|
|
|
|
|
by umvi
2483 days ago
|
|
Yeah except in this case an employee account was likely compromised by spearphishing/social engineering/(or worst case keylogger). That can be very hard to defend against. Good security is not easy, and not always due to "carelessness". It's an expensive, onerous, never ending, and ever evolving process to get right. Most, if not all, companies do the bare minimum security they believe is necessary; anything beyond that is a waste of money and computing resources (if you believe otherwise, I have some retina scanners to sell you...) |
|
This why we continue to have incidents and vulnerabilities which could have been prevented, or better mitigated. Most often these companies do not even know how to make a correct assessment of their risk. They move forward with this idea that it's a waste of money and resources, yet waste everyone's time with clean-up, or just go out of business as a result. Even with minimal security training and limited curiosity, this incident could have been avoided.