Originally posted by 2200
I agree with most of what you said here, but my issue is with the time frame and the apparent lack of readiness for this situation. Yes, I know that you truly can not be ready for something like this, but actions and statements that Sony has made in the last 3 weeks are not best practices for a company this size. I would be interested in what company you are referring to that has handled a situation like this, and as poorly as Sony has.
I can't find the link
But i believe it on the BBC from a couple firms about this. One of them talks about how long it took them to say. And said for a database as big it about right.
5 days to look over the data then alert users. Note that sony did employee a firm to investigate.
Now it a good example of how to deal with it and how not too. Mainly could have been a bit quicker but still pretty fast.
There are cases all the time which companies have a leak or groups and don't say a thing.
Here a list and how long before some do
Heartland Payment Systems waited one year before saying
October 2007 reported jan 2008 GE Money
July 2005 reported 2007 jan TJ maxx
Etc etc etc
All the cases above are bigger then sony but still show you.
The list goes on, so you see sony waiting 5 days or more is nothing. And there are alot of cases where it goes unreported.
PR wise so far sony done pretty well
Could do better at following the golden rules during a crisis PR - to be open, honest, transparent and fast.
Your right not the best practices but it still a pretty good job compared to other companies.