact that you’ve waited this long to divulge this information to your customers is deplorable. Shame on you” http://ingame.msnbc.msn.com/_news/2011/04/27/6544610-sony-sued-could-bleed-billions-following-playstation-network-hack ... first paragraph first law suit was filed http://articles.cnn.com/2011-04-27/tech/sony.playstation.hack.reaction_1_credit-card-playstation-users-playstation-network?_s=PM:TECH http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/ +tazinlwfl: “…I love my PS3. I really like Sony and I support the developers 100%, but this really tests everyone’s patience. It really tests my patience.”

REACTION – DEVELOPERS “Our belief is that whilst this is terrible news… it won’t affect the user base too much.” Stewart Gilray, Just Add Water “PSN being out definitely affects our bottom line… but as long as the people who were going to be playing… get right back in there playing… we’ll be happy and hopefully income won’t be dented too much.” Dylan Cuthbert, Q-Games Developer “From my perspective, the bigger issue is not about PSN, but confidence in digital distribution generally.” Ste Curran, Zoe Mode Creative Director “We have our first self-funded, self-published PSN game,… coming out next week, so from our point of view , the fact that the network isn’t available is a big concern.” Lol Scragg, Cohort Studios Founder http://www.guardian.co.uk/technology/gamesblog/2011/apr/29/psn-hack-industry-reactions http://www.joystiq.com/2011/04/27/psn-devs-offer-mixed-reactions-to-cost-of-outage/ http://www.develop-online.net/news/37566/PSN-dev-Downtime-has-cost-us-thousands

Senator Rick Blumenthal REACTION – GOVERNMENT “I am concerned that PlayStation Network users’ personal and financial information may have been inappropriately accessed by a third party. Compounding this concern is the troubling lack of notification from Sony about the nature of the data breach. Although the breach occurred nearly a week ago, Sony has not notified customers of the intrusion, or provided information that is vital to allowing individuals to protect themselves from identity theft, such as informing users whether their personal or financial information may have been compromised. Nor has Sony specified how it intends to protect these consumers.” http://www.techfirm.com/storage/JohnsvSony-Complaint-FINAL.pdf http://www.ps3blog.net/2011/04/26/senator-richard-blumenthal-demands-answers-from-sony-over-playstation-data-breach/ Senator Rick Blumenthal (D-Connecticut) Domestic

REACTION – GOVERNMENT Christopher Graham Jennifer Stoddart UK’s Information Commissioner Researching PlayStation Hack Has power to fine companies ₤500,000 for serious data breaches Jennifer Stoddart Canada’s Privacy Commissioner Currently investigating Sony to determine whether it has violated any privacy laws http://www.techfirm.com/storage/JohnsvSony-Complaint-FINAL.pdf http://www.telegraph.co.uk/technology/sony/8476441/PlayStation-hack-Sony-faces-watchdogs-questions.html http://www.bloomberg.com/news/2011-04-28/sony-faces-lawsuit-regulators-scrutiny-over-playstation-user-data-breach.html http://www.itwire.com/virtualisation/46877-minister-sony-hack-firms-breach-notification-case http://www.businessweek.com/news/2011-04-28/sony-faces-lawsuit-regulators-probe-over-playstation-hack.html International

LAWSUITS “This action arises from SONY’s failure to maintain adequate computer data security of consumer personal data… Subsequent to the compromise of private consumer information and financial data, Defendant unduly delayed or failed to inform in a timely fashion the appropriate entities…” Kristopher Johns v. Sony Computer Entertainment America “Because of Defendant’s actions, millions of their customers have had their Financial Data, Personal ID, and Usage Data compromised, have had their privacy rights violated, have been exposed to the risk of fraud and identity theft, and have otherwise suffered damages.” Rebecca Mitchell v. Sony Computer Entertainment America http://www.techfirm.com/storage/JohnsvSony-Complaint-FINAL.pdf http://www.telegraph.co.uk/technology/sony/8476441/PlayStation-hack-Sony-faces-watchdogs-questions.htmlhttp://www.motleyrice.com/files/consumer-fraud/04-27-11_sony_mitchell_complaint.pdf

LAWS & REGULATIONS Payment Card Industry – Data Security Standard (Requirements) Maintain a Firewall Don’t use vendor-supplied default system passwords Protect cardholder data Encrypt transmission across open , public networks Use and update anti-virus software Maintain a policy that addresses information security Restrict access to need to know Assign a unique ID Restrict physical access to cardholder data Track and monitor all access to network resources Regularly test security systems Develop and maintain secure systems and applications http://www.defendyourdollars.org/2005/02/states_with_not.html => Laws vary greatly from state to state

ADDITIONAL INFORMATION SIMILAR SITUATIONS SCENARIO 12/22/07 – Microsoft’s Xbox Live service went down for 13 days due to a server crash. 03/30/11 – Epsilon discovered that its network had been breached RESPONSE Free downloadable arcade games to members valued at roughly over $80M 04/01/11 – Official press release issued notifying public ADDITIONAL INFORMATION 01/03/08 – Microsoft was notified that they were the subject of a $5 Million class action suit Clients (Kroger, JP Morgan, Capital One) customer data was stolen “…greatest risk to Epsilon and Alliance Data is the potential loss of clients” http://www.wired.com/gamelife/2008/01/xbla-undertow-f/ Shows that the price of the XBLA game Undertow at the time was $10 http://www.dailytech.com/Xbox+Live+Collects+Eight+Million+Users+in+Five+Years/article9665.htm In the month before the incident there were over $8Million users. Assuming that every user downloaded the game or were compensated for their purchase, it meant a potential loss of revenue to Microsoft in excess of $80 Million probably more because the cause of the downtime seemed to be that an extremely large number of players tried to sign up and use the service during the holidays http://www.gamespot.com/news/6184323/microsoft-sued-over-xbox-live-outage $5 Million Class Action Suit http://www.foxbusiness.com/technology/2011/04/06/alliance-data-sees-minimal-impact-data-breach-epsilon/ Says that the largest impact will be due to the loss in trust from its customers (Source for Quote) http://www.epsilon.com/News%20&%20Events/Press%20Releases%202011/Epsilon_Notifies_Clients_of_Unauthorized_Entry_into_Email_System/p1057-l3

WHAT NEXT? What are the critical issues in this case? Who are the stakeholders? What can Sony learn from other similar scenarios? How will Sony compensate PSN consumers for this malfunction? How can Sony not lose consumer confidence in products? How should Sony handle the regulatory environment surrounding data theft protection? What communications should Sony make and to whom?