4 ms·
Most companies are poorly run. Security and privacy safeguards are either non-existent or easily overridden.
by confluence 12y ago
Most companies are poorly run. Security and privacy safeguards are either non-existent or easily overridden.
- zo1 12y agoAnd some of them rely on the goodwill / honesty of the employees that have access to said sensitive data. Might not be the best way to go around it, but it does happen.
- dredmorbius 12y agoMore to the point: confidentiality of customer data is at best a secondary concern, and often not at all, until it becomes "a problem" (lawsuit, news scandal). More story time. I worked for a firm providing services to a large revolving consumer credit organization. These companies are essentially two things: a really impressive transactions processing network (the volume of traffic they handle is immense), and branding. Think of all the credit card commercials you've seen. That's the branding side at work. As a contractor of theirs, there was a requirement to go through their data security training. And while, yes, PII (personally identifiable information) was a concern, the vast bulk of the message, and emphatically highest concern, was with the brand, business plans, and similar information. That is, a company with vast holdings of personal information (described by a military acquaintance with intelligence ties in the late 1990s as "more than we've got" from the perspective of the TLAs, though that status may have since changed), was more concerned with how its trademarks and marketing campaigns were protected was ... revealing.
- confluence 12y agoGotta focus on them core competencies. Identical services don't market themselves, someone has got to spend a lot of money to convince people of their uniqueness, and that makes security secondary.