Target CIO Beth Jacob resigns following security breach
NEW YORK (AP) - Target Corp. Chief Information Officer Beth Jacob is resigning effective Wednesday as the retailer overhauls its information security and compliance division in the wake of a massive pre-Christmas data breach.
Target Chairman, President and CEO Gregg Steinhafel said in a statement released to The Associated Press that the company will search for an interim chief information officer who can help guide the company through the transformation. Jacob had been in her current role since 2008 and oversaw teams in the U.S. and India.
The resignation reflects the pressure that the nation's second-largest discount retailer faces as it tries to restore its reputation among investors and shoppers nervous about the security of their personal data.
Target said Jacob's resignation was her decision. But analysts say Jacob, who brought a series of technology initiatives to Target's stores and its website, was a scapegoat.
"Target has been obviously impacted. People are questioning Target's security. And she was the fall guy," said Walter Loeb, a New York-based independent retail consultant.
Target disclosed on Dec. 19 that the data breach compromised 40 million credit and debit card accounts between Nov. 27 and Dec. 15. Then on Jan. 10 it said hackers also stole personal information - including names, phone numbers, and email and mailing addresses - from as many as 70 million customers.
Target has said it believes hackers broke into its network by infiltrating the computers of a vendor. Then the hackers installed malicious software in the checkout system for Target's estimated 1,800 U.S. stores.
Target, based in Minneapolis, also plans to look outside the company for a chief information security officer and a chief compliance officer. Before the overhaul, information security functions were split among a variety of executives. Target's new chief information security officer will centralize those responsibilities, the company said.
Compliance duties were previously overseen by Target's current vice president of assurance risk and compliance, who already had plans to retire at the end of March. Now, Target is separating the responsibility for assurance risk and compliance.
Target also said it is working with an outside adviser, Promontory Financial Group, to evaluate its technology, structure, processes and talent as part of the overhaul.
"While we are still in the process of an ongoing investigation, we recognize that the information security environment is evolving rapidly," Steinhafel said in a statement.
Target will be facing fallout from the theft for a while. The company said last week that its fourth-quarter profit fell 46 percent on a revenue decline of 5.3 percent as the breach scared off customers.
Target said sales have been recovering as more time passes since news of the breach. But the company expects business to be muted for some time. It issued a profit outlook for the current quarter and full year that was below Wall Street estimates as it faces hefty costs related to the breach.
Steinhafel told investors last week that Target has updated shoppers early and often on the investigation and is offering free credit monitoring for a year for any customer shopping at a Target store who wants it.
The company is also equipping its locations with more security technology. Target is accelerating its $100 million plan to roll out chip-based credit card technology, which experts say is more secure than traditional magnetic stripe cards.
Target's breach may eventually eclipse the biggest known data breach at a retailer, one disclosed in 2007 at the parent company of TJ Maxx that affected 90 million records.
In a posting last week on a company blog, Steinhafel said, "In the weeks ahead, we hope to understand more about how this attack happened. And will use what we learn to inform our guests, make Target a safer place to shop and to drive change across the broader retail industry."
In a letter to Steinhafel furnished by Target, the outgoing Chief Information Officer Jacob said that resigning was a "difficult decision," but she said that "this was a time of significant transformation for the retail industry and for Target." She did not mention the data breach.
During her tenure as chief information officer, Jacob received attention for helping Target respond more quickly to shoppers' shift to researching and buying on mobile devices.
That included a mobile app called Cartwheel, which combines social networking and discounts. She also oversaw Target's innovation lab that opened last May in San Francisco. The lab looks at futuristic technology, such as how wearable gadgets like smart watches might be used in its stores.
Shares of Target are down 87 cents to $60.46 in midday trading Wednesday. The stock is down a little over 3 percent since the breach was disclosed.