‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. louthy · · focus · HN ↗
      Or … and hear me out on this one … care?
      1. toomuchtodo · · focus · HN ↗
        Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky.

        To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.

        (cyber consultant and practitioner)

        1. my-huge-pony · · focus · HN ↗
          Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached?

          I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.

          1. augment_me · · focus · HN ↗
            This is already the law, but the shell company signs the ownership of the data and the security responsility. The university in this case is just using APIs to load and store stuff to someone else's servers.

            If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.