‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. amelius · · focus · HN ↗
      That's like blaming Seagate when your harddisk fails.

      No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

      1. augment_me · · focus · HN ↗
        Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.

        Seagate will not in a million years sign anything like this when you buy a HDD.

        1. SoftTalker · · focus · HN ↗
          It's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.