Hacker News new | ask | show | jobs
by deadmetheny 3211 days ago
>Preferably with their jobs

That's not nearly enough, considering the reach and impact this could potentially have. These people need to be getting life prison sentences before security is finally taken seriously enough by executives.

1 comments

It's high time we had an equivalent law to Sarbanes-Oxley for security.

S-O made sure that when a C-level type guy signs a report, he knows his ass is on the line in case an illegal transaction just occur under his nose. If your company deals with PII, I want that data to be treated as important, if not more important, then company's funds. If you lose it, and you had any say in security (or lack thereof), you should do time.