Such information might be sensitive employee or customer information, confidential business research or plans, financial information, or information falling under special information categories such as privacy information, health information, or certain types of financial information. Some of these information categories have special, much more restrictive regulatory requirements for specific types of information security protections. Failure to properly protect such information, based on the required protections, can easily result in significant fines and penalties from the regulatory agencies involved. Just as there is a cost involved in protecting information (for hardware, software, or management controls such.