Live data from Hacker News

Despite decades of hacking attacks, companies leave sensitive data unprotected

propublica.org

41–45 of 45 posts

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#41
Until they faces consequences other than "1 year of credit monitoring" it will continue. Especially given at this point various lawsuits mean most people have credit monitoring already.

The fact that credit agencies, etc are allowed to report incorrect information without consequence is a similar problem. There's no incentive for them to ensure accurate info. In fact they're incentivized to accept false information as it lets them offer "credit monitoring" as a service people have to pay for.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#42
post #18

Earlier quoted context omitted.

>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't. Of course if…

Fines don't happen until they get caught. How long can a company go and how much can they make before they get caught? What happens to the executives? They just move on pointing to their old success numbers. I run internal audits for a large org as part of a strike team when my company is acquiring smaller orgs. External auditors are a joke and it's incredibly easy to slip things by them. The only reason we catch stu…

But your company wouldn't even have a line item to look for those problems if regulations didn't require it. It's not a fool-proof solution but it's at least a foot in the door for improvement

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#43
One of the reasons is that businesses fail to understand or identify what the real risk is of having sensitive data taken. Even so, most organisations I have worked with couldn't even tell me where all of their sensitive data is, or even what they classify sensitive data as.

If we take a scenario where sensitive data is taken but there is no impact on business operations (e.g. encrypted systems & backups) it is difficult for businesses to be impacted apart from reputational damage. And realistically given the amount of cyber attacks on the news, chances are your customers will forget about it over a short period of time.

The issue with reputational damage is that we are in this "new" world of cyber security and we know its important and everyone else is being attacked (it seems). But also many people if not most people don't have security together themselves, or have any idea of how to poke a stick at it. So we're in this not so mature stage of cyber security where if a organisation has its data taken, it's more forgiving than say rampant financial fraud. Which has had decades if not centuries of global fraud incidents impacting the pockets of billions of people. As such when it comes to financial risk and penalties, there are more real scenarios in which people can do the wrong thing and it have a material impact.

It's simply a case of there not having been enough material cyber security incidents that have generally impacted people and organisations. It's got to get worse before it gets better.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#44
In Japan there are real consequences for exposure of personal information. Companies can be fined x-yen per customer based on the type of PII exposed. In addition to this the government can force a company to cease trading for a certain number of days based on severity (this has already happened at least once). I don't have any data pointing to whether breaches are any more or less common in Japan. But I can say security is taken more seriously, at least compared to other countries I've worked, and that full encryption of PII is now the rule rather than the exception.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#45
post #18

Earlier quoted context omitted.

>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't. Of course if…

Look up the cap on fines per year. It's less than $2m. I've consulted for healthcare companies where that is a literal rounding error on their bottom line. They. Do. Not. Care.

There's also a criminal liability aspect to it. I've worked for healthcare companies too and they do care, at least enough to have it in the conversation and to include the HIPAA officer in those conversations. Nowhere I have worked have they been flippant about it.

I agree with you that the cap is too low. It should cap based on gross or revenue. I suspect it's so that the smaller companies won't get destroyed by fines leaving the larger ones largely unaffected, but I'm speculating.

Post reply on HN