There are a few things companies are supposed to be doing. Obviously there is the data protection act that mean companies should take due care to secure personal information. We also have PCI:DSS (Payment Card Industry : Data Security Standard) that specifically looks at ensuring a secure environment for the storage and processing of credit card data.
As we know there is no easy step when it comes to security, its good we have these requirements, but security is often seen as a like as opposed to a need.
Organisations are sadly very reactive when it comes to security, and will only spend when / if an issue occurs. Proactive security is the key, using a risk based approach to get the balance right.
Keeps us in a job anyway
