Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty.
In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises.
It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place.
When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines.
Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today.
Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business.
> Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty. It seems you think “fuck the human cost as long as I’m making money”. I’d suggest changing your outlook on life if I didn’t feel like it wasn’t such a lost cause.
This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on.
Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again.
The person you're replying to is citing the incentives that are created. That's not cynicism, it's analyzing motives to help model outcomes.
As for the buck stopping with the executives: can you apply this to a case I've heard of? We have multiple data breaches of companies that scan IDs. We have the Experian breach. We have multiple LastPass breaches. Is there any executive at any of these companies that has been held accountable?
I've actually done the legwork on the ones I just mentioned and the answer is there have been no criminal or civil penalties to any individual in an executive role at any of those companies as a result of the data breaches. Maybe I'm missing one?