These companies are so massively large that they price in the risk of databreaches as a cost of doing business.
Insurance Underwriters pour through corpo infosec documents, and require only the most basic level of protections.
I think instead, a stricter certification standard needs to be created, and all these large companies must pass ANNUAL audits, or simply lose access to government leased spectrum.
It seems that we agree that regulatory enforcement is a great framework through which to make this happen. I think we should regulate both security and data retention far more aggressively, and be willing to destroy companies if they fail to comply. The lack of an existential risk makes it easier for them to maneuver around other solutions
Insurance Underwriters pour through corpo infosec documents, and require only the most basic level of protections.
I think instead, a stricter certification standard needs to be created, and all these large companies must pass ANNUAL audits, or simply lose access to government leased spectrum.