3 ms·
Don't stop there. You can make some even greater efficiencies. By having cyber-insurance you can do nothing and just have someone pay you out money when you fuc
by nonrandomstring 2y ago
Don't stop there. You can make some even greater efficiencies. By
having cyber-insurance you can do nothing and just have someone pay
you out money when you fuck up. There's no end of ways security
theatre and half-arsed "compliance" can help lower standards,
- quacksilver 2y agoTo be fair, if using insurance and risking being hacked anyway has a higher expected net payoff than implementing a given set of security measures, then you may be financially incentivized (or legally beholden to your shareholders) to take the risk, get hacked and pay any fines if it gets discovered. The security literature refers to it as "risk transference". Chances are your company ultimately exists to optimize for shareholder value