Bad news for smaller players.
Bad news for smaller players.
This is simply what professional security assessment costs. There's a lot of competition and a diversity of firms, and this is the range the rates float in.
It doesn't make sense that small companies should be allowed to circumvent the requirement when what they're doing is just as sensitive as apps from large companies.
* professional security is needed, and this is what it costs
* the cost is more of a barrier to smaller companies (and hence provides an advantage to larger companies)
It seems like an inherent tension; I'm not sure how to get around it.
We talk about two different data sets here: * The actual User data. * Data from third persons, including, but not limited to their e-mail address.
While a user can agree that their own data should be processed by a third party, the problem is that he cannot consent for other people.
And in my understanding (INAL), every part of the software where those third person information is transferred or processed needs to be part of that full assessment.
A limited API that does not give out any third persons data would have to somehow filter out all the information of all third partys.
If they really are small companies then (in most cases) what they're doing isn't as sensitive, because the value of the assets under protection is lower. It would be completely reasonable to say that companies with less than 5,000 users only need to be assessed for vulnerability to automated attacks and not targeted attacks.
If you're a company the size of Facebook and you're accidentally sending password reset tokens to your analytics partners then that's a disaster. But I don't know that it's worth shutting down hundreds of startups with a couple dozen users each over the sort of potential security weaknesses that, while not ideal, realistically aren't going to result in anyone having their private data exposed.
Where I disagree is that for a small company that doesn't use SQL, being forced to pay someone $10,000 to spend an extra week testing every single endpoint for SQL injections isn't going to mitigate any potential vulnerabilities, nor would being allowed to opt out of that requirement externalize any risk.
And if we're going going to say that companies shouldn't be allowed to externalize risk then that requires some baseline understanding of what risk actually is. And at the end of the day, it's impossible to separate risk from the value of the assets under protection, as Bruce Schneier has been saying for 20+ years.