was stolen, what direct impact it may have on its customers, or what customers
should do about it, other than some generic statements. Vendor B was also
successfully attacked on Monday night. However, Vendor B waited 10 days
before revealing the attack to its customers, but they included detailed information
about the attack, its consequences, and how customers could protect themselves.
In both cases, clear and immediate information was not distributed. Should
vendors be obligated to inform customers when attacks occur and how to protect
ourselves? What should be the time line for doing so? What should be the
penalties if vendors do not follow such guidelines?