You can outsource work, you can't outsource responsibility. It will likely be a long time before the various powers that be really get this.

Isn't monetary liability a form of "outsourced responsibility"? I'm not understanding why damages from lawsuits are not sufficiently motivating the industry to take data breaches seriously. Maybe they just aren't awarding enough damages to change behavior?

Think liability insurance, by the same companies who charge you healthcare. We are spreading the cost of irresponsible folks across society then bailing out the companies who make those choices.

