You point out that people that use a product should be provided security updates. Are they indemnified? Must a company provide updates after they declare some product obsolete and no longer supported? For people using Windows 7 today, for example. What about voluntary sharing of peoples data. Are companies required to report that? I think if not, this legislation is worthless, because companies will just sell, or even give, their records to hackers to avoid reporting breaches.
Thanks!
RE: Cybersecurity Regulations Will Force Companies to be Trustworthy