4 ms·
Not wanting to defend Twitter, but I'm pretty sure the situation is very similar across a whole lot of companies, even those that make security their main busin
by freeflight 4y ago
Not wanting to defend Twitter, but I'm pretty sure the situation is very similar across a whole lot of companies, even those that make security their main business, i.e. FireEye.
Because investing in IT security usually has no apparent profit incentives, so most companies leadership will consider it something of very little importance funding wise.
Particularly in the current climate where even minor hacks, and simple ransomware infections, are regularly made out as some kind of "act of God"/allegedly done by some super advanced "state actor", to create the narrative how it just wasn't preventable with the resources of a private company.
Which outsources all the responsibility to ominous intangible parties based on wonky, and often politically motivated, attribution, while holding nobody responsible for running outdate software in exploitable combinations, thus creating the problem in the very first place.