At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already.
The chickens will continue to come home to roost until people treat digital security as seriously as physical security.
While everyone here says "Oh that's terrible!" the market says "Oh that's terr-SQUIRREL" and then forgets it ever happened. Additionally, no appropriate fines have been levied nor jail time handed out for this sort of thing - right now the sane approach (money wise) is just occasionally have a breech and offer up an apology.
> The chickens will continue to come home to roost until people treat digital security as seriously as physical security
Do people take physical security seriously? It doesn't seem like it.
Anyway, when I was an undergrad in the 1990s and took a computer security class our professor (Gene Spafford) talked about security being primarily an economic question. And that is generally how security, both physical and digital, has been treated since forever. And how it will always be.
The economic and physical damage caused by poor digital security is a rounding error compared to everything that happens in the real world.
As long as you understand that the following link is at least partly tongue-in-cheek, you may find this to be an entertaining read:
Very few people take workplace physical security seriously outside of a few industries like prisons. Complete strangers have physically unlocked and opened the door for me to enter "secured" areas because they assumed that since I was walking in that direction I must be authorized to enter.
Laws won’t change this. It will only make it a compliance burden and the same mistakes will continue to happen. Plus standards and practices move way faster than laws.
What investors should be concerned about is the reputational risk and loss of business to competitors that are able demonstrate more transparent and secure practices.
Maybe laws for monopolies, but not for competitive markets where consumers have choice to shop around.
For a competing business these dumps are a powerful marketing tool. It’s a direct client list. They just have to be able to show that their security is better.
Laws would make things so much worse for everyone. The key is to keep hacking away at all systems. Break things apart and build them back together. And win customers by showing that you can!
I wonder if we should take mandatory breach reporting a step further too and require them to list all security vendor products and services that were in place at the time of the breach.
Should security solution vendors be held to account for failing to live up to the bold claims they make?
It may not be workable, but when big businesses have invested millions in tools and services I can't help feeling there should be some vendor accountability.
That would be unfair, as the efficacy of most products depends on how they are configured, monitored and maintained.
For example, if I install an application whitelisting system, but whitelist too much, pay no attention to logs and alerts, or never patch it, then that's not really the vendor's fault.
> At some point people will realise that holding large quantities of sensitive information is a liability, not an asset.
That's my line :):
"It forces you to think about data as a liability, rather than an asset and that particular mindset is a good one to have when you are dealing with end user data."
It stood the test of time rather well. Now we see a US push for a similar law and articles such as this one hopefully will cause that to arrive sooner rather than later.
This company is dealing in financial transaction data. Someone needs to hold it, and it can be deleted (especially when someone asks for it). I don't see how this particular situation advances your position.
For one they could split it into 'hot' data and 'cold' data that needs to be stored for legal and compliance reasons but that does not necessarily need to be part of the live set. That strategy alone would seriously limit the impact of a lot of these breaches.
Absolutely agree, and to further it I think this data liability goes beyond PII. Any data which could be used nefariously if publicly available is a potential liability if leaked - NDA'd documents, product roadmaps, source code of closed source software, private keys, pre-results earnings, the list is enormous.
With the shift in the economy from physical goods to IP I don't see why laws for physical goods storage, warehousing and safekeeping (eg. safety deposit boxes) won't be updated to include the digital equivalents in the not too distant future. And at that point I wouldn't want to be a Dropbox, EC2 or DigitalOcean unless I was very very sure of my security systems, never mind being a Facebook or Google.
Having a good definition of the data life-cycle is a very important step. A lot of companies only do CRU but forget about the D because they feel that more data is more value. As you correctly infer at some point in time the value of the data no longer outweighs the liability and it should be deleted, and long before that it should probably be moved to a much harder to reach system that contains historical data.
The chickens will continue to come home to roost until people treat digital security as seriously as physical security.