Which option best describes the range of consequences an organisation may face for material non-compliance with a security or privacy regulation?
- AOnly monetary fines imposed by the regulator that owns the rule, capped at a fixed statutory amount per breach.
- BOnly the obligation to retrain staff and update internal policies within a remediation window agreed with the auditor.
- CFines, sanctions, loss of licence to operate, contractual penalties, reputational damage, and personal liability for named officers, depending on the regime and severity. Correct
- DOnly public censure issued through the regulator's website, with no financial or operational impact on the firm.
Why A is wrong: Tempting because fines are the most visible consequence, but real exposure routinely includes contractual, reputational, and operational outcomes alongside, and many regimes scale penalties to turnover rather than using a fixed cap.
Why B is wrong: Tempting because remediation plans often follow findings, but training and policy updates are usually the lightest part of the response and do not represent the full consequence set faced by the organisation.
Why C is correct: This is the correct, broad picture: regulators, customers, courts, and markets each impose different consequences, and serious regimes can also attach personal liability to directors and officers.
Why D is wrong: Tempting because public notices are common, but they are usually one element of a wider package; treating non-compliance as a purely reputational matter understates the real exposure faced by the organisation.