Instead of hardening security defenses, Sony Pictures focused on offending North Koreans less, and was more afraid of security costs than risks
Sony Pictures: Inside the Hack of the Century, Part 2 — We will take “a merciless counter-measure.” — On June 17, leaked emails show … See also Mediagazer
Context & Ripple Effects
Fortune's two-part investigation closes its arc today: after Part 1 reconstructed the breach itself, Part 2 turns to why it happened — leaked emails showing Sony Pictures weighed whether content would offend North Koreans and priced out security hardening before attackers struck. That reframes the earlier reporting: the employees who were slow to grasp how severe the breach was were reacting to a company whose leadership had already decided defense wasn't worth the spend.
The timing matters because the damage kept compounding long after December's attack — five unreleased films leaked to file-sharing hubs, staff forced onto decades-old machines, and weeks later a US firm claimed Russian hackers were selling access to Sony's still-compromised network. The emails turn that from an unlucky incident into a documented governance choice.
First-order effects
- Sony Pictures' executives now have their pre-breach deliberations public: leaked emails documenting that they feared security costs more than risks gives plaintiffs, regulators, and the board direct evidence of what leadership chose not to fix.
- Employees remain the immediate casualties of that decision — internal systems never fully recovered, forcing some to work with decades-old technology while unreleased titles like Fury and Annie circulated on piracy sites.
Second-order effects
- Rival studios and large media companies face pressure to show their own boards are funding cyber defense, because Sony's leaked emails demonstrate that 'we didn't want to spend' is now discoverable and quotable in any post-breach lawsuit.
- Security vendors and insurers gain leverage in negotiations with studios: the Sony case supplies a concrete example of the uninsured downside when hardening budgets lose to content-risk aversion.
Third-order effects
- If the pattern holds, breach liability will shift from IT departments to executive suites — with email records like Sony's becoming standard exhibits in litigation, making pre-attack security spending a defensible fiduciary act rather than discretionary overhead.
- Attribution-driven caution cuts both ways: a studio softening messaging to avoid provoking North Korea shows nation-state threat perception now reaches into corporate content and communications decisions, not just firewalls.
The trend: Corporate breaches are being litigated and judged less on the attacker's sophistication than on what executives knew beforehand and chose not to fund.