Earlier quoted context omitted.
This is exactly what my company went through just a few months ago when we hired an IT security guy whose first order of business was setting up a Palo Alto Networks firewall. Before turning on the MITM functionality he gave a presentation to everyone about what it did, and nobody (support staff, developers, administrators, management...nobody) seemed to mind except for me. This was what I sent to the HR lead immedia…
But it's far worse than that. Look further down in the thread where a security guy has pre-emptively invoked the "acceptable use" policy to cover for up for incompetence to secure the MITM proxy appropriately. Acceptable use policies are not self-enforcing, they are really only used selectively, regardless if they say you shouldn't use your computer for personal use. Everybody does that to some degree and it is accep…
On the topic of liability and owning up to a potential hack, I think my company would be transparent about it, based on a history of being transparent about many atypical things in the past. We're not public, never received any VC funding, and nobody has any equity stake in the company except for the owner, who himself goes over the entire company's income statement in front of all the employees once per year to let us know where all the money's coming from/going to. I do believe he would do whatever he could to make it right, because the buck stops with him and him alone.
Clearly that's only a small comfort if our personal information is leaked, but I don't think in my case it would be covered up. I could certainly see that being the case in most corporate structures, though.