Can't answer to 'Proven' on account of comment depth, but I am not concern trolling. I work as a ML engineer and many of our projects and datasets are sensitive. The company has signed contracts of confidentiality for this data and we are really concerned about where it sits and who gets access to it.
Another major concern is GDPR - can you reliably track and delete data related to a specific person? You got to think about this right from the start to keep the necessary metadata in the tagging pipeline.
A large company may lose more than the value of the impacted business line while a startup is capped at the value of the business line (or rather the cash on hand which is even less). So the maximum loss is much higher in absolute terms for a large company and so they're able to invest more absolute money into security. Plus, philosophically, startups already have such massive risk that another X% due to a potential security breach isn't even worth bothering with versus spending the money on lowering risk in other areas.
Comments
On the opposite, startup has everything to lose. No other business lines
Can't answer to 'Proven' on account of comment depth, but I am not concern trolling. I work as a ML engineer and many of our projects and datasets are sensitive. The company has signed contracts of confidentiality for this data and we are really concerned about where it sits and who gets access to it.
Another major concern is GDPR - can you reliably track and delete data related to a specific person? You got to think about this right from the start to keep the necessary metadata in the tagging pipeline.
A large company may lose more than the value of the impacted business line while a startup is capped at the value of the business line (or rather the cash on hand which is even less). So the maximum loss is much higher in absolute terms for a large company and so they're able to invest more absolute money into security. Plus, philosophically, startups already have such massive risk that another X% due to a potential security breach isn't even worth bothering with versus spending the money on lowering risk in other areas.