QOTD - Pescatore on Lawsuits & Executives

There is always a hope in security circles that threats such as class action lawsuits or 'downstream liability' will cause a light bulb to go off in boards of directors' heads and they will say 'Aha - information security is important, increase the budget, promote the CISO!!' In reality, when boards hear 'liability' they tend to mostly make sure that the corporate Directors and Officers Liability insurance coverage is sufficient. The actual business damage of incidents is usually the bigger driver for action by boards of directors. -- John Pescatore, Vice President at Gartner Inc., writing about Aetna being named in a class action data breach lawsuit.
Src: SANS Institute - SANS NewsBites Vol 11 Num 46

