FTC Takes action against Drizly and CEO following security breaches
ftc.gov
ftc.gov
There is no fine, no prosecution, no consequences of any sort. Essentially, they're just asking the executive to "implement an information security program" at any companies they head.
This seems to send the message that there are absolutely no consequences for getting caught hiding an extremely negligent data breach. Was that the FTC's intent?
The FTC can seek monetary relief if this order is violated.
The FTC can do whatever congress authorizes them to do. The supreme court decided that what congress laid out in law required the FTC to file the cease and desist first, and then if that order is violated, then they can peruse further action.
> Recognizing that reality, the Commission’s proposed order will follow Rellas even if he leaves Drizly. Specifically, Rellas will be required to implement an information security program at future companies if he moves to a business collecting consumer information
I'm not aware of any other decree following the CEO to other companies.
That seems less than ideal.
You would need a way to collect breaches by company, and then a way to tie companies to their URLs. Additionally, is solarwinds a Microsoft breach?
If there were a repository of known security breaches, I think the rest could be done manually or fairly easily for a specific list of websites.