> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.
In my current role at a startup, when a conflict between schedule/time or convenience conflicts with proper data security, I ask people to envision how our processes would look as a news headline or would fare in a legal discovery.