3 ms·
Data breach insurance is not helping. Using weak passwords, leaving credentials where others can see them and downloading infected files can all lead to compro
by vegetablepotpie 2y ago
Data breach insurance is not helping.
Using weak passwords, leaving credentials where others can see them and downloading infected files can all lead to compromised data. Data breach insurance is specifically designed to protect a company in the aftermath of such an unexpected event.
Business correctly recognizes data breaches as a risk. The insurance industry allows companies to export that risk to them. Data breach insurance pays for the financial impact to the business as a result of a data breach. This does not protect customers and in-fact creates misaligned incentives between a business and its customers.
One solution would be to legislate that insurance is not acceptable for an organization to mitigate cyber risk. States and the federal government could do this by passing a law. I don’t see something like that getting passed though. The insurance industry and every business, both large and small, will lobby hard against it. You’d really need a strong grassroots consumer advocacy group to push hard for this, something that tells people’s personal stories to the media.
- lll-o-lll 2y agoWe don’t need legislation, just dramatically increased penalties for a breach. Now insurance premiums drastically increase unless you’ve done x, y, z. I’m not all “free market solves it all”, but it definitely works well at balancing money through the system. We just haven’t correctly priced a data-breach.
- sopooneo 2y agoExactly. At $500 or $1000 per record, PII starts to look highly radioactive. Companies would be avoiding it's collection with a passion. And those that had to hold it would be compelled to do so less stupidly.
- yjftsjthsd-h 2y agoMy first thought would be that insurance could be workable, but it might be too cheap right now. I would expect that when a company signs up for such a thing, they get audited and charged according to risk - a well run organization might find it a tiny cost, while say a company storing passwords in plaintext might find that their monthly bill is ruinous because they're practically guaranteed to be breached and subsequently fined into oblivion. Insurance shouldn't so much remove risk as amortize it.