• jubilationtcornpone@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    22
    ·
    1 day ago

    Most organizations in the US don’t value cybersecurity as anything more than an abstract concept. The reasons for that can be numerous but in my experience it’s usually a combination of cost + survivorship bias.

    Lack of serious consequences is another factor. Had a breach? Pay a small fine and an even smaller settlement (or should I say your insurance pays) and then it’s back to business as usual. Even in situations where the breach is due to gross negligence, the consequences are minimal (see Equifax).

    • Shirasho@lemmings.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      In my experience it has been that the company cares about security but they keep hiring the cheapest contractors from India who know nothing about security and they introduce holes faster than onshore developers can fix them.

      Either way, you can point to cost cutting as the underlying root cause.

      • entwine413@lemm.ee
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 day ago

        That and IT is often seen as the redhead step child because they’re not revenue generating. I’ve had a purchase request for a single bag of zip ties denied before.

        • taladar@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          22 hours ago

          Plus security is one of those if everything goes right “what are we paying you for” and if something goes wrong “what are we paying you for” parts of the business.

    • Telorand@reddthat.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      I wish we could make fines a percentage of unrealized gains that are over a certain amount. That would make some of them care.