Is Security a Benefit or a Feature?

Is Security a Benefit or a Feature?

I recently came across a tweet that was shared during the Infosecurity Maganzine Conference in Boston, “Security is a benefit, but not always a feature.” Why? You can spend a lot of money and still be hacked or not spend a dime and not be hacked.

How did the Inside Out Security Show panel react? Here's what Mike Buckbee, Kilian Englert and Alan Cizenski had to say:

Buckbee: It’s all tradeoffs. It’s all a bet. If you go into a casino and putting money down…While it’s true you can spend a lot of money and still get hacked, it’s less likely than you spend nothing. Or not even so much spend, in terms of money, but in terms of effort. You spend the effort and time to make secure systems….so you’re trying to play the odds.

Englert: We can write it up as a true-ism…We’ve never been hacked before, so we must be secure. That’s the default security mindset, which is at odds with the truth…The best security in the world, only takes you so far.

Cizenski: When you’re spending money on security tools, at that point, at the very least, you’re gonna have an audit trail or something to look back at so you can say, “How did that happen?” Instead of just thinking, “We’ve never been hacked. We’re good.”…When it does happen, you can’t really do much about it [if you don’t have an audit trail].

Click play to learn more!

Additional comments include:
• A rogue admin who took down a former employer’s network
• Admins who experience burn out
• NIST announced guidance on SMS on two factor.
• Whether or not security problems are the user’s fault or not
• As well as the latest research report on security shortcomings on a heart device.

Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

More from Varonis ⬇️

Visit our website: https://www.varonis.com

LinkedIn: https://www.linkedin.com/company/varonis

X/Twitter: https://twitter.com/varonis

Instagram: https://www.instagram.com/varonislife/

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(211)

The Ransomware That Ran Itself

The Ransomware That Ran Itself

More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat h...

18 Juli 38min

Megalodon Poisons Github

Megalodon Poisons Github

More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat h...

12 Juni 29min

The Canvas Breach

The Canvas Breach

More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat h...

19 Maj 29min

The Axios Supply Chain Attack

The Axios Supply Chain Attack

The Axios supply chain attack proves attackers don’t need vulnerabilities if they can hit the assembly line. By compromising a single npm maintainer account, they were able to slip a trojan into Axios...

10 Apr 43min

Salesforce Aura Data Theft

Salesforce Aura Data Theft

ShinyHunters has once again placed Salesforce customers in their crosshairs – this time abusing guest user misconfigurations in public-facing Experience Cloud sites. The group claims to have compromis...

20 Mars 29min

OpenClaw & Moltbook (w/ Moriah Hara!)

OpenClaw & Moltbook (w/ Moriah Hara!)

OpenClaw – an opensource AI agent dubbed “Claude with hands” – has exploded across GitHub, rocketing from obscurity to 170,000 stars in just two weeks. It’s now the fastest spreading form of shadow IT...

14 Feb 43min

The React2Shell Crisis

The React2Shell Crisis

React2Shell, the zero-click RCE exploit, is rapidly becoming one of the most significant cybersecurity incidents this year. From emergency patches causing a massive Cloudflare outage to active exploi...

15 Dec 202522min

AI-Powered Espionage

AI-Powered Espionage

A Chinese state-sponsored group weaponized Anthropic’s Claude tool to launch the first large-scale AI-driven espionage campaign, targeting more than 30 organizations across tech, finance, manufacturin...

24 Nov 202523min

Populärt inom Business & ekonomi

framgangspodden
badfluence
dynastin
varvet
svd-tech-brief
uppgang-och-fall
avanzapodden
rss-inga-dumma-fragor-om-pengar
rikatillsammans-om-privatekonomi-rikedom-i-livet
tabberaset
fill-or-kill
rss-kort-lang-analyspodden-fran-di
market-makers
rss-borslunch
borslunch-2
rss-veckans-trade
bathina-en-podcast
rss-dagen-med-di
rss-borssurr-med-mitelman-och-mellqvist
ekonomiekot-extra