3 ms·
One of the counterintuitive things I've learned is that "security is everyone's job" is one of the worst possible scenarios. First, the vast majority of people
by Kalium 3y ago
One of the counterintuitive things I've learned is that "security is everyone's job" is one of the worst possible scenarios.
First, the vast majority of people are not equipped to find or address major security issues well. Unless you have specialists integrated in the right places this means everyone's likely to be bad at the security part of their job and ill-equipped to notice.
Second, this means conflicts of interest everywhere. When you have a dedicated security org, you have people whose job it is to catch issues, hold things up, and generally make sure things get fixed. Without that, you have a bunch of people who have to choose between the possibility of a security event they don't understand and the certainty of blowing a deadline.
Third, security being everyone's job almost certainly means accountability is broken. Consequences will likely fall on some junior employee who might be directly accountable for an issue, but the huge org around them that did not enable them to succeed go unaffected.
You need specialists, an org to enable them, and an enterprise-wide apparatus to support a strong security process.