top | item 15280737

(no title)

valas | 8 years ago

It's quite possible the security firm was asked to audit their systems, but not asked (or paid) to fix them.

discuss

order

086421357909764|8 years ago

A lot of people want you to come in and find a quick answer and fix, rarely allowing a full proper investigation. Many times they're adverse to spending money and want to cut corners where they can. It's actually disheartening. Much like one of the posters above, I've seen people purposely stop investigations because if the investigation reported on known issues it would open up more questions about other wrong doings.

The Irony is their actions on remediation are almost exactly in line with the decisions made that often times lead to the incident. It's cyclical.

chii|8 years ago

So you can't do this with accounting audit, so laws should be updated to make security audits the same!