SCENARIO
Please use the following to answer the next QUESTION:
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern.
There were neither adequate rules governing access to customer information nor procedures for purging and destroying outdated data. In her research, Roberta discovered that even low-level employees had access to all of the company's customer data, including financial records, and that the company still retained obsolete customer data dating back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needed-to-know basis, restricting employees' access to customer information to data relevant to their job responsibilities. Second, create a highly secure database for storing customers' financial information, such as credit card and bank account numbers, separate from less sensitive information. Third, identify outdated customer information and develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting, where she presented the recommendations in her report. She explained that because the company had a national customer base, it was required to comply with all applicable state breach notification laws. As a result of Roberta's guidance, the company was able to notify customers promptly and within the timeframes required by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta had recommended.
The privacy program is now far more effective because of these changes and because privacy and security are considered the responsibility of every employee.
Based on the problems with the company's privacy and security practices that Roberta identified, what is the most likely cause of the breach?