Remix.run Logo
jm4 3 days ago

This is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.

tocs3 3 days ago | parent | next [-]

Holding actual people liable sounds like a more effective option. The insurance would just be included into the cost of doing business and make everything more expensive. Insurance makes everything worse.

Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.

p_l 3 days ago | parent | next [-]

In EU, NIS2 regulations already hold top management personally liable both financially and in worst case criminally.

Does wonders for how c-level treats compliance work, now if only middle management followed...

jen20 3 days ago | parent [-]

Sarbanes-Oxley in the US holds top management personally responsible too, and compliance is taken far more seriously than with other regulations as a result.

jimbokun 3 days ago | parent | prev | next [-]

If you think there is never a valid use for insurance policies I can’t take you seriously.

watwut 3 days ago | parent | next [-]

Sure, when you want payout. This is not about payout, but about us not wanting it to happen again.

tocs3 3 days ago | parent | prev [-]

Sure there are valid uses for insurance. It is just the incentives are all wrong for the insurance companies.

jimbokun 3 days ago | parent [-]

The incentives are to price risk correctly so that they can price their policies cheap enough to beat the competition while not going out of business from paying more in claims than they receive in premiums.

What do you think their incentives should be?

tocs3 2 days ago | parent [-]

There is a cap to how much and insurance company can make (health insurance for instance are capped at 20% of premiums). To make more money next year they can sign up more policy holders or make sure costs go up. Companies also often have a large stake in the fix it shops/clinics/hospitals so they recoup much of their cost that way. Market capture, if it cost more to buy insurance than to fix it/absorb the cost without insurance why would you buy insurance. It is useful for the insurance companies to see costs increase.

Sure there can be good arguments for having insurance. Insurance companies are part of the financial sector and will be working to make more money. That is a fine incentive for the insurance industry but for the insurance consumer it is a reason to be skeptical and careful.

jm4 3 days ago | parent | prev [-]

Are we talking hypothetical utopia or something that could actually happen? Insurance probably isn’t the most perfect solution but it’s the most feasible. These exact policies and insurers already exist.

And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.

I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.

bluefirebrand 3 days ago | parent | next [-]

> And why the hell would anyone want a job where a mistake results in personal ruin

We are talking about the sort of job where you are paid ludicrous amounts of money. The sort of jobs that usually come with massive golden parachutes

People earning more money in a year than most people earn their whole lives should be accepting a much higher burden of risk

shimman 3 days ago | parent [-]

Very true. If you don't want to be exposed to such rich, you're free to work elsewhere. No one is forcing you to take on these jobs that immiserate society.

collingreen 3 days ago | parent | prev | next [-]

"A mistake" is a far cry from criminal negligence and we shouldn't conflate them.

Suzuran 2 days ago | parent | prev | next [-]

>why the hell would anyone want a job where a mistake results in personal ruin?

I guess you think pilots, doctors, air traffic controllers, etc. are all made up?

curt15 3 days ago | parent | prev [-]

> And why the hell would anyone want a job where a mistake results in personal ruin?

People will do nearly anything if the price is right.

solidsnack9000 3 days ago | parent | next [-]

The most reckless will, of course; but most people won't -- they just won't do it.

Corporations evolved the liability structure they have today so that large undertakings, where many people have to work together and where the bad deeds of a small number of those people could sink the undertaking, were something that regular -- people who can't self insure -- could be a part of, as investors, managers, staff, &c, &c.

Limited liability may make accountability too narrow; but blanket personal liability makes it far too broad. It's not a solution for running a large, complex economy in a more accountable way.

bigbuppo 3 days ago | parent [-]

And 70 years ago I would agree with you, but now we have a handful of individuals who are the economy with wealth that's rivaling nations. Something has gone awry.

solidsnack9000 2 days ago | parent [-]

What does that have to with assigning liability to managers as proposed?

It seems like the handful of people you're talking about are totally different people.

Ajedi32 3 days ago | parent | prev [-]

Yes, there are some people who thrive on risk and will do things like jump off a mountain in a wing suit just for the thrill of it. That doesn't mean making that sort of personal recklessness legally mandatory for employment is a good idea.

This sort of personal liability OP is proposing would just ensure the security industry is dominated by highly compensated compulsive gamblers because nobody else is insane enough to take the risk. It's an absolutely ridiculous idea.

atoav 3 days ago | parent | prev | next [-]

This is data that will be relevant for every single victim for decades to come and they will pay for this regularly, and it cannot be undone.

What amount per person is acceptable for a thing that simply should never happen?

I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).

We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.

8note 3 days ago | parent | prev | next [-]

if you hold people liable, then they will want liability insurance.

what's the point of liability insurance if youll never be held liable?

AngryData 3 days ago | parent | prev | next [-]

Could we not keep the same "harsh" plan, and then let others provide and purchase such insurance on their own? Why does the insurance have to be mandated?

petcat 3 days ago | parent [-]

Because the company will file bankruptcy and nobody will get anything. Requiring insurance up front at least provides some coverage for liabilities.

It's why you can't legally drive without insurance. It's not for you or your car, nobody cares about that. It's for the other people and their property.

watwut 3 days ago | parent [-]

Driving badly or dangerously gets you in prison. Insurance is not there to ensure road safety. Road safety is enforced by punishments.

petcat 3 days ago | parent | next [-]

Nobody is talking about criminal wreckless driving.

We're talking about assurances that you're going to be able to cover damages if you rear-end a sedan and cause $8,000 in repairs. That's why you're required to drive with insurance coverage.

tedd4u 2 days ago | parent | prev [-]

I would draw the comparison to malpractice insurance for doctors. Gun owners should be required to buy something like it. And police departments.

dylan604 3 days ago | parent | prev [-]

Who receives the payouts of those insurance benefits and how would one go about making a claim?

jm4 3 days ago | parent [-]

The company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy.

What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.

toss1 3 days ago | parent [-]

And when the hacked information is used to cause a national-level disaster, the costs of which are greater than the assets of the insurer, and their re-insurance funds, bankrupting them, what then?

Insurance is not a solution for everything.

More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.

It is really simple:

If they can not handle properly the risks of their business, they should be in another business.

jimbokun 3 days ago | parent | next [-]

In that kind of situation you are just fucked regardless.

jm4 3 days ago | parent | prev [-]

Ok. How do you propose they prove they can handle the risks? Who is responsible for determining that and what are their qualifications?

whatisthiseven 3 days ago | parent | next [-]

That's the secret: no one can.

Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.

Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.

Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.

collingreen 3 days ago | parent [-]

Seriously this

We need people to stop internalizing that the government and the rich somehow deserve access to private data just because they want to use it. Seeing a way to make money using enough to make you entitled to it.

Force businesses to add value if they want to exist instead of extraction or rent seeking.

toss1 3 days ago | parent | prev | next [-]

Reality and certainty of consequences, not evasion and insuring of liability

I specified it in the last sentence: >>If they can not handle properly the risks of their business, they should be in another business.

The same way it is handled in any other business or trade with risk.

Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.

If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.

Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.

It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.

Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.

lazyasciiart 3 days ago | parent | prev [-]

They are, by deciding if they are able to handle having their lives certainly ruined if they screw up. The trick to punishment as deterrence to planned actions is 100% identification and enforcement, so that people will avoid the behavior to avoid the punishment. Anything less and some people will decide the potential payoff of success is worth it.