Penetration Testing mailing list archives

RE: Fwd: Why suing auditors won't solve the data breach epidemic


From: "Nick Vaernhoej" <nick.vaernhoej () capitalcardservices com>
Date: Tue, 23 Jun 2009 13:59:14 -0500

Jeff,

Oh I doubt there are anyone left on the planet not aware of standard
bonus practice here.
But I hope it is also apparent at this point that the solution doesn't
scale.
Starting out a new business model along the same standards seems like a
bad idea to me.
But then again, I really don't know what I am talking about ;)

Nick

-> -----Original Message-----
-> From: Jeffrey Walton
-> Sent: Tuesday, June 23, 2009 12:10 PM
-> Subject: Re: Fwd: Why suing auditors won't solve the data breach
-> epidemic
->
-> Hi Nick,
->
-> Standard practice in the US. For a 1 trillion dollar example, look at
-> the US financial industry. Some companies were run into the ground.
-> Amazingly, their executives took performance and retention bonus for
a
-> job well done.
->
-> The only folks who should have received a bonus in the fiasco were
the
-> CFOs since they managed to get bailout money (ie, TARP) from the US
-> Congress with very few strings attached. The CFOs should have
received
-> an even larger bonus when they managed to keep their bonuses (only
new
-> executives do not qualify [1]) .
->
-> Jeff
->
-> [1] Public Law 110-343, Section 111, 'EXECUTIVE COMPENSATION AND
-> CORPORATE GOVERNANCE'

This electronic transmission is intended for the addressee (s) named above. It contains information that is privileged, 
confidential, or otherwise protected from use and disclosure. If you are not the intended recipient you are hereby 
notified that any review, disclosure, copy, or dissemination of this transmission or the taking of any action in 
reliance on its contents, or other use is strictly prohibited. If you have received this transmission in error, please 
notify the sender that this message was received in error and then delete this message.
Thank you.

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: