Remix.run Logo
jm4 3 days ago

The company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy.

What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.

toss1 3 days ago | parent [-]

And when the hacked information is used to cause a national-level disaster, the costs of which are greater than the assets of the insurer, and their re-insurance funds, bankrupting them, what then?

Insurance is not a solution for everything.

More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.

It is really simple:

If they can not handle properly the risks of their business, they should be in another business.

jimbokun 3 days ago | parent | next [-]

In that kind of situation you are just fucked regardless.

jm4 3 days ago | parent | prev [-]

Ok. How do you propose they prove they can handle the risks? Who is responsible for determining that and what are their qualifications?

whatisthiseven 3 days ago | parent | next [-]

That's the secret: no one can.

Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.

Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.

Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.

collingreen 3 days ago | parent [-]

Seriously this

We need people to stop internalizing that the government and the rich somehow deserve access to private data just because they want to use it. Seeing a way to make money using enough to make you entitled to it.

Force businesses to add value if they want to exist instead of extraction or rent seeking.

toss1 3 days ago | parent | prev | next [-]

Reality and certainty of consequences, not evasion and insuring of liability

I specified it in the last sentence: >>If they can not handle properly the risks of their business, they should be in another business.

The same way it is handled in any other business or trade with risk.

Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.

If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.

Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.

It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.

Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.

lazyasciiart 3 days ago | parent | prev [-]

They are, by deciding if they are able to handle having their lives certainly ruined if they screw up. The trick to punishment as deterrence to planned actions is 100% identification and enforcement, so that people will avoid the behavior to avoid the punishment. Anything less and some people will decide the potential payoff of success is worth it.