You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
The bar is: do you have effective compliance in place? And are you audited? (ISO27001 [1] or similar).
If you are hacked and you are seen to have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.
However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.
You may still get a fine, but it would be much reduced.
It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.
It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.
augment_me · · focus · HN ↗
Minimizes money usage and does not require any security investments
louthy · · focus · HN ↗
AIiscoming · · focus · HN ↗
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
louthy · · focus · HN ↗
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
someguynamedq · · focus · HN ↗
louthy · · focus · HN ↗
If you are hacked and you are seen to have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.
However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.
You may still get a fine, but it would be much reduced.
It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.
It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.
[1] <a href="https://www.iso.org/standard/27001" rel="nofollow">https://www.iso.org/standard/27001