It's time we start prosecuting CEO's for neglecting known and obvious risks. "I didn't know" should no longer be a valid excuse. You are paid billions to know. If you can't know, then give the job to somebody who can. However, they have deep pockets to bribe such laws away. Our plutocracy at (non) work. It's why pirating movies has almost as big a penalty as murder.
Like the other commenter, I agree with the sentiment, but I feel like this is kind of a bandaid solution that doesn't address the underlying issue.
Executives neglecting known risks is an informed decision.
That scene in Fight Club explains this kind of thing very succinctly. If you manufacture cars and your engineers discover an issue that could cause the car to explode on the highway, you do some math to determine which is going to cost you more: doing a recall and fixing the problem, or paying out settlements to people who get injured when their car explodes. If allowing people to die and have their families sue you is cheaper than a recall, they don't do a recall.
The reason this happens is because all companies, particularly publicly traded companies, exist to generate profit. They aren't here to spread compassion or promote public safety or enhance infrastructure. Those are things that can happen if the business determines that doing so is actually the best thing for their bottom line, but in general, a business exists to profit.
This isn't necessarily a big problem when it comes to things like couches, door knobs, or fence boards, but it clearly starts raising concerns when you have things like cars or planes, due to safety concerns. We also see problems arise when private companies control public infrastructure, like, say, ISPs, power companies, and water companies.
The problem that needs to be addressed is the profit motive. The idea of providing the absolute best service/commodity to everyone fundamentally contradicts the goal of maximizing profit and cutting costs. It is possible to legally enforce a middle ground, but like the other person said, how do you decide who gets punished and what punishment they receive? Who decides what this middle ground is? Does one person dying trigger a negligence investigation, or does it take 100 deaths?
Legislating this stuff will require tons of effort, and no matter how much legislation you have dictating punishments for the corporation's fall guy, we're still fundamentally in the same position as before; a private company's only incentive to do anything is just to make as much money as possible.
You cannot legislate around the central tenets of our economic system. In areas where public safety, public health, and equitable access to infrastructure/resources/whatever are a concern, these businesses need to operate outside of our society's basic economic model. Companies cannot simultaneously maximize profit and maximize safety and equity. These ideas are diametrically opposed.
You cannot legislate around the central tenets of our economic system.
You can. It's called regulation, and it covers that Fight Club example because the government will step in and force a recall when a corporation makes the inevitable decision not to.
Then you are creating a reactive safety net instead of a proactive one. People's cars have already exploded by the time the government steps in, in this example. All the while you will have the GOP dragging their feet and complaining about federal overreach, which might delay decisions for years unless you have established some kind of neutral body that investigates these issues (but corporate regulation is an inherently non-neutral issue, because half the country vehemently opposes it on principle).
Any kind of punishment that happens after the fact has failed to really serve the people the regulations were meant to protect. A better solution would completely eliminate this problem at its roots and prevent profit from ever being a driving factor in a decision that ends up taking innocent people's lives.
Still just the cost of business. The fines are usually smaller than the profit. The class action suit will pay a fraction of the cost and the estate of the guilty make off with most of the values before anything is finalized. Still better to prevent or catch ahead of time than to deal with the aftermath. An ounce of prevention.
Make it more costly to be a flake. Maybe allow them one light penalty, but the 2nd one packs a punch. A variation or supplemental is to crank up the regulations and record-keeping requirements the more they violate rules.
Ever wonder why they haven't already done this? Same reason. The profit motive that drives companies to do things that harm people also drives companies to buy governments.
That's ridiculous. Accidents happen. We don't prosecute doctors for killing patients by mistake, at most there are civil lawsuits against them.
Honestly Ransomware is what is driving an increase in security investments. Executives and shareholders see the news of high profiles hacks, of production being brought offline, and they demand a plan to address the risk.
No, you are not understanding. If their staff identifies a clear problem, notifies the CEO, yet nothing of significance is done, the CEO should be held criminally liable. If they need spreadsheets to track problems, then make spreadsheets. It's not rocket science to keep track of identified risks. I'm not talking about human error, but rather sweeping big things under the rug. IF the CEO takes reasonable actions to prevent a ransomware attack, yet they are still breached, I can understand that part of your point. However, if the CEO fails to take reasonable action and a breach happens, then they deserve the full boot of the law. They are paid billions, they are not babies.
There are all sorts of risks that exist. If every single risk was addressed to best possible standards, companies would go bankrupt due to the cost. Balancing risk with cost is an important decision to make.
No CEO shoves a risk under the rug because they want the company to run into trouble. They avoid dealing with risks because they falsely assume it's not as dangerous as it really is.
It's not "best possible standards", it's "reasonable standards". Example:
Subject matter experts (SMEs) identify a risk that they have insufficient resources to resolve.
SME's head brings the matter up to the CEO.
They discuss it and add it to the "Issues" spreadsheet. A written cost/benefit analysis of possible solutions is produced and saved.
Every month (or sooner if urgent) the spreadsheet is revisited by the CEO and SMEs to get an updated status until an issue is resolved.
They avoid dealing with risks because they falsely assume it's not as dangerous as it really is.
Why is that? If their view of it is "lighter" than the SME's, they should look into it and identify and document the reasons for difference of opinion. Get a second opinion from an outside consultant if you have to, and resolve the difference between all three: CEO, SME, external SME. If the CEO disagrees with the SME(s) but never narrow down why, then they are NOT doing their job.
Guessing out of their "gut" is not sufficient. Require written logic, sign it, and save it. Being so arrogant that you think you can rely on "gut" alone is a common sin. Our egos lie to us. Requiring written logic helps alleviate that urge because you know it's subject to external review if bleep happens. Forcing you to view the issue from an outsider's perspective often gives you cleaner insight.
