“The FTC intends to use its full legal authority to pursue companies that fail to takereasonablesteps to protect consumer data from exposureas a result of Log4j,or similar known vulnerabilities in the future,” the FTC said, adding that it plans to apply its legal authority to protect consumers in the cases of “similar known vulnerabilities in the future.”
What I hate about language like this is that reasonable action could be as simple as saying "we don't allow external user inputs into our systems that aren't processed for invalid values." Or it could be something like "this app is used internally only by authorized users." While it's true that those are valid risk mitigators (though the effectiveness can easily be challenged) it's not the same thing as patching. So in my opinion, it may sound a bit threatening at first but I don't think it will do much.
He has not acquired a fortune; the fortune has acquired him. -- Bion