As predicted, congress is stirring the pot around additional oversight relative to breach disclosures. This time, the plan is to ask the SEC to get involved and require firms to give details about breach disclosure risk. An interesting idea.
Their supposition is that firms aren’t really doing anything about IT risk. A supposition that is correct, by the way. As a person in the business of providing risk-based support to companies, I’m all about making the services I provide mandatory across the board (how sweet would that be?) But realistically, I think they’re missing a piece of the puzzle.
Namely, their premise seems to be that increased… Continue reading: Risk of breaches: Congress asks SEC to intervene

