4 ms·
That's like saying we've all written code susceptible to a buffer overflow, so when a medical device (or air traffic control or whatever) vendor does the same t
by davb 9y ago
That's like saying we've all written code susceptible to a buffer overflow, so when a medical device (or air traffic control or whatever) vendor does the same then it's ok.
There's a reasonable expectation that those sorts of companies produce very resilient, fail safe software.
Credit reference agencies deal in PII. It's their main asset. It's incumbent on them to protect that data with secure coding practices, proper patching policies, pen-testing, etc. Above all else, that's their key professional obligation.
If they refuse to do this, they shouldn't be in business. I would go so far as to say that given their size and available financial assets they should be held criminally liable. There's no reasonable excuse for them not securing the data entrusted to them.