• INeedMana@lemmy.world
    link
    fedilink
    English
    arrow-up
    33
    ·
    1 month ago

    When a building needs maintenance bad enough that it doesn’t pass a set of regulations, it will get closed until fixed. Maybe we need something like that for IT infrastructure

    • roofuskit@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 month ago

      The insurance industry is filling in this gap right now for cyber insurance. They are requiring a certain level of security before they will write a policy. Try doing business with any other company without a huge cyber insurance requirement in the contract.

    • Xaphanos@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 month ago

      It already works like this. Audits perform this function. Failing a mandatory audit generally goes very poorly for financial companies. The unintended result is falsified audits - something my former company did (still does?) every year. The banks and the Fed never found out.