Commentary

Let's Raise The Stakes For Data Loss Culpability

After a year of unbelievable (and in some cases incomprehensible) data loss among corporations both big and small, I propose we adopt a brand-new catchphrase for 2008. To borrow somewhat from culinary personality Emeril Lagasse: It's time to kick the penalties up a notch.

After a year of unbelievable (and in some cases incomprehensible) data loss among corporations both big and small, I propose we adopt a brand-new catchphrase for 2008. To borrow somewhat from culinary personality Emeril Lagasse: It's time to kick the penalties up a notch.Think about it -- what's a few million dollars in fines to a multibillion dollar company? We're talking a pittance here. What if instead, for every lost record, the business was charged a standardized fee? A recent study by the Ponemon Institute determined that every single lost, stolen, or compromised customer record costs about $200. Now let's see -- T.J. Maxx "misplaced" about 45 million customer records. Hmmm.

OK, OK, I'm not really suggesting they pony up a ridiculous, Doctor Evil-esque amount of $9,000,000,000. But how about $50 per record for Fortune 500 companies, with a lesser fine for companies in a smaller tax bracket? Depending on the total number of records lost, the fine wouldn't be enough to cause the business to collapse but would definitely hurt -- enough that security practices would start to be considered more than just an add-on or afterthought.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

What about accountability? Shouldn't someone's head be on the chopping block for these transgressions? Sure, the guy who left his laptop unattended while he hit the airport bathroom will probably lose his job. The guy that sneaked in after hours and intentionally stole the data will get prosecuted. But what about the CEO or the CSO? Shouldn't they be taken to task for failed security measures or lack of policies? Shouldn't one of them be handed a pink slip? Or maybe a little time in prison would make these folks think twice before being so lax with customer data. I'm being too harsh, you say? Some things are just beyond our control? Perhaps you've never heard of gross negligence or breach of duty? Our courtrooms are full of cases where one party's conduct failed to uphold "the legal standard required of a reasonable person in protecting individuals against foreseeably risky, harmful acts of other members of society."

Simple Scenario: If the guy who runs the local deli fails to repair a broken sidewalk, he's held liable by the courts if someone is injured. The owner had a reasonable opportunity to correct the situation and chose not to. The injured party, on the other hand, is not responsible to know that there was a hazard. How is that any different than when a company fails to update its security policies (or neglects to implement any), resulting in the "injury" to thousands, if not millions, of customers' identities? Bottom line, companies are getting off light when it comes to being held accountable for data loss. It's time to take everyone responsible for these incidents to task. Higher penalties, loss of jobs, maybe even the threat of a little white-collar prison time might prompt the management to start caring a little more about the little guy.

What do you think -- do data loss punishments and fines fit the crimes? Or should we be hitting these companies -- and their officers -- harder ... a lot harder?


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links