Gonzalez Lawyers, Judges Debate Data Breach Costs
Written by Evan SchumanA new filing on Wednesday (March 24) from TJX had the chain refusing to offer the specifics behind its loss claims in an attempt to fight a federal subpoena. Attorneys on both sides raise some legitimate questions about how to fairly calculate the cost of a breach. Is it limited to what is taken or to what the thief attempts to take? Should the loss include what was actually—and successfully—accessed, or should it assume that when a card with a $10,000 limit is taken, a $10,000 loss—regardless of what the thief did—should be recorded? If class-action lawsuits are filed (and they will be filed), should the cost of lawyers and courthouse travel be included? What about payment for additional security? And perhaps a new POS system that includes that better security?
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Leave a Reply
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
