4 ms·
My assumption has always been that companies large enough to have a security team also have better security practices than my small company. E.g. I'd guess Atla
by MichaelGlass 9y ago
My assumption has always been that companies large enough to have a security team also have better security practices than my small company. E.g. I'd guess Atlassian infrastructure folks don't share ssh keys over chat. Maybe they do.
- bjoernw 9y agoWhen a zero day drops the size of the security team is irrelevant.
- Godel_unicode 9y agoWho do you think is responsible for detecting a breach with that 0day? How about containing (and ensuring your believed containment is effective) and eradicating it? Would you rather have a dedicated security team do this, or would you prefer to have your devs wipe and rebuild naively, hoping they got everything? Even if you go MSSP, do they know your network? Security is just as much (if not more) responding to a breach effectively and quickly as it is preventing one.