After two full years of investigation into a 2014 security breach that exposed the personal information of 40 million customers, The Home Depot Inc. appears to be finally settling the case. The Atlanta-based company has reached a settlement that will pay 46 states a total of $17.5 million.

The incident occurred in 2014, when hackers gained access to the network , deploying malware in an automated checkout system, allowing access to payment card information for customers who used the self-checkout systems between April 10 and September 13, 2014. The company agreed to implement a series of practices and improvements designed to strengthen information security, which under the terms of the agreement, must be implemented within 180 days after December 21, 2020.
“The Home Depot failed to protect consumers and put their data at risk,” said New York Attorney General Letitia James, whose state will receive about $600,000. The company agreed to undergo an information security assessment after the settlement.
Among the moves Home Depot must make as a result of the settlement is adding a chief information security officer, who will report to both senior and C-level executives and the board. Officials also agreed to provide appropriate security briefings and privacy training to every employee who has access to the company’s network or is responsible for consumer personal information. Other key efforts include maintaining software, ensuring systems are fully updated with the latest security measures and using appropriate encryption methods.

To prevent future breaches, engineers are tasked with segmenting cardholder data environments and mapping connections to the company’s network to identify how data is being trafficked. In addition to two-factor authentication for system administrator accounts and remote access and “strong and complex passwords,” the company must take steps to ensure password rotation, firewalls, file integrity monitoring and payment card security, as well as maintaining separation of development and production environments.
Logs must also be created to monitor network activity for any device attempting to connect to data . According to the settlement, after the improvements are published, the company will be required to undergo annual risk assessments, including documentation of the safeguards implemented.
