13 ms·
I anticipate managers dissuading people from investigating possible breaches. If you don’t know there is a breach you don’t have to report it.
by dumbfounder 3y ago
I anticipate managers dissuading people from investigating possible breaches. If you don’t know there is a breach you don’t have to report it.
- elashri 3y agoThen you need to make it illegal to know of a breach and don't report it. This might give employees incentive to report their management illegal act of hiding a potential breach by obstructing internal investigation. Or better make the consequences of failing to secure system very painful and may put the company out of business. Not that 12 month of free credit monitoring for affected users. This will encourage companies to secure the data or better to not store what is not absolutely unnecessary because it is a huge liability. But of course governments like to access these data themselves from time to time.
- dumbfounder 3y agoYou can’t know unless you investigate, right? I am saying managers will see situations where it could have happened, and they can figure out if there was a breach, but then instruct people to not look for it. Or just make it not a priority. Or whatever. They don’t know for sure so they can’t say you knew and didn’t report it.
- cush 3y agoHow would that go down? "I believe that someone currently has access to our customer database" - "It's probably nothing. Carry on with your regular work. Nothing to see here." Luckily for consumers, the do nothing approach to this problem is more costly than disclosing.
- vaxman 3y agoBecause the hackers know, they may also threaten to report their victim’s tort (arising from any failure of their victim to self-report the data breach): https://techcrunch.com/2023/12/18/why-extortion-is-the-new-ransomware-threat/ https://techcrunch.com/2023/12/18/why-extortion-is-the-new-r...
- tekla 3y agoFunny, I see developers refusing to investigate breaches because "its not their job"