3 ms·
So, what should we do? Should we just fire/jail everyone who has ever worked for a company that was breached? You realize that would be literally everyone, in p
by bodz 9y ago
So, what should we do? Should we just fire/jail everyone who has ever worked for a company that was breached? You realize that would be literally everyone, in pretty much every company ever, right? There's a saying in the cybersec world: "there are two types of companies: those who know they've been hacked, and those who don't realize it yet".
Cybersecurity is a field where there's already not enough good talent. And even the very best talent is still going to not be good enough from time to time.
It is simply completely naive and unrealistic to expect a company to be 100% hack-proof, and if you start punishing people for that, then you're just not going to have anyone taking the job at all, and you're going to have even less security.
- liberte82 9y agoOh come on. Anyone here who is a developer has at least some experience with raising a security concern to business or management and having it shot down as not important enough to worry about. We all know companies still aren't taking cybersecurity seriously enough, and it's because the consequences for a breach aren't severe enough.