3 ms·
That CEOs should be accountable for lazy security. That everyone does security theater, no one does real security. Mostly for convenience to marketing data is
by _Codemonkeyism 9y ago
That CEOs should be accountable for lazy security.
That everyone does security theater, no one does real security. Mostly for convenience to marketing data is not encrypted in REST, data is not segmented into different data stores (own store for passwords etc.) but stored in the same MySQL database, employees can dump millions of records instead on one-record-at-a-time, people let fly unencrypted Excel sheets everywhere etc.
- Spivak 9y agoWhy? What does a CEO know about InfoSec? Why make CEO's punching bags for fields they aren't experts in?
- SOLAR_FIELDS 9y agoWhat does a CEO know about accounting? Should they be held liable for irresponsible accounting practices performed by their subordinates if they are not an expert in accounting?
- pbhjpbhj 9y agoThen they manage the company and make sure they have someone in charge of overseeing InfoSec that does.