Another #sony hack brings back funny memories, like the time their #CISO did an interview and speaking tour bragging about doing the minimum possible on security as a business benefit. When security auditors delivered lists of fundamental problems that threatened Sarbanes Oxley compliance, he negotiated the list down to save money on fixes. #geniusmove

Sony famously suffered 190+ breaches in 10 months during his tenure. Not sure if he's still there or not.

https://www.cio.com/article/272225/risk-management-your-guide-to-good-enough-compliance.html

Your Guide To Good-Enough Compliance

Decisions about complying with Sarbanes-Oxley, HIPAA and other rules is often an exercise in risk management and negotiation.

CIO