3 ms·
Security training improves security but it doesn't get close to stopping 100% of attacks. I know it's obvious, but it feels like it's only obvious to those tha
by gav 6y ago
Security training improves security but it doesn't get close to stopping 100% of attacks.
I know it's obvious, but it feels like it's only obvious to those that think about security. It's the same reason that putting your developers through a yearly OWASP Top 10 secure coding course isn't going to get you to 100% secure code.
Locking down systems seems draconian, but it's the only way:
- Disabling USB storage
- Moving away from passwords to hardware authentication
- Strong controls on internet access
- Stop incoming calls from reaching most employees. Better: take away phones altogether
And so on.
- manquer 6y agoin a remote only or remote first working environment, many of these policies are not feasible , ultimately employees have to be able work somewhat productively . Such clean room requirements could perhaps work when the threat model include nation state actors or your are handling sensitive financial applications. Most companies are not defence contractors or banks the security levels you propose won’t be worth the cost to a typical internet tech company .
- lobster45 6y agoAnytime there are humans involved, there is no way to 100% secure it