3 ms·
You would be surprised how much of corporate cybersecurity is done like this. It has not in anyway improved sine crowdstrike, on the contrary EDR shenanigans ha
by daghamm 2y ago
You would be surprised how much of corporate cybersecurity is done like this. It has not in anyway improved sine crowdstrike, on the contrary EDR shenanigans has probably grow 100% since last year.
These security companies must have really good salesmen. Or maybe IT departments are always ran by clueless fools, who knows?
- vladvasiliu 2y ago> Or maybe IT departments are always ran by clueless fools, who knows? I think IT has its fair share of clueless fools, but what I've noticed is that when the "security department" is separate, people there tend to have no idea what they're talking about and rely on checklists. Plus, "everybody uses X, that means we're missing out".
- MaKey 2y agoCorporate IT security seems to be mainly about checklists and compliance, not about actual security.
- mrguyorama 2y agoThere's no reason to do anything else. Nobody has gone to jail as of yet for not securing their company, and even "security" companies that get utterly popped still have plentiful business a year later. There is no legal incentive to do good security. There is no market incentive to do good security. Why is it so surprising to people that we have abysmal security?
- vladvasiliu 2y agoIn my case, it's surprising because companies waste a ton of money buying snake oil and aggravating their users for next to no benefit. You'd expect companies that "only care about their bottom line" to optimize this away, yet they don't.
- screcth 2y agoThe security team cares about minimizing risks to the company and to their own careers. Deviating from what everybody else is doing makes it so that the burden of proving that your policies are sane is on you and if anything bad happens your head is the first to roll. You use CrowdStrike and the company lost millions of dollars due to the outage? That's not your problem, you applied industry standard practices. You don't use CrowdStrike and the company got hacked? You will have to explain to the executives and the board why you didn't apply industry standard practices and you will be fired.