analysis. Was there a flaw in their information security governance? What could/should

Please answer both questions: Recently, Equifax, one of the three major credit reporting organizations, revealed a major security breach.  Let’s collectively investigate the incident, find and report the facts. The second thread is for our governance analysis. Was there a flaw in their information security governance?  What could/should have been done differently? Again, be sure to cite your source(s).