The Laissez-fare theory applies to this sample letter. The idea that the government should intervene only to protect user’s rights comes into play following a breach. The government should be able to step in after a breach to help minimize the loss of user data. The rational choice theory also comes into play. Businesses leave themselves open to breaches because strong cyber security departments can be expensive, and they would rather focus on the bottom line than proper safety in some cases.
The rational choice theory also applies to the social science aspect. The companies know what vulnerabilities they are living with and choose how thoroughly to protect them. The deterrence theory can apply to criminals and companies. The penalties for cybercrime should be high to deter criminals from trying them. The penalties for loss of PII by companies should also be high enough to incentivize proper protection.