Remix.run Logo
toomuchtodo a day ago

Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky.

To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.

(cyber consultant and practitioner)

my-huge-pony a day ago | parent | next [-]

Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached?

I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.

augment_me a day ago | parent | next [-]

This is already the law, but the shell company signs the ownership of the data and the security responsility. The university in this case is just using APIs to load and store stuff to someone else's servers.

If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.

SoftTalker a day ago | parent | prev [-]

Insurance only pays for damages, up to the limit of coverage. It does not do anything to remove liability.

x3n0ph3n3 a day ago | parent | prev [-]

That's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable.

toomuchtodo a day ago | parent [-]

You can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s).

I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.

TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.

bluGill a day ago | parent [-]

There is a lot more than regulations. Reputation is important as well. While you can give up a reputation fairly quickly, it is very hard to get/keep. Many companies are well aware of the value of their reputation - they call it the value of the brand.