Earlier quoted context omitted.
There are several ways we could write a list of best practices. But the simplest would be to simply attach a financial cost to leaking any personal data to the open internet. This is essentially how every other industry already works: If my building falls down, the company which made it is financially liable. If I get sick from food poisoning, I can sue the companies responsible for giving me that food. And so on. We…
Software is in a very unique position. It can be attacked all the time with completely impunity. Buildings are completely vulnerable even to simple hammer breaking windows, locks have been basically broken for decades Food processor is easily vulnerable to poisoned potato. Only the software has to take all attacks humans can come up with and withstand it. What other industry has to deal with that? Maybe military, arm…
If I make a window of bulletproof glass, it's a lot harder to compromise.
If I surround my building with a wall topped by razor wire, it's a lot harder to compromise. (Unless, of course, I'm making an action film.)
Depending on what or who I'm protecting, I might find these solutions very valuable. Similarly in software, depending on what or who I am protecting, I might be very interested in various security measures.
So far, we've managed to escape an incident where bad actors have compromised systems in a way that's led to severe loss or harm. People are terrible at evaluating risk, so people tend to assume the status quo is okay. It's not, and it's only a matter of time before a bad actor does some real damage. Think 9/11 style, something that causes an immediate reaction and shocks the population. Then, suddenly, our politicians will be all in favor of requiring software developers to be licensed; liability for companies that allow damages; etc.