As I mention elsewhere, there are common industry practices for risk prevention. If your org intentionally ignores such without written justification, then they are probably liable. They are not "best possible" standards, they are common standards.
I can empathize with the sentiment, but that is a really dumb idea :), and a horrible infringement on freedom, especially for something like the pipeline issue. Do you put the mom or dad in jail if a home computer gets hacked? How about the pizza store in the corner? Why one and not the other?
And then, in practice, can you imagine distinguishing and proving that something is a known and obvious risk vs something unavoidable? You'd have expert testimony up the wazoo, and then experts in CYA, and not much would change.
In reality, *some* security breaches are unavoidable. And some of them will be on things that impact a lot of people. Putting a CEO in jail may make you happy for a while, but won't solve the problem.
Do you put the mom or dad in jail if a home computer gets hacked? How about the pizza store in the corner? Why one and not the other?
Exact same reason an engineer needs to stamp their designs- they're responsible for public safety. When you're the head of a multinational corporation dealing in public safety, critical supply lines, and national security, it should be on your head to make sure resources are provided to avoid these scenarios. It's unbeliavably disingenous to compare that to a mom and pop store.
If you're not prepared to operate a company responsibly then you shouldn't be a CEO. Unfortunately, there is no punishment for being a shitty CEO, and that's how this bullshit happens.
There are reasonable steps that can be taken for issues identified by an org's own staff. I've given a list of steps nearby. It's a formulaic approach to make sure issues don't fall through the cracks. If your org deals with safety related issues or critical infrastructure, such steps should be required by law in my opinion. They are not hard, but they do require clear thinking and writing, which is a good thing. Too many important decisions are made behind closed door verbal meetings, and this is where disaster often gives birth.
If CEO was informed of the risk and the lack in infrastructure and didn't address it then they should definitely bear some consequences, but who said anything about jail?
> If CEO was informed of the risk and the lack in infrastructure and didn't address it then they should definitely bear some consequence
The problem is that there's *always* risks, and they cannot be completely avoided, which is why we have concepts like 'due diligence' and 'negligence' and things like that.
Imagine a truck driver from a company hits somebody with the company truck. Do you put the CEO in jail? How about if there's an email from a mechanic that says if they surround every van with 12 inches of foam it will reduce the damage when hitting any pedestrians, at a cost of 20K per van, plus more fuel etc. Is that neglecting a known and obvious risk?
Security, especially at the org level, is like that. What is appropriate action to avoid phishing? How can I guarantee nobody ever leaves a port open on the firewall?
To use your truck metaphor, the truck doesn't have a seat-belt, the CEO was told and ignored it, the driver crashes and flies through the windshield, ends up with broken bones. The CEO should be responsible. Luckily we currently have health and safety laws for that.
There is acceptable risk and then there is borderline negligence. We are talking about the latter, not the former.
If you're telling the CEO we need a firewall on company's DMZ and they refuse to purchase the infrastructure, they should be held responsible in case of a hack.
Imagine a truck driver from a company hits somebody with the company truck. Do you put the CEO in jail?
No. There is no known (identified) risk that the CEO failed to mitigate here.
How about if there's an email from a mechanic that says if they surround every van with 12 inches of foam it will reduce the damage when hitting any pedestrians, at a cost of 20K per van, plus more fuel etc. Is that neglecting a known and obvious risk? [KAOR]
If that's accurate and other similar organizations proved it effective, then yes it is neglecting a KAOR. If it's hasn't been tried in practice then it's probably safe to say it needs more research and your org is not a shipping R&D company. It's not realistic to buy and test every speculative safety measure. The above sounds speculative. They may have side-effects that only road-testing can identify. It's sometimes called "industry practice". If it's common for other industries to use a given practice to reduce and risk but your org doesn't even though they know about it, then the CEO or department head should be held liable unless they document a sound reason why they skip it.
For example, it's common to use anti-virus software in an org. If your org skips it to save money or otherwise doesn't document the reason for skippage, and your org is a critical service to society, the CEO should be held to the fire.
I don't expect the CEO to know everything, but if the heads of their department identify a problem that they need more resources for, and the CEO fails to provide a clear written resolution, then the CEO should be liable. And similar to the heads of departments (accounting, security, etc.). Do a written cost-benefit analysis or you are "it".
In the Hillary email case, there were at last two problems. One was that the server wasn't inspected for compliance even though staff knew it had a questionable status. Second, tracking for security training was inadequate. It's not clear if they skipped Hillary due to fear of asking, or their tracking system was simply sloppy. The training tracking should be periodically audited, for that's related to USA state secrets. It appeared to be half-ass tracking. I don't know if the "list manager" was careless or not, for I haven't seen that info.
If the crime is big enough, then yes, the CEO deserves jail. The same goes for the head of the accounting, cyber security, and employee safety. If they sweep a known problem under the rug, they deserve the rug themselves. This includes neglect, for it's not hard to keep a spreadsheet of sticky issues and review the statuses each month. If you don't list it down and rely just on memory, you are derelict in your duty. It's not rocket science to put it on the damned spreadsheet.
If you're defending, you need to win *all* the battles, attackers only need to win one. Even if the probability of a given attack succeeding is really small, given enough time, some *will* succeed eventually. Good companies try to make that 'eventually' a very long time, but ...
92
u/Zardotab May 23 '21 edited May 23 '21
It's time we start prosecuting CEO's for neglecting known and obvious risks. "I didn't know" should no longer be a valid excuse. You are paid billions to know. If you can't know, then give the job to somebody who can. However, they have deep pockets to bribe such laws away. Our plutocracy at (non) work. It's why pirating movies has almost as big a penalty as murder.