DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Target Appoints New Chief Information Officer, Outlines Updates on Security Enhancements

Posted on April 29, 2014 by Dissent

Press release from today:

Today Target Corp. (NYSE: TGT) announced the company has hired a new technology leader to help guide the company’s information technology transformation. Target also provided details on additional security enhancements the company has made following its 2013 data breach, and shared plans to incorporate MasterCard chip-and-PIN technology across its REDcard portfolio.

Effective May 5, Bob DeRodes will lead Target’s information technology transformation as executive vice president and chief information officer. In his role, DeRodes will assume oversight of the Target technology team and operations, with responsibility for the ongoing data security enhancement efforts as well as the development of Target’s long-term information technology and digital roadmap. The company is continuing its active search for a chief information security officer and a chief compliance officer.

“Establishing a clear path forward for Target following the data breach has been my top priority. I believe Target has a tremendous opportunity to take the lessons learned from this incident and enhance our overall approach to data security and information technology. Bob’s history of leading transformational change positions him well to lead our continued breach responses and guide our long-term digital strategy,” said Gregg Steinhafel, Target chairman, president and chief executive officer.

DeRodes comes to Target with more than 40 years of experience and is a recognized leader in information technology, data security, and business operations. He has been a senior information technology advisor for the Center for CIO Leadership, the U.S. Department of Homeland Security, the U.S. Secretary of Defense, and the U.S. Department of Justice. In addition, DeRodes has provided independent advisory services to corporations, private equity firms, and boards. DeRodes has also held top technology positions at a number of industry-leading, multinational companies including CitiBank, USAA Federal Savings Bank, First Data, Home Depot and Delta Air Lines. He also serves on the board of directors for NCR Corporation.

“I look forward to helping shape information technology and data security at Target in the days and months ahead. It is clear to me that Target is an organization that is committed to doing whatever it takes to do right by their guests,” said DeRodes.

Target’s Technology Enhancements

Since the initial confirmation of the data breach, Target has shared that there has been an active investigation. During that time, the company has taken significant actions to further strengthen security across the network, just a sampling includes:

  • Enhancing monitoring and logging
    • Includes implementation of additional rules, alerts, centralizing log feeds and enabling additional logging capabilities
  • Installation of application whitelisting point-of-sale systems
    • Includes deploying to all registers, point-of-sale servers and development of whitelisting rules
  • Implementation of enhanced segmentation
    • Includes development of point-of-sale management tools, review and streamlining of network firewall rules and development of a comprehensive firewall governance process
  • Reviewing and limiting vendor access
    • Includes decommissioning vendor access to the server impacted in the breach and disabling select vendor access points including FTP and telnet protocols
  • Enhanced security of accounts
    • Includes coordinated reset of 445,000 Target team member and contractor passwords, broadening the use of two-factor authentication, expansion of password vaults, disabled multiple vendor accounts, reduced privileges for certain accounts, and developing additional training related to password rotation

New MasterCard Initiative and Commitment to Chip-and-PIN

Today, Target also announced a significant new initiative as part of the company’s accelerated transition to chip-and-PIN-enabled REDcards. Beginning in early 2015, the entire REDcard portfolio, including all Target-branded credit and debit cards, will be enabled with MasterCard’s chip-and-PIN solution. Existing co-branded cards will be reissued as MasterCard co-branded chip-and-PIN cards. Ultimately, through this initiative, all of Target’s REDcard products will be chip-and-PIN secured.

Earlier this year, Target announced an accelerated $100 million plan to move its REDcard portfolio to chip-and-PIN-enabled technology and to install supporting software and next-generation payment devices in stores. The new payment terminals will be in all 1,797 U.S. stores by this September, six months ahead of schedule. In addition, by early next year, Target will enable all REDcards with chip-and-PIN technology and begin accepting payments from all chip-enabled cards in its stores.

“Target has long been an advocate for the widespread adoption of chip-and-PIN card technology,” said John Mulligan, executive vice president, chief financial officer for Target. “As we aggressively move forward to bring enhanced technology to Target, we believe it is critical that we provide our REDcard guests with the most secure payment product available. This new initiative satisfies that goal.”

“Target and MasterCard are taking an important step forward in providing consumers with a secure shopping experience, and the latest in payments technology,” said Chris McWilton, president, North American Markets for MasterCard. “Our focus, together with Target, is on safety and security.”

Ongoing Commitment to Information Sharing

In March, Target joined the Financial Services Information Sharing & Analysis Center (FS-ISAC), a non-profit private sector initiative developed by the financial services industry to help facilitate the detection, prevention, and response to cyber attacks and fraud activity. This step reflects the company’s continued commitment to shared responsibility between retailers and financial institutions with a focus on strengthening protections for American consumers.

The company also continues to voice support for responsible policy measures that help further enhance security for consumers, including supporting a national notification standard for all data breaches.

Category: Business Sector

Post navigation

← TX: Computer containing patient data stolen from Seton Healthcare
California man receives faxes intended for Michigan credit union containing social security numbers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • International cybercrime tackled: Amsterdam police and FBI dismantle proxy service Anyproxy
  • Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
  • N.W.T.’s medical record system under the microscope after 2 reported cases of snooping
  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.