‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. amelius · · focus · HN ↗
      That's like blaming Seagate when your harddisk fails.

      No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

      1. augment_me · · focus · HN ↗
        Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.

        Seagate will not in a million years sign anything like this when you buy a HDD.

        1. louthy · · focus · HN ↗
          That’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too.
          1. augment_me · · focus · HN ↗
            Maybe it's different in the US, but in the EU you can get certified to be able to handle certain data securely, for example getting SOC/ISO/ESC certifications. When you then are looking for storage solutions you can in practice absolve yourself from liability/gross negligence if you choose a provider that has these certifications. So when an org needs cheap solutions, they find the cheapest compliant provider and hands are clean.
            1. louthy · · focus · HN ↗
              If you want to be certified for SOC or ISO in the US you have to check all your suppliers too. You can’t outsource your responsibility if you want to comply. I know this because I have been through it in the US, EU, and UK.

              If your supplier has these compliance audits in place and has the documentation to prove it, this isn’t “absolving”, it’s literally the diligence process.

              But a “shell company”, as per your original comment, is not going to reach a compliance threshold to allow the diligence chain to succeed. Just from a business continuity point of view they would fail, but there are plenty of other areas that would be problematic from a compliance standpoint.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.