This morning, I retweeted a link to an articleÂ (in Dutch) published by a Belgian newspaper. It looks that Belgian municipalitiesÂ (small as well as largest) which do not properly secure their data could be fined in a near future! Public services Â manage a huge amount of private data about us. They know almost everything about our lifes! Increasing the security around theseÂ data looks a very good idea but… are fines a good idea? Fines are very repressive.
Iâ€™ll make a rough comparison with speeds tickets. Iâ€™m driving a lot, always on the road between two customers. MoreÂ kilometers you spend on roads,Â more chances you have to be controlled by speed cameras. Sometimes, I receive a nice giftâ€¦ a speed ticket! Ok, I admit: itâ€™s frustrating. Iâ€™ve always the feeling to be 0wn3d but guess what? I just pay the bill and continue to use roads as before. This does not affect my way of driving, it is â€œpart of the gameâ€. I even know people who reserve a budget to pay theirÂ speed tickets! Just like any other risk, it can be quantified and we are free to take it into account â€¦ or not! Where is the breaking point between paying fines and driving slowly?
Let’s go back to Belgian municipalities. They could be facing the same issue: To invest in information security (tools, services, audits) or cross their fingers and hope to not be cought? The could also reserve some budget to pay fines. Fortunately, before punishingÂ the bad players, the authorities will perform some checks as statedÂ in the article:
By beginning of theÂ next year, all municipalities must have a safety plan in place.
IMHO,Â fines won’t be the solution! Instead of paying fines, why not invest this money into security projects? When a company (read: “with commercial activities“) has to pay a fine in case of security incident, only its customers are affected. In case of a municipality, all citizens are involved asÂ the buget is based on taxes! Instead of repression, authorities must implement more prevention like forcing municipalities to have a safety plan. Repression gives always a feeling of actingÂ badly while prevention helps to stop something from happening or arising!