Hacker News new | ask | show | jobs
by cipherzero 2065 days ago
Slightly off topic, are fines even the right approach to get better behavior? What incentive structure does they encourage?

I fear it encourages you to hide or down play an incident, if possible, when issues do happen. Instead you’d rather want to encourage transparency and some way to prove you’re following good practices and have a good track record. Maybe some incentives like car insurance companies claim to follow: better driving record, reduced insurance costs. (Not that I think car insurance is a successful/good example.)

Failure cases (like data breaches and ransomware attacks) are certainly easier to measure though, so maybe this is the best we can hope for...

1 comments

They should put them into special measures like a failing school. And BA should be forced (at their own expense) to have regular detailed audits of their information security which are published and scrutinised by the ICO. Maybe for at least two years. Of course one would need to find competent and able auditors and ICO employees to fulfil this.