6 ms·
Would you care to comment on who you'd consider better?
by YouKnowBetter 9y ago
Would you care to comment on who you'd consider better?
- thinkMOAR 9y agoThat is a very hard question. The simple answer is _that one_ security company that manages to compromise you and point out all issues within your company and or code for you to fix/address, that's the best one (for you). (if we can leave the financial part out of it, because security advice or audits aren't cheap either.) But it is not that simple. I don't consider that very likely, that you actually find that 'right' company. (and putting faith in a third party to audit your code/company, brings other risks too). And chances are that some issues will be overlooked but not by that 'weird' guy/girl in the attic that has all the time of the world to security probe you 'for free'. And there will always be a part you can't audit properly, your employees, which often is the origin of a hack, disgruntled employees. Or even worse, a disgruntled employee of the security company that just audited you. And keep in mind, with enough power, you can get anything offline or in a non acceptable state (half working, data compromise etc). So security companies can only help you a certain length, nonetheless it can be very helpful to have a person from outside look at things with 'fresh eyes' and see things you have overlooked for so long because you are right in the middle of it all.
- d215 9y agohttps://radicallyopensecurity.com/ https://radicallyopensecurity.com/ are pretty great. Don't know if they're actually better than fox-it. The latter I only know by reputation.