5 ms·
Just like Cryptolocker, this will be the "Finding Out" phase for everyone who has been putting off best practice security. But, lets be clear, Best Practice wi
by protocolture 9d ago
Just like Cryptolocker, this will be the "Finding Out" phase for everyone who has been putting off best practice security.
But, lets be clear, Best Practice will save you. We can engineer assuming there are zero days in path. Go to your CTO now cap in hand and ask for overlapping controls, wafs, application monitoring, backups and all the other shit you haven't been doing.
Because when you find out, I will laugh, it will be very very very funny to me.
- taurath 9d agoMeanwhile a huge portion of management and leadership in software companies are encouraging everyone to de facto stop looking at code and let the LLM and a bunch of boundaries handle this for you.
- m_mueller 9d ago“You are a CISO who needs to review and secure all our slop, and you never make mistakes or you get shut down immediately!”
- LoganDark 9d ago"You are a Miso soup..."
- protocolture 9d agoWhich is why you need someone who is responsible for IT security without also being responsible for shipping product. An asshole who can stop releases until security is properly in place. My understanding is this bloke gets very quickly removed from Fortune 500 companies. Which is why I am going to need a very large capacity popcorn bucket.
- rukuu001 9d agoA couple high-profile crash & burns will get their attention.
- jcgl 9d agoJust like well-publicized data breaches over the years got people’s attention? Color me skeptical.
- Shorel 7d agoThe CEO of the company I work for is extremely paranoic about data breaches. We do a lot of prevention and recovery testing. So yes, it can happen.
- jcgl 7d agoThe world is a big place. Of course it happens. But, colloquially speaking, "getting people's attention" suggests that more than a rounding error took heed. I'm glad your CEO cares. It makes a difference and I hope you feel good about that. And the world would be a better place if more did care. But, to a first approximation, it seems like organizations don't care about data breaches.