Blowing the whistle
No, Panera Bread Doesn’t Take Security Seriously is a heartfelt piece by Dylan Houlihan regarding a company that was notified responsibly of a privacy breach but apparently failed to act until, some 8 months later, it was informed by Brian Krebs. Then, all of a sudden, it reacted. This is far from the first time a genuine, well-meaning whistleblower has been callously rebuffed or studiously ignored. Organizations clearly need strategies, policies and procedures for receiving and dealing with incident notifications and warnings of all sorts. Doing so makes sense for several good reasons: Business reasons e.g . hacking, fraud, privacy breaches and other inappropriate disclosures; Compliance reasons e.g . PCI-DSS and [soon] GDPR; Ethical/social reasons e.g . offensive/inappropriate behavior or bribery & corruption by workers, failure to uphold corporate social responsibilities; Bringing those responsible for various issues to account. So why don't they? Lame excuses inclu...