3 ms·
> Their recent security issues with that hack were devops management and governance problems If those are the hard business/technology management problems (and
by peterwwillis 6y ago
> Their recent security issues with that hack were devops management and governance problems
If those are the hard business/technology management problems (and they are), then try solving those while also securing them.
Security by itself is relatively straightforward: 0days, red teaming, scanning for known vulns, etc. Just like every other aspect of the business, you hire someone to do one specific thing and you've got lots of options.
But then try to infuse security into every single aspect of a business and product, in a way that increases both velocity & quality of product dev, without sacrificing efficient organizational management. There are already a ton of inscrutable complexities between all facets of the organization and its products. Trying to add security to all that is like teaching a juggling elephant to ice skate.
So you need someone who's very good at managing security in the context of all those other problems. That's hard to find. It helps to have people who've seen problems in the same general space from a lot of different angles.