On GameFAQs: What causes the Red Ring of Death?
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 17:
Next »
It's all a matter of money
Until it costs a business more to fix breaches than it does their security, nothing will happen.

The way most businesses look at this is simple: it costs me a little bad PR (Public Relations) if we have a break-in. I can sweep it under the rug and let the consumers deal with the aftermath. If I fix my systems and business processes, this costs me real money and time. And it would cost a little bad PR because it would admit my systems weren't secure in the first place. So let's see: both have bad PR but one costs me significantly more than the other. Gee, that's a simple decision.

So let's turn the tables and try this one out. If you have a security breach, you are responsible for cleaning up the mess. That means:

* You must pay for any fradulent charges
* You must pay for the reissue of credit/debit cards
* You must pay a fine to each consumer to compensate them for their time in fixing their credit
* You must pay a fine to the government for each account compromised
* If you have a security breach, you don't report it, and we subsequently find out, you go to jail. No, no, not your company, you Mr./Ms. CEO, you personally go to jail because you're an idiot and couldn't manage your business.

We could argue individual items but here's the point: under this scenario, it is much more expensive and risky to have a security breach than not to. Since it is less expensive to be secure than not, guess what path business who traffic in personal data will do?
Posted by: bitflippper1   Posted on: 03/29/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

It's all a matter of money  bitflippper1 | 03/29/06
How soon do we get our congress people on the same page?  ordaj@... | 03/29/06
Behind the times  RU_Trustified | 03/29/06
Congress wants to protect Corp interest not...  redstone | 03/29/06
If we are very lucky  ebrke | 03/29/06
Naw, it'll be just like Social Security  bitflippper1 | 03/29/06
Okay, what are you going to do about it?  Chad_z | 03/29/06
Return some lawmaking back to the people...  redstone | 03/29/06
Re: Okay, what are you going to do about it?  none none | 03/29/06
The system is flawed when the vendor is trusted with this kind of data.  enduser_z | 03/29/06
Where do I get a stolen credit card  BXLE | 03/29/06
Don't trust Capital One  gordon@... | 03/29/06
Simple answer  cubbage@... | 03/29/06
but it's not so simple  dmhunter@... | 03/30/06
Been to a restaurant?  TonyMcS | 03/29/06
Most breakins are for the bandwidth  GreatInca | 03/30/06
GOOD  QQQQQQQQ1 | 04/17/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here
advertisement

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline