‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. louthy · · focus · HN ↗
      Or … and hear me out on this one … care?
      1. novok · · focus · HN ↗
        How much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard?

        Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.

        1. asp_hornet · · focus · HN ↗
          > to have leaked the personal data of 10 million or more people through intent or gross negligence

          But to your point, the article doesn’t define what that means.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.