‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. amelius · · focus · HN ↗
      That's like blaming Seagate when your harddisk fails.

      No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

      1. augment_me · · focus · HN ↗
        Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.

        Seagate will not in a million years sign anything like this when you buy a HDD.

        1. xboxnolifes · · focus · HN ↗
          You can't just absolve yourself of responsibility by saying "I hired a contractor". You are still responsible for doing your due diligence in picking your contractor.
          1. someguynamedq · · focus · HN ↗
            Correction, you "shouldn't be able to." Currently you can, actually
            1. [deleted] · · focus · HN ↗

              [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.