Where do I admit this? About fines? Yes, fines don't work.
The difference with my proposal is that companies wouldn't lose a few days' worth of revenue to a fine, they would lose 100% of revenue. That goes from being a "cost of doing business" to an existential threat.
> Not to be rude to the author, but it sort of seems like they forgot that not all software is developed in the US.
I didn't forget. In fact, it's because of worldwide things that I keep pushing this here in the US. The EU already passed the Cybersecurity Resilience Act [1].
Sure, we may not have things apply globally, but we don't need agreement on the punishments globally. We just need agreement on the certification globally.
We have done global agreements before. ICANN, International Telecommunications Union, etc. ICANN is interesting because it started as US-only and expanded.