We know this doesn't work, and author admits as much.
Where do I admit this? About fines? Yes, fines don't work.
The difference with my proposal is that companies wouldn't lose a few days' worth of revenue to a fine, they would lose 100% of revenue. That goes from being a "cost of doing business" to an existential threat.
Not to be rude to the author, but it sort of seems like they forgot that not all software is developed in the US.
I didn't forget. In fact, it's because of worldwide things that I keep pushing this here in the US. The EU already passed the Cybersecurity Resilience Act [1].
Sure, we may not have things apply globally, but we don't need agreement on the punishments globally. We just need agreement on the certification globally.
We have done global agreements before. ICANN, International Telecommunications Union, etc. ICANN is interesting because it started as US-only and expanded.
Where do I admit this? About fines? Yes, fines don't work.
Yes, about fines. From your post: "Ah, yes, fines for companies are not enough. I agree."
they would lose 100% of revenue.
We can't get the government to enforce this when tens of millions of records are leaked publicly, this absolutely will not happen for failure to report a vulnerability. If you have any idea of how to make it happen, please, lets immediately apply it to breaches and then figure out how to apply it to failure to report vulnerabilities.
We just need agreement on the certification globally.
As far as I am aware, there is no certification (one which is legally required to obtain a job) on the planet that is globally recognized. But I would be happy to be proven wrong here.
but we don't need agreement on the punishments globally.
Which will end up with some countries not willing to charge 100% loss of revenue, causing a mass exodus of companies from any country which does charge 100%, thus making the solution untenable.
ICANN is an interesting example, but it's not a certification. The scale (and thus administration, compliance, etc.) is very different.
Comments
Where do I admit this? About fines? Yes, fines don't work.
The difference with my proposal is that companies wouldn't lose a few days' worth of revenue to a fine, they would lose 100% of revenue. That goes from being a "cost of doing business" to an existential threat.
I didn't forget. In fact, it's because of worldwide things that I keep pushing this here in the US. The EU already passed the Cybersecurity Resilience Act [1].
Sure, we may not have things apply globally, but we don't need agreement on the punishments globally. We just need agreement on the certification globally.
We have done global agreements before. ICANN, International Telecommunications Union, etc. ICANN is interesting because it started as US-only and expanded.
[1]: https://en.wikipedia.org/wiki/Cyber_Resilience_Act
Yes, about fines. From your post: "Ah, yes, fines for companies are not enough. I agree."
We can't get the government to enforce this when tens of millions of records are leaked publicly, this absolutely will not happen for failure to report a vulnerability. If you have any idea of how to make it happen, please, lets immediately apply it to breaches and then figure out how to apply it to failure to report vulnerabilities.
As far as I am aware, there is no certification (one which is legally required to obtain a job) on the planet that is globally recognized. But I would be happy to be proven wrong here.
Which will end up with some countries not willing to charge 100% loss of revenue, causing a mass exodus of companies from any country which does charge 100%, thus making the solution untenable.
ICANN is an interesting example, but it's not a certification. The scale (and thus administration, compliance, etc.) is very different.
To provide some additional context to OP.
In the CRA, there’s (among others):
- reporting of actively exploited vulns or severe incidents to a national cert
- reporting obligation of vulns to the provider of that vulnerable code
- mandatory vulnerability disclosure policy (to receive vuln reports)
- obligation to provide security updates and alert customers when a vuln has become known
We’ll see how well this is all followed, but from a security perspective these are all good ideas.
About the fines, there’s a second option: make them more frequent, so there’s less chance on getting away with (minor) transgressions.
This would require well staffed regulatory bodies. At least for GDPR, I don’t think we have that.