3 ms·
You're describing what's popularly known as a "security champion" program. The problem is you're giving a little bit of training and authority to someone who is
by Kalium 2y ago
You're describing what's popularly known as a "security champion" program. The problem is you're giving a little bit of training and authority to someone who is primarily accountable for marketing/dev/whatever. At best, this sets up a conflict of interest that the person will occasionally navigate successfully. At worst, they now know enough to be even more dangerous.
The problem isn't just knowledge. The problem is getting people to use that knowledge to push back on bad ideas.
- consumer451 2y agoThanks. I'm filing that phrase away for future reference. Again, I am just stabbing in the dark from the outside here: From my external POV, it feels like for all its faults, Google/Alphabet took the time to create BeyondCorp, and does not have the same record of infosec errors that Microsoft seems to regularly display in recent times. Is that correct? If so, in your opinion, what is the difference? They both print money... Is this just a difference in "corporate culture?" Disclaimer: I grew up in Kirkland/Redmond, have a bias that is favorable towards MS, and would love to understand what the heck is happening.
- Kalium 2y agoGoogle/Alphabet is willing to mandate - and then enforce - sweeping changes. When they shifted to U2F and forced everyone to use it, phishing all but vanished as an ongoing problem. I don't know if Microsoft is capable of that, technologically or culturally.