4 ms·
This will change with time. I have thought, studied, talked, and written extensively on this general theme. What comes to mind to frame it for you is my "four
by jjguy 9y ago
This will change with time. I have thought, studied, talked, and written extensively on this general theme. What comes to mind to frame it for you is my "four principles:" [a]
1. Compromise is inevitable
2. Default-allow products always fail
3. 1 and 2 are not opinion or marketing spin, just simple truths
4. As an industry, we are still learning 1 and 2
Security is slowly shifting from an administrative IT function to an operational function. In IT, the business value comes from the products and people are a tax required to administer the products. In security operations, the business value comes from the people, products are just tools in their toolbag. [c]
Keep walking this dog and you realize basic IT activities for core infrastructure are critical for security, to the point the CIO will report to the CISO -- unless the CIO steps up. [b]
So - in short - your frustrations are accurate, but the winds are shifting. Companies will incresingly value top people for their internal staff/blue teams. It's going to take a few more years, but I believe it is inevitable.
[a] - https://www.linkedin.com/pulse/my-four-cybersecurity-principles-j-j-guy https://www.linkedin.com/pulse/my-four-cybersecurity-princip...
[b] - https://www.linkedin.com/pulse/cio-report-ciso-j-j-guy https://www.linkedin.com/pulse/cio-report-ciso-j-j-guy
[c] - https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy