top | item 45526580

(no title)

atbvu | 4 months ago

Every time I see a data breach caused by a third party vendor, I can't help but wonder why are these big companies so deeply reliant on outsourcing, yet so lax when it comes to controlling security?

discuss

order

theknarf|4 months ago

Usually some regulation change that the company is not aware off, they have to run to find a fix as soon as possible, some business guy who don't know anything about tech find a vendor who are ready to sell a solution (they probably created their whole business last month on a gamble that the new regulation would be passed and that businesses would be rushing for a solution). Then they simply buy that solution "for compliance" as a top down decision, even when internal employees ring the warning bell.

kevincox|4 months ago

Because the consequences of events like this are minimal so why would they waste time and effort worrying about it?

atbvu|4 months ago

I don't think incidents like this are minor. I believe personal information security is very important. Maybe they see the consequences as small, but I don't.