4 ms·
That’s how most companies do most everything. If they get big then they’ve figured out a systematic way to win at one or more games in business. Everything else
by ryanmarsh 5y ago
That’s how most companies do most everything. If they get big then they’ve figured out a systematic way to win at one or more games in business. Everything else is just enough of a shit show to get by.
As with all aspects of modern business operations “how to do it right” has been crowed about for decades by experts who care. It’s just that nothing matters until it matters, such as waste disposal, workers rights, product safety, etc…
If you show me the incentives I’ll show you the behavior. The only way we will ever get data security to matter more than theater and “check the box” is for the obvious to happen (bad consequences).
We don’t have a Ralph Nader.
This is why I’m against responsible disclosure, accepting below market payouts on bug bounties, and generally treating companies with any modicum of trust. Until it hurts so bad that people are on the steps of the capitol building beying for the blood of CIOs will we see meaningful change.
- Cd00d 5y agooh, wow. I already thought the job of CIO was overwhelmingly stressful! I think the job description is: try to create some guardrails but worry constantly about events way outside your control ruining everything.
- ryanmarsh 5y agoNo it’s primarily vendor management (according to the CIOs I’ve interviewed). When you have a network security department unable to articulate its policies, which relies on vendors for everything including expertise, you damn well should worry.
- datavirtue 5y agoHmmm Ralph Nader? The guy that went after GM for safety and helped establish a new agency that studied the car he used as fodder for his theatrical campaign only to find it had no safety issues. Ralph Nader is already a laughing stock and a warning to all in the history books.