logoalt Hacker News

twothreeonetoday at 7:25 PM1 replyview on HN

I think it's similar with other liability issues, e.g., when a company happens to "lose" customer data through a breach. They will be on the hook for not having certain audits and certifications at regular intervals. Practically never will anyone be feeling any pain due to absolute disregard for basic common sense precautions to prevent issues in the first place. So usually, the pattern is that issues that can be outsourced to insurance will be handled by compliance departments - which don't care about the actual problems, just that the fallout from them is "managed" accordingly.


Replies

giantg2today at 7:45 PM

That's actually a little funny. I work in compliance and we regularly work with the teams to improve processes that enhance security. I will say though, that the outsourced work that we send to consultants has the same sort of result you describe.