FR version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
59% Positive
Analyzed from 1550 words in the discussion.
Trending Topics
#data#business#care#system#companies#fines#security#company#don#breaches

Discussion (68 Comments)Read Original on HackerNews
Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
Minimizes money usage and does not require any security investments
Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.
So, there is that.
To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.
(cyber consultant and practitioner)
I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.
No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
Seagate will not in a million years sign anything like this when you buy a HDD.
Sort of like EULA's a lot of the "value" is incredibly theoretical.
guess who holds the bag if capacity needs collapse
I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all.
I'm thinking:
(The following example is in "American" terms, I assume some other countries have similar ideas as SSN though)
- Name and address or name and phone number leak: $100 per customer affected.
- Email: $50 per customer affected, or $100 if tied to any other data.
- Social Security numbers: $2000 per customer affected
- Unsalted or plaintext passwords: $500 per customer affected.
- Cap is the greater of 200% of annual EBITDA, or 20% of revenue
Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users.
This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse.
My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.
10% maximum mean nothing if it’s not enforced, you got to make examples.
* Before Tax Revenue
* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.
* Includes Worldwide Revenue
* Includes companies based in all other Countries.
I would have went for 20%, but if he above applies I wish the US would do the same.
Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.
Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.
You can’t. You don’t need source for that, just common sense.
Exploits are discovered every day, bugs happen, bad actors.
You can do the best system, shit still happen.
BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ?
If the cia couldn’t prevent it, I bet you can’t.
Edit: "That'll be $23B. Cash or card?"