Promote legislation that will impose civil penalties at the executive level for improper governance of credit card and other personal data.
The incidence of a breech should not be considered a violation of the law unless the corporation did not implement best practices to protect private data from hackers. Making a lack of information technology governance actionable by the state as a civil violation will help ensure that corporations act responsibly to protect private data.



