SEC's new data breach disclosure rules take effect, here's what you need to know
techcrunch.com
techcrunch.com
"I believe that someone currently has access to our customer database"
- "It's probably nothing. Carry on with your regular work. Nothing to see here."
Luckily for consumers, the do nothing approach to this problem is more costly than disclosing.
https://techcrunch.com/2023/12/18/why-extortion-is-the-new-r...
How would receiving an encrypted email detailing a vulnerability of your flagship product fit with the 96 hours, given that 90 days are often needed to fix said vulnerability (s) before informing the public?
In short, wouldn't that company's vulnerability make for excellent zero-days while they are trying to repair and retest the problematic product?
first line. It's going to a speicif org, not russian hackers in siberia.
I agree, that better be one damn secure batphone they're using.
Sources:
https://last10k.com/sec-filings/vfc/0000950123-23-011228.htm
https://www.sec.gov/Archives/edgar/data/103379/0000950123230...
https://www.reuters.com/business/retail-consumer/vans-owner-...