3 ms·
Having built security programs at multiple companies, I can tell you it's not something as easy as one person cramming content for a day and then implementing w
by ericalexander0 4y ago
Having built security programs at multiple companies, I can tell you it's not something as easy as one person cramming content for a day and then implementing with ease.
It's also unclear what outcome the business is looking for. If I had to guess, a big contract requires "security" and management wants to check that box the cheapest way possible.
If it's about first steps to improving security posture, and assuming you have a SAAS offering - then the first thing I'd do is start a bug bounty with hackerone or bugcrowd. It's the quickest way to both establish a feedback loop on security state, while also introducing a forcing function to prioritize fixing defects.