10 ms·
> 500-employee company, 100 of those in engineering/IT roles. > No security policy in place. How is that possible? Are you saying there's no security policy o
by el_dev_hell 7y ago
> 500-employee company, 100 of those in engineering/IT roles.
> No security policy in place.
How is that possible? Are you saying there's no security policy or a minimal security policy? I can't imagine how a company gets to 500 employees without a single security incident that forces your hand to create some kind of formal policy.
- twunde 7y agoLet's be honest, Enterprise sales companies have to get a soc2 or equivalent. Otherwise, if your customers aren't asking for it, it's easy to go without. Especially at under 1000 people. I've worked at companies with ~200 employees that didn't have a security policy and were incredibly insecure. 500 is typically when b2c will start thinking about security programs, but the reality is that unless security is revenue generating it becomes incredibly hard to build out security policies