| ▲ | BrenBarn 13 hours ago | |
> It's fine + obligation to fix, and daily fine until fixed, and higher fine if you do it again. The important proviso is that the penalties need to (on some non-geological timescale) get high enough that the offender is no longer capable of operating. That could mean the fines reach $500 billion, or it could mean the company is barred from operating in the EU, or it could mean people get arrested and assets are seized. But unless the penalties become crippling, it won't matter. It needs to reach a point where the downsides of noncompliance are actually greater than the benefits. | ||
| ▲ | esterna 11 hours ago | parent | next [-] | |
NIS2 allows for the arrest of managers in case of cybersecurity incidents resulting from negligence. I think it's a step in the right direction, but we'll have to see how it plays out. | ||
| ▲ | nolok 13 hours ago | parent | prev [-] | |
In the EU they like the "daily fine until fixed". It's how Microsoft bowed down. But unlike the story some on HN and in the US like to think, US tech companies don't ever get there except rare exception, they know the game. | ||