Daniel Haido, hand-delivered..
Probably a valid question for the person who hired this person to hand-deliver the IT policy written by the moron in charge of cybersecurity..
..not that I'm pointing fingers at the shit rolling down a hill or anything.
In all seriousness the human hand-delivering IP, was supposed to BE the fucking security. As in the same kind of security when Hollywood IP was sitting in an unencrypted film canister. If a CEO can't trust a human hand-off, they probably shouldn't be trusting their own HR with PII. Their mistake was not enforcing a timely delete policy by following up an hour after screening. If you're going to spend the money to hand-deliver IP, spend the money to hand-collect it or spend the money to ensure you don't have to.
Now this becomes a matter of who is responsible for damages when IP is leaked like this. Who is the custodian of transferred IP and the defined responsibilities.
This will likely change how Hollywood stores IP. Which means a guy named Skroob will set the combination lock to 1-2-3-4-5..