Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked
Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much.
Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively?
What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault? Maybe they thought it was good but were simply wrong?
I think a more fundamental approach would be to set mandatory qualifications for IT workers/devs to ensure a base-level of security/understanding. I know great web devs who don't know about web app security - that shouldn't be possible. It wouldn't be perfect but it would be easier to do refreshers/regular testing for things that people should already have learned, just like train drivers do.
The same is true of legislation like SOX, which is very much a checkbox approach and has not solved everything related to financial reporting, by a longshot. But that doesn't mean regulation would be totally useless. From the article:
>The European Union has been operating under such a standard since May 2018. Known as the General Data Protection Regulation, the law requires companies to implement security measures to protect sensitive personal data and to promptly notify regulators and affected consumers when it gets compromised. Violations of the data protection rules can result in fines as high as 4% of a business’s annual worldwide sales. “You have to implement cybersecurity measures if you process personal data, and if you do not, you will have a legal problem,” said Stefan Hessel, a cybersecurity specialist in Germany at the Reuschlaw law firm.
>Such measures may in fact make it harder for hackers to ply their trade, if Pompompurin’s postings are any indication. In August he was asked on RaidForums why large collections of personal data always seem to come from the U.S. He responded: “Because its the easiest to get, other countries have load of protection laws & shit, in the US your address is basically public information no matter how hard you try not to be put on lists like this.”
>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much.
So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't.
Of course if congress would apply HIPAA rules to everyone's data and actually enforce it, data leaks for the most part will stop.
Fines don't happen until they get caught. How long can a company go and how much can they make before they get caught? What happens to the executives? They just move on pointing to their old success numbers.
I run internal audits for a large org as part of a strike team when my company is acquiring smaller orgs. External auditors are a joke and it's incredibly easy to slip things by them. The only reason we catch stuff is because we assume full ownership as part of our takeover process and actually build and deploy product to find issues.
But your company wouldn't even have a line item to look for those problems if regulations didn't require it. It's not a fool-proof solution but it's at least a foot in the door for improvement
There's also a criminal liability aspect to it. I've worked for healthcare companies too and they do care, at least enough to have it in the conversation and to include the HIPAA officer in those conversations. Nowhere I have worked have they been flippant about it.
I agree with you that the cap is too low. It should cap based on gross or revenue. I suspect it's so that the smaller companies won't get destroyed by fines leaving the larger ones largely unaffected, but I'm speculating.
It also doesn't help that these frameworks are often dated and don't align with modern best practices. Shops have the choice to check the boxes and do things the dumb way or to fill out page after page after page of special exception documentation for their auditors. Most take the easy way.
And that doesn't even cover the part where PCI, SOCII, and SOX all have various bits that contradict or are not compatible with each other.
I've seen too many times where the head of security or IT or whatever picks a pre-made package off a shelf from one of the audit providers where they guarantee you will pass all of them. Then they follow it like it's law ultimately leading the swe/devop/sre groups to build out layers of shadow it/ops to actually get productive work done.
My work primarily is to jump into startups after they are acquired to make them "enterprise ready" for a bigger org and its always a unique shit show dealing with the preexisting war between their security/it orgs and their actual product development orgs.
I think just enough components of the problem are too abstract for most people to practically reason about.
HIPAA passed when people expected Clinton to push for health insurance improvements. The HITECH accompaniment passed in 2009 when health care was a huge issue in the wake of the 2008 disaster, and people expected the govt to crack down on big company malfeasance. Subjectively, I think 'keeping your health information secret because it should be secret' seems more viscerally compelling. SOX passed in the wake of Enron and WorldCom during the .com bust. The EU, broadly, seems less regulation averse than the US, but I'm no expert. That the US hasn't followed suit, despite the current backlash against social media and data tracking in general, is telling.
Most folks think someone getting ahold of their CC# is the worst-case scenario and they or someone they know has probably experienced it. It was probably resolved with a 5-minute phone call, and they probably blamed the last in-person retail transaction they executed before the fraudulent charges rather than some online company they bought a potholder from 18 months prior. They likely don't even consider the implications of someone using their SSN to open a mortgage, lease a boat, claim unemployment benefits, or work a year claiming total tax exemption on their W4.
Even many people who understand the privacy implications might not understand how frequently breaches happen, the practical steps to mitigate them, and whether they're proportional to the risk. Few could factually evaluate the inevitable industry FUD. I think it'd get way more pushback than the right to repair did in Massachusetts, and industry flung some pretty outrageous fear-mongering BS over that one— they implied non-proprietary car computer interfaces would result in women being stalked and raped. In a television commercial.
I think it's doable and very important that we do, but I completely understand why there hasn't been any popular grassroots uprising about it.
Politicians will say it’s the companies responsibility, and you should talk to them. Companies will say that they follow all data protection laws and that policy discussions should be up to the government.