The fact that credit agencies, etc are allowed to report incorrect information without consequence is a similar problem. There's no incentive for them to ensure accurate info. In fact they're incentivized to accept false information as it lets them offer "credit monitoring" as a service people have to pay for.
Despite decades of hacking attacks, companies leave sensitive data unprotected
41–45 of 45 posts
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#42Earlier quoted context omitted.
>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't. Of course if…
Fines don't happen until they get caught. How long can a company go and how much can they make before they get caught? What happens to the executives? They just move on pointing to their old success numbers. I run internal audits for a large org as part of a strike team when my company is acquiring smaller orgs. External auditors are a joke and it's incredibly easy to slip things by them. The only reason we catch stu…
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#43If we take a scenario where sensitive data is taken but there is no impact on business operations (e.g. encrypted systems & backups) it is difficult for businesses to be impacted apart from reputational damage. And realistically given the amount of cyber attacks on the news, chances are your customers will forget about it over a short period of time.
The issue with reputational damage is that we are in this "new" world of cyber security and we know its important and everyone else is being attacked (it seems). But also many people if not most people don't have security together themselves, or have any idea of how to poke a stick at it. So we're in this not so mature stage of cyber security where if a organisation has its data taken, it's more forgiving than say rampant financial fraud. Which has had decades if not centuries of global fraud incidents impacting the pockets of billions of people. As such when it comes to financial risk and penalties, there are more real scenarios in which people can do the wrong thing and it have a material impact.
It's simply a case of there not having been enough material cyber security incidents that have generally impacted people and organisations. It's got to get worse before it gets better.
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#44Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#45Earlier quoted context omitted.
>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't. Of course if…
Look up the cap on fines per year. It's less than $2m. I've consulted for healthcare companies where that is a literal rounding error on their bottom line. They. Do. Not. Care.
I agree with you that the cap is too low. It should cap based on gross or revenue. I suspect it's so that the smaller companies won't get destroyed by fines leaving the larger ones largely unaffected, but I'm speculating.