* Before Tax Revenue
* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.
* Includes Worldwide Revenue
* Includes companies based in all other Countries.
I would have went for 20%, but if he above applies I wish the US would do the same.
Minimizes money usage and does not require any security investments
It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.
So, there is that.
Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional.
I did it because:
* it’s the right thing to do
* for professional pride
* and so I could sleep at night
And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection by the industry as a whole made it seem like it would be survivable.
I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks.
To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.
(cyber consultant and practitioner)
I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.
TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.
I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.
If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
guess who holds the bag if capacity needs collapse
Sort of like EULA's a lot of the "value" is incredibly theoretical.
No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
Seagate will not in a million years sign anything like this when you buy a HDD.
quickthrowman•43m ago
buellerbueller•39m ago
google234123•38m ago
google234123•39m ago
Retro_Dev•5m ago
Retro_Dev•7m ago
Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.
Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.