4 ms·
An organization going out of business isn't just a case of bad management being eliminated. I wrote that line thinking of the clients I've worked with who've b
by ideksec 5y ago
An organization going out of business isn't just a case of bad management being eliminated.
I wrote that line thinking of the clients I've worked with who've been hit by ransomware and didn't realize IT were not doing their job until it was too late. In some cases it's a failure on their part - not investing enough time or resources and seeing IT as "the guy who installs windows". More often than not, they were assured it was taken care of. I don't expect a manager of a car dealership to know if their Exchange server is running recent patches. If companies like SolarWinds and Kaseya can get popped and compromise their downstream customers, think of the number of small MSPs causing that same issue every day. I don't think a business should go under with people losing their jobs because IT screwed up.
We would be better off without leadership who take no interest in security, and once a company is hit with a 100k ransomware bill you can bet they'll care going forward.
- throw0101a 5y ago> More often than not, they were assured it was taken care of. I don't expect a manager of a car dealership to know if their Exchange server is running recent patches. You're not wrong, but would the same dealership be as blasé about the assurances from their accountant that all their taxes are being paid? Certainly no one can be an expert in everything, but regular audits from third parties of one's business at semi-regular intervals is prudent. We call in an external IT security auditor regularly ourselves to make sure we're not missing things and still following best practices.
- nobody9999 5y ago>Certainly no one can be an expert in everything, but regular audits from third parties of one's business at semi-regular intervals is prudent. We call in an external IT security auditor regularly ourselves to make sure we're not missing things and still following best practices. You're absolutely correct, up to a point. As an InfoSec professional, I've been on both sides of such audits. Sometimes they're quite good. Sometimes they're awful. Usually, they're somewhere in between. What's more, just because an audit has been performed (even a really thorough one), there's no guarantee that the recommendations will be applied, or even if they are, that they will be applied competently. Leaving that aside and assuming that everything is done properly and thoroughly, regardless of all that hard work, it just takes one non-technical resource to click one link, and ransomware could be loosed on your network. There are, of course, mitigations and, hopefully they are all in place and just the one desktop/laptop system is compromised. All that said, many organizations don't have the time, money or expertise to properly secure their environment, let alone bring in outside auditors. Medium/large companies with such resources should absolutely do all of those things. But the vast majority of companies in the US are SMBs who likely don't have those resources. I'm not making a value judgement either way about the value of mandatory reporting, but I don't agree with your assessment. Edit: Fixed typo (word --> work).
- tomc1985 5y ago> An organization going out of business isn't just a case of bad management being eliminated. Being dispersed. Those people are still around and will go to "work" for someone else