logoalt Hacker News

rpdillonyesterday at 10:30 PM1 replyview on HN

The person you're replying to is citing the incentives that are created. That's not cynicism, it's analyzing motives to help model outcomes.

As for the buck stopping with the executives: can you apply this to a case I've heard of? We have multiple data breaches of companies that scan IDs. We have the Experian breach. We have multiple LastPass breaches. Is there any executive at any of these companies that has been held accountable?

I've actually done the legwork on the ones I just mentioned and the answer is there have been no criminal or civil penalties to any individual in an executive role at any of those companies as a result of the data breaches. Maybe I'm missing one?


Replies

louthyyesterday at 10:51 PM

Maybe I wasn’t clear in my message. But the buck stopping with the executives is when ‘the company’ breaks law. Usually because of gross negligence or corporate manslaughter.

With my last company, managing medical records, I was always conscious that if we didn’t take our responsibility of managing medical data correctly it could lead to the death of one of my customer’s patients; or some other extreme circumstance that the executives could be held liable for.

That was my point about being professional, if you have proper processes in place and audits to prove it, you have protection. And only the most egregious cases would land.

It’s good business to protect yourself from a gross negligence or corporate manslaughter claim. It just so happens that it’s good for your customer too.

Presumably, the reason you don’t hear much about executives in the dock for these crimes is because most professional organisations put these processes in place.

Again, I was just stating that it isn’t just data-breach fines that should encourage executives to professionalise.

show 1 reply