Built Wrong

Richard Bird has spent decades inside the cybersecurity industry and has questions about the results. A seven-time C-level executive, author and speaker, he writes about security, AI, identity, privacy and the uncomfortable gap between what the cybersecurity ecosystem promises and what actually happens. Built Wrong is where he works through what we got wrong, why it matters, and what we should build instead.

Sep 23 • 4 min read

The "Remedy" Nobody Measures


The "Remedy" Nobody Measures - Part 1

Oh, hey! Another free credit monitoring service I get instead of actual security.


Every breach letter ends with the same apology, and frequently the offer of a service. If you live in one of six states in the U.S., the remedy is required by law.

Nobody has ever shown it protects anyone, and nobody in the supply-chain that provides or promotes it is paid to find out.

You’ve read the letter. Probably more than once, just this year alone.

It opens with how seriously a company takes your privacy, and it closes with the offer: twelve or twenty-four months of complimentary credit monitoring, an activation code, and an enrollment deadline.

Let’s try a thought experiment. Imagine a treatment offered to tens of millions of people, mandated by several states, paid for by someone other than the patient, and never once tested to see whether it works.

No trials, no outcome data and nobody asking if it is really working. We would call that a scandal.

In breach response, we call it standard practice.

The record, or as much as we get of one

The most serious look the federal government has taken at these services came from GAO, twice. In March 2017, it found that credit monitoring can alert you to a new account opened in your name but does not prevent that fraud and does nothing about misuse of the accounts you already hold.

The effectiveness of identity monitoring, the dark web scanning half of the bundle, was unclear. And these services generally ignore medical identity theft and tax refund fraud.1

In March 2019, GAO went back and looked harder. It searched the scholarly databases and interviewed 35 academic, consumer, government, and industry experts. It did not find a single study analyzing whether people who sign up for these services suffer less identity theft, or catch fraud any faster, than people who watch their own accounts for free.2

The GAO also asked seven providers how they measure effectiveness. The answer: they measure how customers use the product, whether customers are satisfied, and whether the alerts get delivered. None of that addresses whether the service works better than what consumers can do on their own. Two of the providers said outright that their services focus on detection and cleanup, not prevention.3

The buyers of these services are not asking either.

The GAO found that organizations purchasing these services after a breach do not necessarily base the decision on effectiveness. They base it on legal requirements and on the expectation that they should do something. Retail and banking associations told GAO that one year of monitoring has simply become the industry standard.4

The GAO asked the Office of Management and Budget to analyze how these services perform against cheaper alternatives. That recommendation, made in 2017, is still open and unaddressed. The OMB did not respond to the GAO’s repeated requests for an update in 2018 and 2019,5 and at the GAO’s most recent check it still had no further update.6

Let’s look at the one program where the numbers are public.

After its 2015 breaches, The Office of Personnel Management (OPM) obligated about $421 million for monitoring, insurance, and restoration services for roughly 22 million people. About 13 percent used them. Sixty-one insurance claims had been paid, averaging $1,800, against a Congressionally mandated coverage limit of $5 million per person.7

LifeLock, for years the loudest brand in the category, told the SEC that reimbursements under its $1 million service guarantee were not material in aggregate for 2013 through 2015.8

A guarantee that almost never pays, attached to a service nobody has tested. That is the product.

Aimed at the smallest target

Credit monitoring watches for one thing: new accounts opened in your name. That is the rarest form of identity theft.

The Bureau of Justice Statistics estimated 23.9 million identity theft victims in 2021. Fewer than 1 percent of people had their information used to open a new account.9 A University of Michigan analysis pooling every BJS Identity Theft Supplement from 2008 to 2021 found that misuse of an existing credit card hit about 48 percent of victims and misuse of an existing bank account about 42 percent. New-account fraud hit under 8 percent.

Only .81 percent of victims discovered the crime by checking their credit report.

Banks’ own fraud detection caught roughly 38 percent.10 Monitoring by banks and individuals is like a burglar alarm that tells you someone stole your TV, laptop and car 6 months ago.

To be intellectually honest, the rare slice is also the expensive one. BJS found new-account victims lost $3,430 on average, against $620 for credit card misuse and $670 for bank account misuse.11 That is the best defense of monitoring, and it still loses to the credit freeze.

The GAO calls the freeze the only consumer option that can prevent new-account fraud, and a federal law that took effect in September 2018 made it free at all three bureaus.12

One prevents the crime. The other sends you an email about it.


✉️

Subscribe to Built Wrong

Join the Newsletter →

📕

Follow The Built Wrong Book Launch

Get Book Updates →

📊

Explore the Hacker In A Hoodie Index

See the evidence →

Notes

  1. U.S. Government Accountability Office, Identity Theft Services: Services Offer Some Benefits but Are Limited in Preventing Fraud, GAO-17-254, March 30, 2017, including recommendation status as updated on the product page. https://www.gao.gov/products/gao-17-254
  2. U.S. Government Accountability Office, Data Breaches: Range of Consumer Risks Highlights Limitations of Identity Theft Services, GAO-19-230, March 27, 2019, especially pp. 10–13, 17–22, 27–32. https://www.gao.gov/assets/700/698899.pdf
  3. GAO, Data Breaches.
  4. GAO, Data Breaches.
  5. GAO, Data Breaches.
  6. GAO, Identity Theft Services.
  7. GAO, Data Breaches.
  8. LifeLock, Inc., Form 10-K for fiscal year 2015, Note 18, Contingencies. https://www.sec.gov/Archives/edgar/data/0001383871/000162828016011544/lock10-k20151231.htm
  9. Bureau of Justice Statistics, “Victims of Identity Theft, 2021,” press release and bulletin NCJ 306474, October 2023. https://bjs.ojp.gov/press-release/victims-identity-theft-2021
  10. Lina Alkarmi, Armin Sarabi, and Mingyan Liu, “Estimating the Social Cost of Corporate Data Breaches,” arXiv:2603.21270, March 2026 (preprint). https://arxiv.org/pdf/2603.21270
  11. BJS, “Victims of Identity Theft, 2021.”
  12. GAO, Data Breaches.

Richard Bird has spent decades inside the cybersecurity industry and has questions about the results. A seven-time C-level executive, author and speaker, he writes about security, AI, identity, privacy and the uncomfortable gap between what the cybersecurity ecosystem promises and what actually happens. Built Wrong is where he works through what we got wrong, why it matters, and what we should build instead.


Read next ...