Here's the question: Should the company notify their customers of a POSSIBLE compromise of their data? I have been trying to convince them that they should operate as though the data is compromised. Is that the right position to take as a security consultant?
What would be the consequence to their business be if the news of compromise came from a third party, and not the business itself? They need to get out front on this.
-- Hawaiian Astronomical Society: http://www.hawastsoc.org HAS Deepsky Atlas: http://www.hawastsoc.org/deepsky _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/