You should worry about lightning strikes and like solar flares disrupting your business before you worry about cyber security. Why should any enterprise risk manager waste their time on an issue that has no consequences?
You should worry about lightning strikes and like solar flares disrupting your business before you worry about cyber security. Why should any enterprise risk manager waste their time on an issue that has no consequences?
July 1st, 2019
H.R. 3151
"Taxpayer First Act
This bill revises provisions relating to the Internal Revenue Service (IRS), its customer service, enforcement procedures, cybersecurity and identity protection, management of information technology, and use of electronic systems."
https://www.congress.gov/bill/116th-congress/house-bill/3151...
Just because actual legislation is too boring for cable news and NPR doesn't mean it's not happening.
You can find all the bills that passed into law here: https://www.congress.gov/advanced-search/legislation?congres...
PS: Believe the 9/11 first responders bill would be more recent, but I figured people would take issue with that as a celebrity bill.
At least the 9/11 first responders bill was about allocating resources to do something, but the main reason it doesn’t serve your point is the fact it stood for 18 years as an example of our government’s incompetence and inability to do basic, non controversial things.
Reducing everything to "creates a new department or abolishes an existing one" or "does nothing and just keeps the lights on" isn't a useful rubric.
Good law is acreted over time, in the same way bulletproof code is.
US tax law has been dysfunctional and getting worse for decades, to me that says there are issues with how the system is designed and meaningful progress beyond “keeping the lights on” will require restructuring the law and the agency, not adding a new office here and giving taxpayers more notifications there. Those types of measures, as you correctly point out, have to be looked at as part of a larger plan for the organization that meaningfully addresses a problem, not in isolation. Except here we have a collection of measures that doesn’t coherently address a problem, so there is no way left to look at them except in isolation.
The law has many stated goals, as set forth in the quote I posted.
Let's take freedom of speech. One side believes it's unlimited, and the other doesn't. How do you compromise on that? You can't. How do you solve that problem? You don't, it's not the government's job to solve all of society's problems. That's the point most people don't understand: quit trying to control the behavior of others.
Why is your assumption that the social conservatives are the ones that have to compromise? Shouldn't both sides be compromising?
Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and banks still need the credit score and there aren't much competition in that sector.
I think I'm just more angry about these "too big to fail" companies that are apparently immune from any oversight or consequence today. We should really just convert the FTC building into a homeless shelter and fire all employees, they have done absolutely nothing for decades so this would be great way to actually use the space effectively.
In a small market with few potential customers, reputation loss could kill you. OTOH if you sell to general population, then even a scandal involving you being featured on national TV won't hurt your company directly (related lawsuits might, though).
They're absolutely not too big to fail. Equifax or FB? Other than the unfortunate employees and their families, does anyone give a shit? No. No one suffers. To the contrary, thinning sick herd members helpfully invigorates the health of the surviving individuals.
What these organization are are in too many pockets to be too big to jail. It's a trope but it's a fact, Jack
Edits for herd reference and reduced snark
And yeah, ditto Equifax. There are two other credit agencies already. They're all same-ish as far as I can tell. Pretty sure there are only three so they can pretend there's competition, not for any actual purpose. Again, it might be an opening for a new competitor anyway, while causing minimal short-term harm.
Yeah, i fully agree...But, what about orgs like equifax where you and I are not really given a choice about their role in our lives? Even before all the shenanigans around equifax, would i have willingly allowed equifax into my life? Heck no! So, while i 100% agree that we should vote with our wallets/purses, sometimes that isn't enough...and that makes me a sad panda. </sigh>
100m people losing a minute of their life to handling this (lets call it nanodeath) is 190 continuous years of wasted time that you could have spent with your family, napping, reading or other pleasurable life things.
That’s the kind of math that, say, an insurer, should do to determine whether an intervention should be paid for.
But usually you just get called a monster for doing that kind of math.
For Capital One, or other companies with which we directly do business, I think there's likely to be more direct ramifications - namely people refusing to do business with them. Letting anyone access your customers' data is a good way to lose those customers.