Hacker News new | ask | show | jobs
by StreamBright 2665 days ago
You can regulate by having legislation that has 2 components. One is the law that such companies have to follow best practices. Second, best practices are created and published by a set of companies who have the best record of implementing security correctly, or even having security professionals (and there are many well respected security experts who can do this since they talk about it on their blogs all the time).
1 comments

You can also regulate by having fines or substantial civil damages for breaches, requiring insurance to cover the liability, and letting the insurers figure out what practices are needed to get cheap rates.