Comment by worik
3 days ago
People understand cars. Abstract data structures, not so much.
There are laws about what goes into a car, strict regulation. Software, not so much.
Until my boss can be prosecuted for selling untested bug ridden bad software that is what I am instructed to produce
With the introduction of insurance for covering the cost of a security breach, suddenly managers have an understanding of the value of at least the security aspect of software quality. As it impacts their premiums.
I really hope so. But I do not have much faith in insurance companies. I have seen what they have done to worker safety, made it a minefield for workers, a box ticking exercise for bosses, and done very little for worker safety.
What works for worker safety is regulation. I am afraid the same will be true for software.
The regulations are the reason the insurance policies exist. Otherwise, corporations would just ignore or cover up any breaches.