3 ms·
Putting aside the whole "punishing the victim" argument, the problem is that it's excruciatingly hard to draw a line between "being careless" and "you did every
by bodz 9y ago
Putting aside the whole "punishing the victim" argument, the problem is that it's excruciatingly hard to draw a line between "being careless" and "you did everything right but it still wasn't enough", and thus it's really hard to punish someone for cybersecurity mistakes. I work in cybersec consulting, and it's certainly true that a large number of companies are simply not investing enough money/time/effort into cybersecurity protections, and are thus doing a disservice to their customers.
However, there are also plenty of companies that spend hundreds of millions of dollars, with massive cybersec departments devoted to protecting from breaches like this, doing pretty much everything they possibly can right, and they will still be hacked. Cybersecurity is incredibly difficult, incredibly expensive, and takes a really long time. And even if you get 99.999999% of your company completely impervious to attackers, it only takes that 0.0000001% of exposure to sink your ship. Cybersec is also constantly evolving, so it's nearly impossible to keep up with the latest attack vectors, etc.
Take the Target breach, for example: Target has a massive effort focused on cybersecurity. They actually have a cybersec research lab that some law enforcement agencies go to for help with cybersec issues. But the attack that hit them took them totally by surprise simply because it was a type of attack that hadn't really been considered, and thus was very very low on the radar (if there at all) when it came to protecting against it.
Now, companies in the US actually are held accountable (to an extent). Data breaches that result in HIPAA violations, for example, usually result in massive fines for companies. Violations of PCI-DSS will land you in hot water with the major payment card companies. Some states also have cybersec regulations that result in fines if you're found to be in violation of them during an audit. The problem, again, is that cybersec is constantly evolving and these regulations are years behind. The HIPAA cybersec requirements are actually pretty laughable, partly because of all the reasons listed above.
- yborg 9y ago>and thus it's really hard to punish someone for cybersecurity mistakes No. If you take it upon yourself to hold this information, you are accepting the responsibility for its disclosure. If you are not willing to accept penalty for this happening despite your best efforts, you should not be doing it.
- bodz 9y agoSo, what should we do? Should we just fire/jail everyone who has ever worked for a company that was breached? You realize that would be literally everyone, in pretty much every company ever, right? There's a saying in the cybersec world: "there are two types of companies: those who know they've been hacked, and those who don't realize it yet". Cybersecurity is a field where there's already not enough good talent. And even the very best talent is still going to not be good enough from time to time. It is simply completely naive and unrealistic to expect a company to be 100% hack-proof, and if you start punishing people for that, then you're just not going to have anyone taking the job at all, and you're going to have even less security.
- liberte82 9y agoOh come on. Anyone here who is a developer has at least some experience with raising a security concern to business or management and having it shot down as not important enough to worry about. We all know companies still aren't taking cybersecurity seriously enough, and it's because the consequences for a breach aren't severe enough.