‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. louthy · · focus · HN ↗
      Or … and hear me out on this one … care?
      1. AIiscoming · · focus · HN ↗
        Lets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it.

        I might suggest a construct like this too.

        What do you think how much it cost to do it perfect?

        1. louthy · · focus · HN ↗
          Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.

          It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).

          1. augment_me · · focus · HN ↗
            Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional".

            There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.

            1. josephg · · focus · HN ↗
              > There is no capitalist incentive for the latter

              This is literally the point of data breach laws like this. To provide a financial incentive to take this stuff seriously.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.