“The Sony PlayStation network breach has revived Australia’s dormant security disclosure debate.

Rob Forsyth, A/NZ managing director of Sophos, says the government must legislate for mandatory disclosure, noting that it has been proposed in a large number of privacy recommendations. If personally identifiable information is lost, he said, companies must notify both the general public and the individuals whose information has been stolen.

“Sony was not quick to notify people that there had been a breach of security,” RMIT lecturer and computer networking specialist Dr Mark Gregory told the same programme, even though the speed with which the network was shut down demonstrated that Sony was aware of the problem before it went public.”

From The Register