You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional".
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
augment_me · · focus · HN ↗
Minimizes money usage and does not require any security investments
louthy · · focus · HN ↗
AIiscoming · · focus · HN ↗
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
louthy · · focus · HN ↗
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
augment_me · · focus · HN ↗
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
josephg · · focus · HN ↗
This is literally the point of data breach laws like this. To provide a financial incentive to take this stuff seriously.