(no title)
abixb | 2 years ago
I am of the opinion that this massive push by big organizations (coupled with mandates for C-suite roles like CISO) into building a dedicated army of staffers for "cybersecurity" feels like just another attempt to bloat up the size of an organization and create more 'bullshit' jobs, as David Graeber put it over half a decade ago.
genmud|2 years ago
I liken my job to being a janitor, and people can't seem to stop from pissing, shitting and trashing everything. It's goddamn 2023 and we still can't get people to always validate input or ensure proper constraints are built in.
slt2021|2 years ago
unknown|2 years ago
[deleted]
Ekaros|2 years ago
I don't expect magic, but at least cover the absolute basics. Then I might be able to figure out something more interesting or rare.
Or if I get report that something has CVE, just tell me if that is a problem for you or not.
slt2021|2 years ago
This makes it impossible to do anything meaningful de-novo on a high level, like create a good security architecture as a platform for all dev teams, or adopt a new security platform.
Outsourced companies do only a piece work on a ticket by ticket basis and require very specific instructions upfront.
Mandating companies to keep inhouse cyber staff makes it possible to grow talent inhouse and do high level designs of platforms to keep stuff secure
makeitdouble|2 years ago
hazmazlaz|2 years ago
zitterbewegung|2 years ago
Honestly in cybersecurity the big hacks that usually go on is the fact that people can get crypto lockers or a whole host of problems that attack humans. The whole argument of the above shouldn’t even be anything about software. The most effective thing to secure networks is to educate your whole staff on when not to click something suspicious so instead of fighting physics we are fighting human psychology.
I could argue the second is the business group overriding security practices because they accept or don’t care about the risk. So then people who were never born when the service was active have to deal with getting a project in with the vendor that doesn’t give a shit about you.
Security usually even is a technical problem it’s human we just like having cool stuff presented at a con because it’s fun.