You keep bringing up huge examples. Millions of credit cards leaked. Guitar center, a company that has 260 locations across the United States. Great clips has over 3,000 locations. Anthem, a company with multiple billions of dollars in revenue that handles extremely sensitive information for millions of people.
I remember as a kid, there was a family owned comic book shop I would visit. I would let them know what comics I'm interested in, and they would call me if they got something in that they thought I would be interested in. So they had good reason to have our phone number. It was probably even stored really insecurely (on a piece of paper). But it was the early 90's. And if someone stole it it might have included 200 phone numbers.
I buy magic the gathering cards from small card shops across the country. They need my address to ship it. Since most of these single store businesses are fairly low tech, I doubt they do too much to protect it.
Also, your initial statement also said handle, not collect. Most brick and mortar stores handle credit card data, although they don't collect it. There's even been instances of thieves affixing devices to ATMs and credit card machines that will scan your card data as you slide or insert it.
You can collect PII by hosting a static webpage (ip addresses). Leaking that PII can cause harm to users (DDOS). This may seem made up but people who make a living off live streaming are fairly regularly DDOS'd by malicious viewers who figure out their IP.
More generally, any leak of data, whether it includes PII or not, will harm a company's reputation.
This is why I called your post insanely irrational. It's all black and white: hire a dedicated security engineer, or you're doing it wrong. Regardless of size. The majority of businesses in the country would go out of business if they had to abide by your rules.
I remember as a kid, there was a family owned comic book shop I would visit. I would let them know what comics I'm interested in, and they would call me if they got something in that they thought I would be interested in. So they had good reason to have our phone number. It was probably even stored really insecurely (on a piece of paper). But it was the early 90's. And if someone stole it it might have included 200 phone numbers.
I buy magic the gathering cards from small card shops across the country. They need my address to ship it. Since most of these single store businesses are fairly low tech, I doubt they do too much to protect it.
Also, your initial statement also said handle, not collect. Most brick and mortar stores handle credit card data, although they don't collect it. There's even been instances of thieves affixing devices to ATMs and credit card machines that will scan your card data as you slide or insert it.
You can collect PII by hosting a static webpage (ip addresses). Leaking that PII can cause harm to users (DDOS). This may seem made up but people who make a living off live streaming are fairly regularly DDOS'd by malicious viewers who figure out their IP.
More generally, any leak of data, whether it includes PII or not, will harm a company's reputation.
This is why I called your post insanely irrational. It's all black and white: hire a dedicated security engineer, or you're doing it wrong. Regardless of size. The majority of businesses in the country would go out of business if they had to abide by your rules.