|
|
|
|
|
by thorwasdfasdf
2510 days ago
|
|
I've never understood people who say: "No amount of controls will stop someone truly motivated and skilled". I don't think that's true. Correct me if I'm wrong, but If there's no holes in the application/web stack to be exploited, then there's no getting in. Right? It's not about hacker/pirate skill. It's about whether or not the target has plugged all their holes or not. |
|
All your software vendors?
How likely are you to get malware on an employee laptop?
Phish employee credentials?
Have somebody sneak into your office late at night and install keyloggers on everyone's keyboards?
Kidnap an employee's family and blackmail them into giving you access?
Go through your recruiting pipeline and join as an employee with the motive to steal your data?
Get two people to do the same and bypass peer review controls?
Of course those are getting outlandish and unlikely, but that depends how "motivated and skilled" your attacker is.