The cost/benefit analysis is exactly why the "Oh, but I have so many
computers and so little budget" philosophy is dead wrong here.

- There is no reason why sensitive personal data should be accessible on
each and every of your thousands of computers. And there is no reason why
all your clients should look the same and have the same level of security.
Introducing different security levels in your infrastructure (e.g. having
"more secure zones") should be the approach here, not complaining that
encrypting all and every kit costs so much..

Getting caught, punished, blamed and thrown in jail *should* be part of that
cost/benefit analysis. - So I just hope that we'll see some real stiff
penalties soon.

- Stefan

Security is simply a cost/benefit excercise at the end of the day. No one
implements security just to feel better about themselves.

Universities have their equivalent of executive boards, trust me.

