You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional".
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data.
One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty.
In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises.
It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place.
When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines.
Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today.
Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business.
> Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty. It seems you think “fuck the human cost as long as I’m making money”. I’d suggest changing your outlook on life if I didn’t feel like it wasn’t such a lost cause.
This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on.
Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again.
It isn’t, it is how some people approach business. Not all.
Again, in my opinion this is just cynical and constantly - almost psychopathically - propagated here as though it’s some kind of virtue of business or the only way a business can be ‘pure’ and succeed.
It just isn’t.
And, if you want to sell B2B, you have to sort out your compliance, or you’re gonna sell nothing. So, for a very large number of businesses, this levelling up is non-negotiable if you want to succeed.
augment_me · · focus · HN ↗
Minimizes money usage and does not require any security investments
louthy · · focus · HN ↗
AIiscoming · · focus · HN ↗
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
louthy · · focus · HN ↗
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
augment_me · · focus · HN ↗
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
louthy · · focus · HN ↗
One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
augment_me · · focus · HN ↗
If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) {
Roll your own security solution
} Else {
Outsource to 3rd party
}
louthy · · focus · HN ↗
In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises.
It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place.
When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines.
Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today.
Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business.
nik282000 · · focus · HN ↗
This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on.
Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again.
louthy · · focus · HN ↗
It isn’t, it is how some people approach business. Not all.
Again, in my opinion this is just cynical and constantly - almost psychopathically - propagated here as though it’s some kind of virtue of business or the only way a business can be ‘pure’ and succeed.
It just isn’t.
And, if you want to sell B2B, you have to sort out your compliance, or you’re gonna sell nothing. So, for a very large number of businesses, this levelling up is non-negotiable if you want to succeed.