Earlier quoted context omitted.
> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers an…
Yeah, security checkboxes don't necessarily result in good security. One option is to still make companies liable for security breaches, regardless of what meaningless checkboxes they may have checked, and then trust that they'll figure it out. Real liability would shift things from theater to weighing actual risks and costs. Another option is we can empower red teams (security researchers) to test the security of al…
It's impossible to ensure what you're asking for. That's the problem with all of these kinds of rules, but worse, because at least something like SOC2 is providing a safe haven if you do the right things. Making companies "liable" for breaches is tantamount to saying that companies will never develop software again, because the risk is simply too great. Certainly, if I were in that kind of a situation, I'd rarely use a third-party service, and never use a startup, or a smaller company. I can't be responsible for the risks of AT&T, and every software company AT&T uses. That's crazy!
We're going to have to come to terms with the fact that "security" is a verb, not a noun, and that data leaks are going to happen, even in the best secured institutions. Punitive rules might improve security in the marginal case, but only at huge costs industry wide.