Instead of hardening security defenses, Sony Pictures focused on offending North Koreans less, and was more afraid of security costs than risks
Sony Pictures: Inside the Hack of the Century, Part 2 — We will take “a merciless counter-measure.” — On June 17, leaked emails show …
Context & Ripple Effects
This is the second installment of Fortune's investigation into the Sony Pictures hack, building directly on Part 1 of the probe and on the first-person account of life inside the studio after the breach. The new material comes from Sony's own leaked emails, which flip the story from victimhood to governance failure: executives weighed security spending against perceived risk and chose austerity, while also calibrating conduct to avoid provoking North Korea.
The finding retroactively explains what earlier coverage only described. The New York Times' interviews showed employees were slow to realize how grave the intrusion was; this reporting suggests why — the organization's leadership had priced the threat low before a single file was wiped.
First-order effects
- Sony Pictures' leadership now owns documented evidence, from its own email archive, that it consciously traded security hardening for cost savings — a direct reputational and legal exposure layered onto the breach itself.
- Employees remain on the front line of that decision: internal systems have not fully recovered, forcing staff to work with decades-old technology months after the attack.
Second-order effects
- Underinvestment left residual openings for others — a US security firm claimed Russian hackers were selling access to Sony Pictures' network well after the original incident, meaning the cost-aversion created a marketable asset for third-party criminals.
- The fallout is already monetized downstream: the studio settled a cyberattack lawsuit with identity-theft protection through 2017 and a $4.5M reimbursement fund, converting deferred security spending into litigation and remediation payouts.
Third-order effects
- If the pattern holds across Hollywood and comparable enterprises, boards will face pressure to treat state-sponsored attackers — here attributed to North Korea — as a baseline threat model rather than an edge case, making explicit security-cost-versus-risk decisions a matter of director liability.
- The episode also shows content piracy as a standing second-order cost of breaches: at least five unreleased films, including Fury and Annie, circulated on file-sharing hubs, giving studios a structural incentive to fund defense as IP protection, not just IT hygiene.
The trend: Major breaches are shifting corporate accountability from the IT department to the boardroom, as leaked internal deliberations turn pre-attack cost-cutting decisions into post-attack legal and reputational liabilities.