|
|
|
|
|
by smt88
4091 days ago
|
|
> As a result, should the government require businesses with sensitive data to implement bug bounties? No. They should go further. We should have a law, similar to Sarbanes-Oxley, that forces companies to undergo a security audit every year. Otherwise, we're going to be in an endless cycle, where companies refuse to invest in security, a huge breach occurs, and everyone suffers. The current system does not incentivize investments in security because they hurt the bottom line and have no tangible, immediate value to shareholders. That's a dangerous situation. |
|
I'd rather see some security standards (updated yearly or so) and heavy fines and reimbursements after an hack (not necessarily malicious - proof of concept published by a white hacker would do), if the security was lax. Triple them if the company hid the fact that they had been hacked.