3 ms·
The bar for not getting hacked is a lot closer to perfect than gross negligence
by someguynamedq 13d ago
The bar for not getting hacked is a lot closer to perfect than gross negligence
- louthy 12d agoThe bar is: do you have effective compliance in place? And are you audited? (ISO27001 [1] or similar). If you are hacked and you are seen to have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim. However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you. You may still get a fine, but it would be much reduced. It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business. It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost. [1] https://www.iso.org/standard/27001 https://www.iso.org/standard/27001