← Back to context

Comment by IAmBroom

4 hours ago

The number of breaches would have to be honestly reported for that idea to work. None of the security firms would want to do that; least of all the lowest quartile of them.

> would have to be honestly reported for that idea to work.

and why does this idea work for accounting audits, but not for security? As long as regulations for companies exist, they would necessarily follow it, and this would lead to reporting of security breaches just like companies would have to report their financials honestly.

  • Accounting is generally both easier to do correctly and easier to verify than security practices, unfortunately