4 ms·
I'm glad to see a solid fine given for a data breach. I've worked on projects in this sector before, and it's a common story to others - client cuts cost as mu
by EnderMB 7y ago
I'm glad to see a solid fine given for a data breach.
I've worked on projects in this sector before, and it's a common story to others - client cuts cost as much as possible, until the risk of an inferior product has grown too high to handle. It's a race to the bottom, and security rarely comes into consideration outside of a basic pen test being mentioned (if it happens).
Still, I'm quite annoyed at the lack of follow-up against what is blatant bullshit from BA. When your business is so heavily reliant on taking payments online, their security procedures should be airtight. I can understand that it's quite a clever hack, but it's security 101 to know what third-party code is doing on your server.
The fine is good, but it would be nice to enforce rules where a company caught in a data breach has to accept liability and not contest the severity.
- JustSomeNobody 7y agoI think what happened to D-Link should be standard. They have to have 10 years of independent security audits.
- Bombthecat 7y agoThe question is, what kind of people do those kind of companies look for / take. Are they looking and taking "just here to mark a check box, I don't care if it works or is true... Or do they take people who will tell them (and they react) what is wrong? More often then not you see something like this: encryption too weak: me guys, this is too weak! Answer : it's good enough for this scenario in this network. And they proceed to mark the box... Encryption existent..
- EnderMB 7y agoI like this idea, although I would also like to see a push towards the improvement of their tech team. IMO, these issues are rarely down to the people in the trenches, and more to do with a lack of budget or care from management. I would push for independent auditing, with a view towards the auditors ensuring that the team in place is capable of continuing this work.
- martinald 7y agoNot quite sure how BA is getting away saying there was no fraud because of this. Many complaints on my twitter of people that used cards only with BA and ended up getting cards used.
- koheripbal 7y agoThis amount represents more than their profits for roughly two years. It isn't realistic and is likely a number released to make headlines. The point of regulation is to change corporate behavior, not drive them out of business. The stock market does not seem to think the fine will ultimately be anywhere near that high, with a drop in stock price of only 1.5%. As always, beware of headlines.
- ginko 7y agoAccording to wikipedia BA's 2016 net income was 1,473 million pounds.
- EnderMB 7y agoI'm not too bothered by the number, but am worried that a company will be able to talk their way out of punishment through misinformation. You only need to look at the latest Zoom vulnerability, and the Panera Bread data leak to see how companies will happily tell its users that everything is fine, while doing absolutely nothing to publicly resolve the issues being raised. To make things worse, a lot of people will blindly believe this, or take their side to be contrarian. As you've rightly said, regulation needs to change corporate behaviour, and while a hefty fine will do that, it's also a minor risk to a firms ongoing reputation. It's a cost that can be offset elsewhere - more than likely onto the customer. I would rather the fine be halved or even quartered, if it meant that BA had to publicly accept full responsibility, and to push for independent auditing of all of their software.