June 15, 2014 -- Peter Drucker, considered by some to be “the man who invented management,” usually gets credit for the phrase, “Culture eats strategy for breakfast.” Target’s woes following its historic data breach last November proves how true it is.
It seems clear at this point that the breach was disastrous for the company. First-quarter sales figures following the breach showed a 16% decline over the same period the year before, and Target’s stock has fallen 11 percent since December – though the $941 million quagmire that was the company’s Canada expansion certainly didn’t help matters, either.
I believe that guttered consumer confidence plays a significant role -- something that could have been avoided had Target’s post-breach emphasis been less on risk assessment and messaging and more on mitigation through quick action.
While there have been surveys that tell a different story, with at least one reporting that more than 60 percent of Target shoppers aren’t too worried about their data security, it’s worth bearing in mind what that sage pundit Sarah Palin once pointed out: polls are for strippers and cross-country skiers. The common wisdom now is that a breach can undo years of brand equity, and that appears to be the case at Target.
A New Direction
On May 28, the proxy adviser Institutional Shareholder Services recommended that Target replace seven of its 10 board members, citing the data breach last November. “The data breach revealed that the company was inadequately prepared for the significant risks of doing business in today’s electronic commerce environment,” the ISS statement said. The shareholders have since decided against the ISS recommendation, however, keeping its board members.
In a spirited written defense of the Target board, its interim chairperson pointed out that pre-breach the company had increased its information security team to 300, annually trained more than 350,000 employees to better protect customer data and had a 24-hour operations center constantly reviewing suspicious activity. Unfortunately, when the moment of truth arrived, and the warning bell clanged, someone overrode the system on several occasions and the data was leaked methodically over several days first within the Target system and then was transmitted to Russitarget="external"rel="nofollow"a for sale on the black market.
The ISS recommendation followed on the heels of some major changes at the highest levels of the company. CEO Gregg Steinhafel walked the plank in early May about a week after announcing a major hire in Bob DeRodes, formerly of Homeland Security, who became the company’s new chief information officer.
The changes at the top were a good sign, since both the breach and its fallout were the consequences of failed leadership, but they were not enough.
Target never addressed the bigger problem regarding its handling of the breach: the company was too slow, less than transparent and insufficiently empathetic -- and that was a failure of culture from the boardroom to the mail room.
The recommendation of ISS suggests this in no uncertain terms. The ultimate leaders of a company are its board members. The proxy’s recommendation signals something new in the business landscape. In the age of transparency and the 24-hour news cycle, there is nowhere to hide -- not even in the boardroom. Hackers have been preaching that for years and identity theft victims understand that as well.
The Root of the Problem
It is with good reason that Target finds itself in a tough spot these days, and it is by no means only because they mismanaged their data security exposing millions of their customers to fraudsters.
As Target said in a recent statement regarding data security: “Target was among the best-in-class within the retail industry.” In light of the questionable state of information security in the retail world and the mega breaches that have plagued the sector for years, I am not sure what that really says about Target.
Read More From Credit.com: Identity Theft: What You Need to Know
That said, the sad reality is that there’s no longer a “best” when it comes to security. Breaches are the third certainty in life. In the age of the super hacker, there is no such thing as failsafe data security. Hackers love to prove they can do things, make scads of money when they do, and there is little they cannot accomplish with sufficient computing power that is unwittingly aided and abetted by the weakest link in all security programs -- humans.
Read More From Credit.com: How Can You Tell If Your Identity Has Been Stolen?
The failure in leadership at Target was a failure in vision. Target talks a lot about its guests, but by not having a strong culture of responsiveness to the best interests of their guests they showed a complete lack of hospitality. In the age of the breach, reaction is everything. The actions taken when your customer’s information has been breached need to be drilled like missile launch exercises on a nuclear submarine so that they become second nature and the notification process is pure muscle memory.
Target failed not only because its information strategy failed, but because its culture took a backseat to the misguided strategic notions that expressions of remorse, 10% discounts and bold reactive measures after millions of consumer records have been improperly accessed can win back the hearts and minds of customers who have been put in economic harm’s way. In a corporate culture that assumes and prepares for the worst-case data security scenarios, and puts the emphasis on urgency, transparency and empathy, the true risk of a breach— massive loss of customer loyalty -- can be contained and perhaps reversed. Putting the pitfalls of the inevitable into human terms is how you build and sustain brand equity.
Adam Levin is chairman and co-founder of Credit.com and Identity Theft 911. His experience as former director of the New Jersey Division of Consumer Affairs gives him unique insight into consumer privacy, legislation and financial advocacy. He is a nationally recognized expert on identity theft and credit.